Next Article in Journal
AI-Driven Reliability in 6G Networks: Enhancing QoE of Real-World Video Streaming
Previous Article in Journal
Challenges in Digitalization for Holistic and Transparent Supply Chains During Crises
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

Enhancing Network Traffic Monitoring Through eXplainable Artificial Intelligence Methodologies

by
Cătălin-Eugen Bucur
1,*,
Georgiana Crihan
2,*,
Anamaria Rădoi
1,
Elena-Grațiela Robe-Voinea
3,* and
Iustin-Nicolae Moroșan
3
1
Faculty of Electronics, Telecommunications and Information Technology, National University of Science and Technology Politehnica Bucharest, Splaiul Independenței 313, 060042 Bucharest, Romania
2
Romanian Naval Forces, Fulgerului Street No. 99, 900218 Constanta, Romania
3
Faculty of Marine Engineering, Romanian Naval Academy “Mircea cel Bătrân”, Fulgerului Street No. 1, 900218 Constanta, Romania
*
Authors to whom correspondence should be addressed.
Telecom 2026, 7(2), 34; https://doi.org/10.3390/telecom7020034
Submission received: 31 December 2025 / Revised: 20 February 2026 / Accepted: 19 March 2026 / Published: 23 March 2026

Abstract

In the contemporary digital landscape, AI (Artificial Intelligence) emerged as a pivotal tool in enhancing the defense technologies developed across the entire network infrastructure. As reliance on AI-based decision-making grew, so did the imperative need for interpretability, transparency, and trustworthiness, leading to the development and integration of XAI (eXplainable Artificial Intelligence). This research paper provides a comprehensive overview of the current state of the art in XAI approaches that can be effectively implemented for network traffic monitoring, especially in critical digital infrastructures. The main contribution of this research article consists of the comparative analysis of the XAI SHAP (Shapley Additive Explanation) method applied to different datasets obtained from real-time network traffic monitoring, utilizing several representative parameters, which demonstrates the performance, vulnerabilities, and limitations of the proposed method, and also the security implications of the system resources from a cybersecurity perspective. Experimental results show that Ethernet networks offer higher predictability and clearer decision boundaries. Consequently, they are a safer solution for deployment in sensitive network architectures. In contrast, BYOD (Bring Your Own Device) Wi-Fi environments exhibit greater randomness.

