Societal Transformation: AI and Big Data Journal

Explainable Intrusion Detection on UNSW-NB15 with ExtraTrees Feature Selection and Ensemble Learning

Research Article
- Volume 4, Issue 1 2026
By Waqas Aziz, Imran Ali, Abdul Ghafoor, Farooq Alam

Intrusion Detection Systems (IDS) are important for protecting modern the networks against increasingly known cyber-attacks. However, the traditional IDS methods are also characterized by high dimensional data, low detection accuracy and the interpretability, this research is aimed at providing an explainable intrusion detection framework to combine the ExtraTrees-based feature selection with the ensemble ML models based on UNSW-NB15 dataset. The introduced methodology will start with the in-depth of the data preprocessing, such as the handling missing values, categorical attributes, and feature normalization to improve the quality of data and model performance. ExtraTrees feature selection is subsequently performed in order to select the most significant network traffic features, dimensionality reduction is performed though important information that is needed to detect an attack accurately is retained. Various ML classifiers, such as the Naive Bayes, Decision Tree K-Nearest Neighbors, Random Forest, and LightGBM are trained and tested to determine their detection performance. It is experimentally demonstrated that the ensemble-based models tend to be more accurate, more precise, more recalling, and have higher F1-score than the individual classifiers. Specifically, the best classification results were obtained with Random Forest and LightGBM which minimized the false positives and the false negatives. Also, the prediction behavior and the reliability of model are analyzed using visualization methods, including ROC curve analysis and scatter plot evaluation. Analysis of feature importance also enhances the model interpretability by establishing the most significant attributes that make intrusion detection decisions. The findings indicate that feature selection coupled with ensemble-learning can effectively to enhance the performance of intrusion detection at a low level of transparency. The framework presented provides a practical and understandable solution to the current network security systems.

Share this paper


Want to publish in ?
Send us your paper for review
22
Authors
28
Research Papers
0
Citations