Next Article in Journal
Performance Evaluation of ADS-B Receivers Implemented Using Software-Defined Radio Platforms and GNU Radio
Previous Article in Journal
COAu-IoD: A Cloud and Offline Computing-Assisted Authentication Framework for Lightweight UAV Communication in IoD
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

Explainable and Analyst-Driven Random Forest for Intrusion Detection

1
National School of Computer Science and Systems Analysis (ENSIAS), Mohammed V University in Rabat, Rabat 10100, Morocco
2
Department of Engineering Technology (INDI), Vrije Universiteit Brussel, Pleinlaan 2, 1050 Brussels, Belgium
*
Author to whom correspondence should be addressed.
Future Internet 2026, 18(9), 490; https://doi.org/10.3390/fi18090490 (registering DOI)
Submission received: 2 August 2026 / Revised: 2 September 2026 / Accepted: 15 September 2026 / Published: 18 September 2026
(This article belongs to the Section Cybersecurity)

Abstract

Random Forest and other tree-ensemble classifiers achieve high accuracy in network intrusion detection; however, their aggregate decision logic prevents analysts from auditing or deploying individual predictions as operational rules. Post hoc explanation methods introduce latencies incompatible with security operation center (SOC) requirements and produce conditions unsuitable for firewall configuration. Among the systems reviewed in this study, none unifies intrinsic explanation, rule deployment, ATT&CK attribution, cross-dataset validation, and adaptive feedback in one pipeline. This work presents a depth-limited Random Forest with deterministic, per-instance explanations at a fraction of gradient-based attribution latency. Complementary mechanisms generate analyst-deployable rule specifications, technique-level adversary attribution, and a feedback protocol that models label noise, missed reviews, and bounded correction budget. Evaluated on a large, multi-category network-traffic benchmark, the system attains high detection accuracy (macro recall 0.86, driven substantially by the majority normal-traffic class at 68% of flows) while sustaining throughput beyond SOC requirements; a stealthy reconnaissance-and-exploitation category remains markedly harder to detect under this class imbalance. Cross-dataset evaluation on a more recent benchmark attains strong performance after limited target-domain retraining. The adaptive feedback protocol yields a statistically significant false-positive reduction over repeated simulated reviews, requiring only modest weekly analyst effort. Together, these capabilities enable auditable and SOC-integrable detection pipelines.
Keywords: adaptive learning; anomaly detection; cybersecurity; explainable artificial intelligence; feature extraction; intrusion detection systems; machine learning; network traffic analysis; random forests; transfer learning adaptive learning; anomaly detection; cybersecurity; explainable artificial intelligence; feature extraction; intrusion detection systems; machine learning; network traffic analysis; random forests; transfer learning

Share and Cite

MDPI and ACS Style

Bellouch, S.; Zbakh, M.; Aouad, S.; Braeken, A. Explainable and Analyst-Driven Random Forest for Intrusion Detection. Future Internet 2026, 18, 490. https://doi.org/10.3390/fi18090490

AMA Style

Bellouch S, Zbakh M, Aouad S, Braeken A. Explainable and Analyst-Driven Random Forest for Intrusion Detection. Future Internet. 2026; 18(9):490. https://doi.org/10.3390/fi18090490

Chicago/Turabian Style

Bellouch, Saloua, Mostapha Zbakh, Siham Aouad, and An Braeken. 2026. "Explainable and Analyst-Driven Random Forest for Intrusion Detection" Future Internet 18, no. 9: 490. https://doi.org/10.3390/fi18090490

APA Style

Bellouch, S., Zbakh, M., Aouad, S., & Braeken, A. (2026). Explainable and Analyst-Driven Random Forest for Intrusion Detection. Future Internet, 18(9), 490. https://doi.org/10.3390/fi18090490

Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details here.

Article Metrics

Back to TopTop