Skip to main navigation Skip to search Skip to main content

IIDS: a light-weight interpretable intrusion detection system for network infrastructures

  • Asadullah Momand
  • , Sana Ullah Jan
  • , Naeem Ramzan*
  • *Corresponding author for this work

    Research output: Contribution to journalArticlepeer-review

    4 Downloads (Pure)

    Abstract

    Network security remains a critical challenge in today’s interconnected world, where effective intrusion detection is essential to safeguarding sensitive infrastructures such as financial, medical, and governmental systems. Existing intrusion detection systems (IDS) often lack interpretability, preventing security personnel from gaining clear insights into detected anomalies and impeding timely, informed decision-making. Moreover, the growing complexity of networks demands adaptable IDS capable of identifying diverse intrusion types, such as overflow, black hole, or diversion across varied environments, while minimizing false positives and computational overhead. To address these issues, this study proposes an interpretable intrusion detection system (IIDS) leveraging an ensemble learning approach that integrates an attention-based convolutional neural network (CNN), long short-term memory (LSTM), and an interpretable random forest (RF) algorithm. The CNN and LSTM components extract spatial and temporal features from network traffic. At the same time, the RF enhances transparency by providing decision trees that elucidate the model’s reasoning, enabling security teams to understand and trust the pblackictions. Evaluated against state-of-theart methods, the proposed IIDS achieves optimum performance with an accuracy of 99.00% and an F1-score of 99.00%, outperforming other models, as demonstrated on benchmark datasets. Notably, it uniquely combines high detection efficacy with interpretability, distinguishing it from black box alternatives. These results highlight IIDS’s potential for real-time deployment in critical network infrastructures, offering optimum protection against cyber threats and actionable insights into intrusion subtypes, thus advancing the reliability and transparency of network security solutions.
    Original languageEnglish
    Article number1860652
    Number of pages20
    JournalFrontiers in Computer Science
    Volume8
    DOIs
    Publication statusPublished - 14 Jul 2026

    UN SDGs

    This output contributes to the following UN Sustainable Development Goals (SDGs)

    1. SDG 9 - Industry, Innovation, and Infrastructure
      SDG 9 Industry, Innovation, and Infrastructure

    Keywords

    • intrusion detection
    • CNN
    • LSTM
    • random forest
    • interpretability

    Fingerprint

    Dive into the research topics of 'IIDS: a light-weight interpretable intrusion detection system for network infrastructures'. Together they form a unique fingerprint.

    Cite this