Object

Title: Explainable Network Traffic Classification Using XGBoost and SHAP: Interpreting Feature Contributions Across Traffic Classes, Journal of Telecommunications and Information Technology, 2026, nr 3

Group publication title:

2026, nr 3, JTIT-artykuły

Description:

kwartalnik

Abstrakt:

Network traffic classification has become an essential component of modern network management, cyber security, and quality-of-service provisioning. The widespread adoption of encryption technologies has reduced the effectiveness of traditional traffic identification techniques, leading to the use of ML approaches based on flow-level characteristics. Although several machine learning and deep learning models were evaluated, the black-box nature complicates the practical deployment in security critical environments. This research proposes a framework for ML-based network traffic classification of explainable artificial intelligence (XAI). The CIC-Darknet2020 dataset is divided into four classes: non-TOR, non-VPN, TOR and VPN. Additionally, machine learning algorithms, including ID3, k-nearest neighbors (KNN), random forest, CatBoost, XGBoost, and LSTM are used as a deep learning approach. The evaluation is carried out through stratified split of trains and 10-fold cross-validation, while XGBoost is classified for explainability analysis. By ensuring model transparency, SHAP (SHapley Additive exPlanations) identifies the most influential features contributing to classification predictions. Furthermore, a novel category SHAP analysis is introduced by grouping higher-level behavioral categories, including temporal, statistical, rate-based, and TCP-related features. The results revealed that temporal traffic characteristics and transport layer behavioral features influence classification outcomes, particularly for encrypted traffic classes. Moreover, the framework demonstrates that high classification performance and model interpretability are achievable simultaneously within a category-level study that enhances the transparency, trustworthiness, and practical applicability of machine learning-based network traffic classification systems.

Volume:

105

Number:

3

Publisher:

National Institute of Telecommunications

Resource Identifier:

oai:bc.itl.waw.pl:2483

DOI:

10.26636/jtit.2026.3.2724

eISSN:

1899-8852

Source:

Journal of Telecommunications and Information Technology

Language:

ang

Rights Management:

Biblioteka Naukowa Instytutu Łączności

License:

CC BY 4.0

rights owner:

Biblioteka Naukowa Instytutu Łączności

Object collections:

Last modified:

Oct 5, 2026

In our library since:

Oct 5, 2026

Number of object content hits:

0

All available object's versions:

https://bc.itl.waw.pl/publication/2806

Show description in RDF format:

RDF

Show description in OAI-PMH format:

OAI-PMH

Objects Similar

×

Citation

Citation style:

This page uses 'cookies'. More information