Obiekt

Tytuł: Explainable Network Traffic Classification Using XGBoost and SHAP: Interpreting Feature Contributions Across Traffic Classes, Journal of Telecommunications and Information Technology, 2026, nr 3

Tytuł publikacji grupowej:

2026, nr 3, JTIT-artykuły

Opis:

kwartalnik

Abstrakt:

Network traffic classification has become an essential component of modern network management, cyber security, and quality-of-service provisioning. The widespread adoption of encryption technologies has reduced the effectiveness of traditional traffic identification techniques, leading to the use of ML approaches based on flow-level characteristics. Although several machine learning and deep learning models were evaluated, the black-box nature complicates the practical deployment in security critical environments. This research proposes a framework for ML-based network traffic classification of explainable artificial intelligence (XAI). The CIC-Darknet2020 dataset is divided into four classes: non-TOR, non-VPN, TOR and VPN. Additionally, machine learning algorithms, including ID3, k-nearest neighbors (KNN), random forest, CatBoost, XGBoost, and LSTM are used as a deep learning approach. The evaluation is carried out through stratified split of trains and 10-fold cross-validation, while XGBoost is classified for explainability analysis. By ensuring model transparency, SHAP (SHapley Additive exPlanations) identifies the most influential features contributing to classification predictions. Furthermore, a novel category SHAP analysis is introduced by grouping higher-level behavioral categories, including temporal, statistical, rate-based, and TCP-related features. The results revealed that temporal traffic characteristics and transport layer behavioral features influence classification outcomes, particularly for encrypted traffic classes. Moreover, the framework demonstrates that high classification performance and model interpretability are achievable simultaneously within a category-level study that enhances the transparency, trustworthiness, and practical applicability of machine learning-based network traffic classification systems.

Tom:

105

Numer:

3

Wydawca:

National Institute of Telecommunications

Identyfikator zasobu:

oai:bc.itl.waw.pl:2483

DOI:

10.26636/jtit.2026.3.2724

eISSN:

1899-8852

Źródło:

Journal of Telecommunications and Information Technology

Język:

ang

Prawa:

Biblioteka Naukowa Instytutu Łączności

Licencja:

CC BY 4.0

Właściciel praw:

Biblioteka Naukowa Instytutu Łączności

Kolekcje, do których przypisany jest obiekt:

Data ostatniej modyfikacji:

5 paź 2026

Data dodania obiektu:

5 paź 2026

Liczba wyświetleń treści obiektu:

0

Wszystkie dostępne wersje tego obiektu:

https://bc.itl.waw.pl/publication/2806

Wyświetl opis w formacie RDF:

RDF

Wyświetl opis w formacie OAI-PMH:

OAI-PMH

Obiekty Podobne

×

Cytowanie

Styl cytowania:

Ta strona wykorzystuje pliki 'cookies'. Więcej informacji