1. Introduction

The rapid development and digitization of computational infrastructures have led to a major increase in data traffic across multiple fields of activity, e.g., UAV-assisted, edge-enhanced networks used in poor-infrastructure scenarios [1]. To secure and manage these environments, people have used AI, which has replaced traditional reactive solutions with more proactive and predictive capabilities, while also introducing additional computational requirements and improved deployment optimization and efficiency. AI-driven systems are developed and implemented in different types of infrastructures, such as—cloud computing, edge computing or fog infrastructure solutions, facilitating adaptive approaches [2]. According to recent studies, digital infrastructures are being reshaped by cutting-edge AI through innovations in data centers, energy-efficient computing, intelligent automation, and structural configurations for large-scale deployment. Industrial systems are transitioning from Industry 4.0 to Industry 5.0, becoming more resilient and sustainable by integrating AI techniques with technologies such as big data analytics, smart systems, robotics, and virtualization [3,4,5]. Over time, the implementation of AI technologies has shown a rising trend and demonstrated its transformative potential and profound impact on theoretical and practical accomplishments across different domains [6].
Figure 1 highlights the stages of AI evolution and its major outcomes that will drive optimization, transparency, and trustworthiness in industries, so that humans will work alongside advanced technology and AI-powered robots to enhance workplace processes. This is coupled with a more human-centric focus, greater resilience, and a stronger emphasis on sustainability.
Despite the numerous and significant advantages and disadvantages of AI for digital infrastructures, the evolution of AI agents highlights their primary benefit: replicating human cognitive capabilities so that systems can act independently, using learning-based architectures to handle high-volume network environments without direct human support or intervention.
As AI systems become increasingly involved in decision-making processes, especially in critical security areas, the need for accuracy and transparency becomes essential. Complex and traditional AI models, especially deep learning systems, are considered “black boxes, so understanding the behavior and the principles underlying decision processes represents a challenging task that is currently difficult for users to comprehend. This lack of understanding automatically leads to a lack of trust in cybersecurity operations [7,8].
XAI is an outstanding solution to these uncertainty-related issues, as it provides clear explanations of how AI systems operate, helping human operators understand AI decisions. Through specific methods and techniques, XAI mitigates the shortcomings of “black boxes” and enables analysts to evaluate and validate AI-driven alerts and recommendations—an increasingly urgent need, especially in critical environments and infrastructure [9]. An effective approach to enhance network security is to integrate XAI for monitoring network traffic. These methods help reduce false alarms while providing transparent and interpretable explanations for their decisions, thereby improving trust and predictability. The implementation of these XAI methods not only diminishes human factor supervision, but also brings financial advantages by reducing operational costs.
Given the growing need for explainability in cybersecurity, Figure 2 depicts AI involvement across four levels, highlighting the interplay between human oversight and automation. This perspective motivates the adoption of XAI as a means to improve operational efficiency through human–AI collaboration while mitigating the drawbacks associated with less transparent approaches. The interdependence between AI and cybersecurity is evident, and XAI techniques and methods are evolving in different ways. XAI will significantly improve the detection, mitigation, and response to vulnerabilities in the system against a wide variety of cyberattacks. Furthermore, as AI systems develop, security breaches involving classified and personal information are increasing; hence, the need for XAI methods that prioritize the privacy and security of sensitive data while enabling prediction, transparency, and accuracy.
The present article focuses on research contributions that are developed in the following directions as follows:
  • provide a systematic review of the applicable XAI methodologies for network traffic analysis and intrusion detection;
  • evaluate the role of XAI in improving decision-making capabilities and operational visibility in critical infrastructure environments;
  • a particular focus is the analysis of the performance, limitations, and implications of using XAI in real-world scenarios from a security perspective;
  • perform a comparative analysis of two network topologies to highlight the behavior of the XAI SHAP method in real-time network traffic monitoring: an Ethernet network with a virtualized platform and a Wi-Fi network based on the BYOD concept, to identify the best alternative for deployment in critical digital infrastructures;
  • provide a specific framework for assessing transparency and trust for benign and malicious traffic to meet the needs of cybersecurity professionals [8].
The article structure is organized as follows: in the Introduction, the presentation of the current digital context and AI evolution are addressed, and also, the need for Explainability in cybersecurity is explained; Section 2 provides a comprehensive overview of XAI concepts, network traffic monitoring main characteristics used in the existing literature and relevant to the research topic, and describes the security requirements in critical infrastructures; Section 3 presents the current framework and taxonomy of XAI methodologies applicable to data traffic monitoring related to real-world applications and develops several case studies; Section 4 performs an analysis of the current XAI SHAP method, based on evaluation parameters to demonstrate their efficiency and reliability, but also their shortcomings, technical constraints, and security vulnerabilities; this section also highlights the implications of XAI on system performance, privacy, and compatibility with existing critical digital infrastructures. Finally, Section 5 concludes the paper and presents future research directions for XAI development in radio, cloud and edge environments, automated approaches to explainability, and integration into smart networks.

