Explainable Machine Learning for DDoS Attack Detection with Physical Network Validation

Authors

  • Muhammad Azzam Anshori Informatics Engineering Study Program, Faculty of Engineering, Universitas Riau
  • Rahyul Amri Informatics Engineering Study Program, Faculty of Engineering, Universitas Riau

DOI:

https://doi.org/10.70356/josapen.v4i2.131

Keywords:

DDoS Detection, Machine Learning, Explainable AI, SHAP, CIC-DDoS2019

Abstract

Distributed Denial-of-Service (DDoS) attacks remain one of the most disruptive threats to network infrastructure, yet many machine learning (ML)-based detection studies report only offline benchmark performance without verifying whether that performance holds under real network conditions. This study evaluates two explainable ML classifiers, XGBoost and Random Forest, for DDoS detection and examines whether their near-perfect offline accuracy translates into reliable physical-network operation. The study combines offline benchmarking on the CIC-DDoS2019 dataset (293,485 flows) with physical-network validation using a working Intrusion Detection System (IDS) prototype under a controlled SYN-flood attack. Session-disjoint stratified sampling prevented flow-level leakage across attack sessions, while SHapley Additive exPlanations (SHAP) interpreted global and local feature importance. Offline, both classifiers achieved near-perfect performance (accuracy 99.99% for XGBoost, 99.98% for Random Forest; F1 = 0.9999; ROC-AUC up to 1.0000), with no statistically significant difference between them (McNemar's exact test, p = 0.2188), though XGBoost achieved approximately 3.69 times higher inference throughput (1,819,816 flows/s). SHAP identified Min Packet Length, Fwd Packet Length Min, Inbound, Protocol, and Init_Win_bytes_forward as the most influential features. In physical deployment, however, the IDS prototype flagged 6.26% of captured flows (6,935 of 110,762) as ATTACK during the SYN-flood test, and a separate 397-flow ambient-benign subset yielded a 6.80% false positive rate (95% Wilson CI: 4.72–9.71%), with short-duration SSDP/UPnP-style UDP control traffic accounting for 70% of observed false positives. This gap shows that near-perfect offline accuracy does not guarantee low false positives in real deployment, indicating that offline benchmarks alone are insufficient for validating IDS readiness.

Downloads

Download data is not yet available.

References

S. Erdas, A. E. Akkaya, and A. A. Aydin, “Machine learning based hybrid DDoS attack prediction,” European Journal of Technique, vol. 15, no. 2, pp. 45–56, 2025, doi: https://doi.org/10.36222/ejt.1670798.

B. K. Mohammed and H. H. Khayoon, “A critical theoretical comparison of DoS and DDoS attacks: Detection and defense perspectives,” in Proc. 2026 2nd Int. Conf. Computing and Emerging Sciences, ACM, 2026, pp. 1–8. doi: https://doi.org/10.1145/3797491.3797497.

A. H. Ali et al., “Unveiling machine learning strategies and considerations in intrusion detection systems: A comprehensive survey,” Front. Comput. Sci., vol. 6, p. 1387354, 2024, doi: https://doi.org/10.3389/fcomp.2024.1387354.

A. Momand, S. U. Jan, and N. Ramzan, “A systematic and comprehensive survey of recent advances in intrusion detection systems using machine learning: Deep learning, datasets, and attack taxonomy,” J. Sens., vol. 2023, p. 6048087, 2023, doi: https://doi.org/10.1155/2023/6048087.

N. Sharma and B. Arora, “Machine learning and deep learning models for anomaly intrusion detection in networks: A systematic review,” SN Comput. Sci., vol. 6, p. 832, 2025, doi: https://doi.org/10.1007/s42979-025-04352-z.

T. H. Sow and M. Adda, “Enhancing IDS performance through a comparative analysis of Random Forest, XGBoost, and Deep Neural Networks,” Machine Learning with Applications, vol. 22, p. 100738, 2025, doi: https://doi.org/10.1016/j.mlwa.2025.100738.

O. Achbarou, T. Datsi, O. Bourkoukou, and A. My El Kiram, “Enhanced intrusion detection system using feature selection and hybrid learning models for high performance and efficiency in an IoT environment,” Journal of Engineering Research, 2025, doi: https://doi.org/10.1016/j.jer.2025.10.016.

N. Moustafa, N. Koroniotis, M. Keshk, A. Y. Zomaya, and Z. Tari, “Explainable intrusion detection for cyber defences in the internet of things: Opportunities and solutions,” IEEE Communications Surveys & Tutorials, vol. 25, no. 3, pp. 1775–1807, 2023, doi: https://doi.org/10.1109/COMST.2023.3280465.

M. T. Islam, M. K. Syfullah, M. G. Rashed, and D. Das, “Bridging the gap: Advancing the transparency and trustworthiness of network intrusion detection with explainable AI,” International Journal of Machine Learning and Cybernetics, vol. 15, no. 11, pp. 5337–5360, 2024, doi: https://doi.org/10.1007/s13042-024-02242-z.

P. Hermosilla, S. Berríos, and H. Allende-Cid, “Explainable AI for forensic analysis: A comparative study of SHAP and LIME in intrusion detection models,” Applied Sciences, vol. 15, no. 13, p. 7329, 2025, doi: https://doi.org/10.3390/app15137329.

