An Explainable AI Framework For Cyber Threat Detection and Risk Assessment in Intelligent Networks
Keywords:
Artificial intelligence, Cybersecurity, Explainable AI, Intrusion detection, Risk assessment.Abstract
This study aims to develop an explainable artificial intelligence framework for cyber-threat detection and risk assessment in intelligent networks. The framework combines machine-learning classification with SHAP-based interpretation to improve the transparency of automated cybersecurity decisions. The objective was to evaluate and compare Logistic Regression, Random Forest, XGBoost, and Multilayer Perceptron models for distinguishing benign and malicious network traffic, identify the most influential network features using SHAP analysis, and assess detected threats using a model-derived risk score. The analysis was conducted using labeled network-flow data from the CIC-IDS2017 dataset. Among the evaluated approaches, XGBoost demonstrated the strongest overall classification performance. SHAP analysis identified several network-flow characteristics that substantially influenced the model's predictions, providing insight into its decision-making process. Threat-specific analysis further demonstrated variation in detection performance and risk classification across different attack categories, with most categories receiving high model-derived risk levels and selected categories receiving medium risk classifications. The findings demonstrate that integrating machine-learning detection with explainability and risk assessment can provide a more informative approach to intelligent network security. The proposed framework combines predictive capability with feature-level interpretation and threat-oriented risk information, potentially supporting transparent cybersecurity analysis and informed security decision-making.