2. Related Works

Complex “black-box” models usually do not show how decisions are made. For this reason, the interest in designing, implementing, and testing XAI has increased in the last years. As presented in [10], these emerging methodologies, developed at the visual or conceptual level, encompass a set of methods and principles designated to transform AI systems into more understandable, transparent, and human-comprehensible systems. Their implementation is especially important in high-risk and critical infrastructure sectors, such as cybersecurity, healthcare, and finance, where confidentiality, trust, and transparency are mandatory.
In the current security architecture dominated by constantly evolving threats, there is an urgent need to develop and to use AI applications in the field of cybersecurity, including intrusion detection and malware classification, with particular emphasis on identifying XAI as a solution for overcoming the interpretability challenges required for AI models as highlighted in [11].
In ref. [12], authors analyze the most promising and available XAI methods for cyber defence related to IoT systems, focusing on the following directions: intrusion detection, malware detection, spam detection, preserving privacy, and digital forensics. This article also delves into the examination of XAI in IoT from a technical perspective, but also security and privacy, helping in developing models with both high accuracy and interpretability for end users, providing trust and control in cybersecurity applications. Regarding the role of XAI in network traffic monitoring, several approaches employing various explainability methodologies have been identified in the specialized literature, as presented in Table 1.
Analyzing the data presented in the table above, it can be observed that the vast applicability of XAI techniques in various levels of networking, with a preponderance in identifying imminent attacks, from which the close connection between the two concepts XAI-Cybersecurity emerges. It is worth noting that most scientific articles focus on using international datasets to conduct tests. Compared to the articles presented in this section, the originality of our work derives from the development level, because applying XAI techniques to real network traffic offer several unique advantages. They are considered superior to software implementation in terms of security, and brings to the forefront much more conclusive results in monitoring network traffic in real-time, detecting possible anomalies and solving the challenges posed by “black-box” models, by increasing the level of understanding and defending against cyber threats.
This specific focus on the intersection of XAI and cybersecurity allows us to offer a more targeted and comprehensive analysis of this domain, helping researchers, network and system security engineers, and practitioners identify existing solutions and gaps.

2.1. Network Traffic Monitoring: Role and Challenges

The emergence of the Internet was based on the creation of a global network that connects computers and facilitates the exchange of information. This evolution has led to the development of tools to monitor data traffic for purposes that can be divided into three broad categories: security, performance, and planning [23,24].
Monitoring represents the measurement of parameters that ensure the speed, efficiency, and reliability of the network. This includes a wide range of metrics, such as:
  • Speed and Quality: packet loss, latency (response time), throughput, and jitter;
  • Capacity: bandwidth utilization and overall network utilization;
  • Reliability: uptime, availability, error rates, connection stability, Mean Time Between Failures (MTBF), and Mean Time To Repair (MTTR);
  • Service Goals: compliance with Service Level Agreements (SLA) and ensuring Quality of Service (QoS).
Performance and planning are two closely interconnected categories. Performance monitoring focuses on ensuring high Quality of Service and identifying issues such as bottlenecks or outages. The resulting data are decisive for the planning process, as long-term traffic analysis allows network architects to identify non-optimized areas and adjust network parameters accordingly.
Today, network security has become the most critical aspect of traffic monitoring, involving real-time analysis of traffic patterns and the identification of anomalies or signatures associated with known attacks [25]. Several types of network attacks, including Network Service Discovery, Denial of Service, Brute Force, Web Attacks, Infiltration, Botnets, Network Scanning or Surveillance, Remote-to-Local attacks, and User-to-Root attacks, constitute significant threats to network integrity and security. Addressing these challenges requires adopting advanced detection frameworks that accurately identify attacks and provide meaningful explanations, even when black-box AI models are employed [19].
Current challenges in network traffic monitoring are reshaping traditional analysis paradigms, which are no longer sufficient for modern network environments. One major challenge is the widespread use of encrypted traffic, which significantly reduces the efficiency of extracting useful information using conventional inspection techniques [26]. Recent studies highlight the importance of encrypted protocols and VPN tunneling for data privacy, while also emphasizing the difficulty of anomaly detection with traditional methods [14,24].
Another critical challenge is the increasing volume, diversity, and dynamism of network data. Processing and analyzing highly variable, complex traffic requires advanced analytical and learning-based technologies [24]. Furthermore, modern network infrastructures span heterogeneous environments, including enterprise backbones, multi-cloud platforms, edge computing nodes, and Internet Service Provider (ISP) infrastructures. These complex ecosystems demand comprehensive, real-time monitoring solutions to maintain performance, reliability, and security, whilst traditional monitoring approaches are often unsuitable for such large-scale and dynamic networks [27]. Flow-based network attack detection aggregates packet-level information into flows, typically defined by a 5-tuple, enabling scalable traffic analysis while preserving behavioral characteristics relevant to intrusion detection. This paradigm is widely adopted in anomaly detection and intrusion detection systems due to its efficiency and descriptive power, and is commonly used in well-established benchmarks, CICFlowMeter-based datasets (e.g., CIC-IDS 2017), as described by [28,29,30].
Finally, resource constraints pose an additional limitation, as high-performance traffic monitoring typically requires substantial computational and storage resources that may not be available in all deployment scenarios [31].