V. Z. Mohale and I. C. Obagbuwa, “A systematic review on the integration of explainable artificial intelligence in intrusion detection systems to enhancing transparency and interpretability in cybersecurity,” Front. Artif. Intell., vol. 8, 2025, doi: https://doi.org/10.3389/frai.2025.1526221.

J. Hesford, “Expectations versus reality: Evaluating intrusion detection systems in practice,” in Proc. 55th Annual IEEE/IFIP Int. Conf. Dependable Systems and Networks — Supplemental Volume (DSN-S), 2025, pp. 56–62. doi: https://doi.org/10.1109/dsn-s65789.2025.00042.

B. Assadhan, A. Bashaiwth, and H. Binsalleeh, “Enhancing explanation of LSTM-based DDoS attack classification using SHAP with pattern dependency,” IEEE Access, vol. 12, pp. 90707–90725, 2024, doi: https://doi.org/10.1109/access.2024.3421299.

A. A. Najar and S. M. Naik, “A robust DDoS intrusion detection system using convolutional neural network,” Computers and Electrical Engineering, vol. 117, 2024, doi: https://doi.org/10.1016/j.compeleceng.2024.109277.

H. Sharif, “A machine learning-based approach for the detection of DDoS attacks on the Internet of Things using CICDDoS2019 dataset - PortMap,” Lahore Garrison University Research Journal of Computer Science and Information Technology, vol. 8, no. 2, pp. 19–30, 2024, doi: https://doi.org/10.54692/lgurjcsit.2024.082569.

Y. Hu, K. Xiao, L. Luo, and L. Chen, “An XGBoost-based intrusion detection framework with interpretability analysis for IoT networks,” Applied Sciences, vol. 16, no. 2, p. 980, 2026, doi: https://doi.org/10.3390/app16020980.

Z. Zhang, S. Kong, T. Xiao, and A. Yang, “A network intrusion detection method based on bagging ensemble,” Symmetry (Basel)., vol. 16, no. 7, p. 850, 2024, doi: https://doi.org/10.3390/sym16070850.

S. Sambangi, L. Gondi, and S. Aljawarneh, “A feature similarity machine learning model for DDoS attack detection in modern network environments for Industry 4.0,” Computers & Electrical Engineering, vol. 100, p. 107955, 2022, doi: https://doi.org/10.1016/j.compeleceng.2022.107955.

D. Akgun, S. Hizal, and U. Cavusoglu, “A new DDoS attacks intrusion detection model based on deep learning for cybersecurity,” Comput. Secur., vol. 118, 2022, doi: https://doi.org/10.1016/j.cose.2022.102748.

J. Shaikh, Y. A. Butt, and H. F. Naqvi, “Effective intrusion detection system using deep learning for DDoS attacks,” Asian Bulletin of Big Data Management, vol. 4, no. 1, pp. 168–183, 2024, doi: https://doi.org/10.62019/abbdm.v4i1.113.

M. A. Bouke and A. Abdullah, “An empirical study of pattern leakage impact during data preprocessing on machine learning-based intrusion detection models reliability,” Expert Syst. Appl., vol. 230, p. 120715, 2023, doi: https://doi.org/10.1016/j.eswa.2023.120715.

A. Luque, A. Carrasco, A. Martín, and A. de las Heras, “The impact of class imbalance in classification performance metrics based on the binary confusion matrix,” Pattern Recognit., vol. 91, pp. 216–231, 2019, doi: https://doi.org/10.1016/j.patcog.2019.02.023.

S. Sathyanarayanan and B. Roopashri Tantri, “Confusion matrix-based performance evaluation metrics,” African Journal of Biomedical Research, vol. 27, no. 4s, pp. 4023–4031, 2024, doi: https://doi.org/10.53555/ajbr.v27i4s.4345.

S. Dash and J. M. Acken, “Intrusion detection latency: the neglected metric,” Cybersecurity, vol. 9, art. 144, 2026, doi: https://doi.org/10.1186/s42400-026-00574-7.

B. Rozemberczki, “The Shapley value in machine learning,” in Proc. 31st Int. Joint Conf. Artificial Intelligence (IJCAI-22), Survey Track, 2022, pp. 5572–5579. doi: https://doi.org/10.24963/ijcai.2022/778.

M. Anagnostopoulos, S. Lagos, and G. Kambourakis, “Large-scale empirical evaluation of DNS and SSDP amplification attacks,” Journal of Information Security and Applications, vol. 66, p. 103168, 2022, doi: https://doi.org/10.1016/j.jisa.2022.103168.

S. A. Madoune et al., “A novel approach for real-time DDoS detection in SDN using dimensionality reduction and ensemble learning,” Journal of Information Security and Applications, vol. 94, 2025, doi: https://doi.org/10.1016/j.jisa.2025.104195.

Published

2026-08-28

How to Cite

Anshori, M. A., & Amri, R. (2026). Explainable Machine Learning for DDoS Attack Detection with Physical Network Validation. Journal of Computer Science Application and Engineering (JOSAPEN), 4(2), 42–49. https://doi.org/10.70356/josapen.v4i2.131