Evaluation of Machine Learning Classification for Intrusion Detection with Explainable AI Implementation

Authors

  • Alvino Kannen Vallian
  • Rafael Sebastian Wibowo
  • Gede Putra Kusuma
  • Hidayaturrahman

Keywords:

Cybersecurity Threat, Intrusion Detection, Artificial Intelligence, Machine Learning, Model Interpretability, Explainable AI, UNSW-NB15 Dataset.

Abstract

Classification is a machine learning objective that enables the model to properly output results based on available features. In current times, intrusion detection systems are able to be developed based on machine learning objectives, enabling them to work in conjunction by having the machine learning model able to help identify which type of intrusion set off the intrusion detection systems’s alarms. With the trend of cybersecurity becoming increasingly prominent and along comes the development of explainable artificial intelligence, the aspect of transparency in machine learning-driven intrusion detection systems is highlighted due to the trend of explainable artificial intelligence. This work contributes to evaluating on how well does a machine learning model implemented with explainable artificial intelligence is able to perform and how will the output of the explainable artificial intelligence be able to increase the model’s transparency. The experiment itself is done with the UNSW-NB15 dataset as a means to replicate the regular day-to-day conditions while also being a certified dataset. As a result, the algorithm best suited for the classification purpose is XGBoost with a value of 0.9767 for the accuracy metric, 0.6207 for macro F1, 0.7063 for macro Recall, 0.5947 for macro Precision, and 0.0024 for Macro FPR as a false alarm metric.

Downloads

Published

2026-09-01

How to Cite

Vallian, A. K., Wibowo, R. S., Kusuma, G. P., & Hidayaturrahman. (2026). Evaluation of Machine Learning Classification for Intrusion Detection with Explainable AI Implementation. International Journal of Artificial Intelligence and Machine Learning, 6(3), 684–696. Retrieved from https://mail.svedbergopen.com/index.php/ijaiml/article/view/2104