2.2. Critical Infrastructures and Security Requirements

Critical infrastructure comprises systems that are essential to various fields of activity. Under legislation, such infrastructure is defined as a set of physical, technological, and organizational resources whose damage or destruction would have a major impact on national security, public order, public health and safety, as well as on the functioning of the economy and state institutions. In the modern era, these infrastructure sectors, including electricity, water distribution, transportation, and healthcare, increasingly rely on sensors and actuators connected via the Internet of Things (IoT) to create smart environments [32,33].
Nowadays, digitalization and system interconnection have made daily operations significantly more efficient across all sectors, to the extent that the absence of such infrastructures has become almost unimaginable. Although this evolution and diversification have brought substantial advantages and improved the monitoring and control of critical infrastructure systems, they have also led to a proportional increase in vulnerabilities, threats, and cyberattacks targeting these infrastructures, with potentially devastating consequences [34]. In this context, effective human–machine collaboration is essential to enhance situational awareness and to ensure transparency, reliability, and predictive capabilities throughout the decision-making process.
Several key components play a critical role in strengthening critical infrastructures against cyberattacks. These include risk assessment, which involves identifying, evaluating, and prioritizing risks; access control mechanisms to prevent unauthorized access and reduce insider threats; incident response capabilities to detect, mitigate, and recover from cybersecurity incidents; resilience building to ensure continuity during and after attacks; and governance and compliance measures to align cybersecurity practices with regulatory requirements and organizational policies [35].
Security requirements for critical infrastructures encompass real-time detection and response to cyberattacks, resilience and recovery capabilities, protection against Advanced Persistent Threats (APTs), and the integrated protection of both information technology (IT) and operational technology (OT) systems [36,37].
For predictive monitoring and real-time response to attacks on critical infrastructures, the adoption of AI and Machine Learning (ML) techniques has become essential. Moreover, the potential use of Generative Artificial Intelligence (GenAI) and Large Language Models (LLMs) is currently being explored. Achieving reliable deployment of such technologies requires significant advancements in XAI and the development of standardized audit mechanisms to ensure transparency, accountability, and regulatory compliance [38,39,40].

3. Materials and Methods

3.1. Overview of eXplainable Artificial Intelligence Methods

XAI refers to a series of methodologies used to transform the outputs of machine learning models, especially “black-box” models, into results that can provide human-comprehensible explanations [41]. The need to explain how AI algorithms work stems from users’ need to trust AI tools and to understand the general AI framework, which is complex and difficult to grasp in terms of the decision-making process [42].
As the concept of XAI continues to evolve, contemporary studies have moved toward multifaceted classification frameworks, as shown in Figure 3.
Depending on the stage (when?) of artificial intelligence application, the possibility of intrinsic interpretability is implemented right from the start of model construction, with a clear understanding of its operating logic—ante-hoc (Latin—“before the event”)—without the need for additional tools to explain it. Examples include models such as linear regression and decision trees.
Conversely, post hoc (Latin: “after the event”) interpretability applies to complex models, such as deep neural networks, that are already trained and require specific tools to analyze and explain how decisions are made.
Related to applicability (what?), the distinction lies between explaining a single prediction—local interpretability—and understanding the logic of the entire model—global interpretability [43,44].
The types of explanations (how?) include aspects such as feature importance—identifying which variables have the greatest impact on the result; example-based explanations using instances from the training dataset as a model; the identification of complex models through a simpler, interpretable model that approximates their behavior; the extraction of a set of logical rules governing the model’s decisions; and the generation of natural language explanations in text form [45].
Classification of XAI methods according to the AI model to which they can be applied identifies two categories: model-agnostic methods, which can be applied to any machine learning model and rely on observing how output predictions change when input data is modified; and model-specific methods, which apply only to a certain class of AI models and exploit the internal structure of those models. Liu et al. [43] emphasize that for inherently transparent models, named “glass-box models”, the priority is not explainability—since they are already interpretable—but rather improving accuracy and performance.
From a data perspective, the need to classify XAI methods stems from the fact that they are functionally different across data types; consequently, the same explainability technique cannot be applied directly across heterogeneous modalities such as images and text.

