A Privacy-Preserving Explainable Artificial Intelligence Hybrid Framework for Abnormal Network Traffic Identification and Intelligent Threat Detection
Abstract
Abstract The rapid evolution of cyber threats, the widespread adoption of encrypted communications, and the increasing complexity of enterprise, cloud, edge, and Internet of Things (IoT) environments have exposed the limitations of conventional intrusion detection systems in accurately identifying abnormal network traffic and detecting sophisticated cyberattacks. Existing hybrid deep learning frameworks, including that of Wang [54], achieve high detection accuracy but lack privacy-preserving computation, explainable artificial intelligence, intelligent threat prioritization, and adaptive operational capabilities. This study therefore designed and developed a Hybrid Artificial Intelligence Framework for Abnormal Network Traffic Identification and Intelligent Threat Detection by integrating Long Short-Term Memory (LSTM), Transformer, Random Forest, CKKS Homomorphic Encryption, Explainable Artificial Intelligence (SHAP/LIME), weighted ensemble decision fusion, intelligent threat prioritization, and adaptive feedback learning. The study adopted the Design Science Research Methodology (DSRM), while the proposed framework was implemented using Python, TensorFlow/Keras, Scikit-learn, Microsoft SEAL/TenSEAL, and evaluated using the CICIDS2017 and UNSW-NB15 benchmark datasets. Experimental evaluation was performed using accuracy, precision, recall, F1-score, false positive rate, detection latency, zero-day detection rate, throughput, scalability, explainability, and encryption overhead as performance metrics. The proposed framework achieved detection accuracies of 99.12% and 98.76% on the CICIDS2017 and UNSW-NB15 datasets, respectively, with precision values of 98.87% and 98.42%, recall values of 99.05% and 98.61%, F1-scores of 98.96% and 98.51%, false positive rates of 0.84% and 1.12%, and zero-day detection rates of 94.30% and 92.75%. Comparative analysis demonstrated improved detection accuracy, lower false-positive rates, reduced detection latency, enhanced interpretability, and stronger privacy preservation compared with the hybrid CNN–LSTM–Transformer framework of Wang [54]. The study concludes that integrating hybrid artificial intelligence, privacy-preserving computation, explainable artificial intelligence, and intelligent threat prioritization provides a robust, scalable, and adaptive solution for modern cybersecurity. The proposed framework is recommended for deployment in enterprise networks, cloud computing, IoT, edge computing, and critical infrastructure environments to strengthen real-time cyber threat detection and response. Keywords: Hybrid Artificial Intelligence, Abnormal Network Traffic Identification, Intelligent Threat Detection, Intrusion Detection System, LSTM, Transformer, Random Forest, Explainable Artificial Intelligence, CKKS Homomorphic Encryption, Zero-Day Attack Detection
// Source
Authors: D. A. Onuma, Matthias D., DR. O. E. Taylor, PROF. N. D. Nwiabu
Institutions: Rivers State University