3.2. LIME, SHAP, and Others Use Cases

Genurio et al. [46] propose an ablative study that compares the performance of deep learning models (MLP—Multilayer Perceptron, CNN—Convolutional Neural Network, LSTM—Long Short-Term Memory), and shallow learning models (DT—Decision Tree, NB—Naive Bayes, LR—Logistic Regression, XGBoost (v.1.7.2), SVM—Support Vector Machine) in detecting network anomalies, Network Intrusion Detection Systems (NIDS). The comparative analysis outlines the performance of deep learning models, in terms of mean accuracy, execution time and security, which are more interpretable and easier to use. The interpretability of AI models used in the NIDS area can be performed using LIME (Local Interpretable Model-Agnostic Explanations) and SHAP methods [42], which are applicable to almost any AI model [19].
Figure 4 illustrates a generic workflow for Network Traffic Monitoring, in which network data traffic is processed by an ML-based NIDS and subsequently interpreted through an XAI method such as LIME or SHAP to produce explained outputs [43].

3.2.1. LIME (Local Interpretable Model-Agnostic Explanations)

This method can be applied to any “black-box” model and focuses on explaining individual predictions by approximating the behavior of the complex model locally, as in Figure 5. Its operating principle is to train a simple, interpretable model by modifying the input data (packets, flows, log entries) around the chosen instance, thereby highlighting each feature’s (ports, IP addresses) contribution to the original prediction via a feature-importance value [43,47]. LIME is used in traffic classification and intrusion detection, often alongside SHAP, to explain model decisions at the local level. Using them together makes them stronger [47,48].

3.2.2. SHAP (SHapley Additive exPlanations)

Unlike the LIME method, the SHAP method works with both agnostic and specific models. The model-agnostic variant is called KernelSHAP, and generally uses many resources to compute the contribution of each feature to the model prediction, with the LIME method being a particular case of KernelSHAP. The so-called TreeSHAP method, optimized specifically for tree-based models, does not use a surrogate model and exploits the internal structure of trees to calculate exact Shapley values with improved computational efficiency [47,49].
Recently, cybersecurity applications have seen an increase in the use of XAI, particularly in network traffic monitoring and intrusion detection. XAI is adopted in modern IDS techniques to improve the interpretability of alerts and reduce false positives. For example, the XAI-IDS framework proposed by Arreche et al. [19] applies XAI techniques that offer multi-faceted and clear explanations about detections from real-world datasets.
The ability of XAI to interpret AI-driven decision-making transforms it into an important tool with an immense potential in a wide variety of applications [8].
Broadly speaking, from the existing literature analyses, undoubtedly SHAP, Figure 6, is considered the most frequently used technique in Network Traffic Analysis, for traffic classification, intrusion detection, and attack classification, while LIME is the next most frequently employed interpretability tool, and it is also used in a significant number of NTA issues [48]. Other relevant XAI methodologies implemented in various research projects and industry with their specific use cases in network traffic management are described in Table 2.

4. Results

To evaluate and monitor the performance of XAI methodologies in scenarios that simulate the complexity of critical digital infrastructures, experiments used systems with complex configurations and diverse network elements. From an infrastructure perspective, two different networks were used as test environments for real-time analysis of the behavior of XAI techniques and methods on network traffic: an Ethernet network with virtualized servers based on the VMware VSphere platform that comprises 150 IT systems, and a Wi-Fi network developed on the Bring Your Own Device (BYOD) concept. The proposed solution is evaluated in a centralized analysis setup. Network traffic is captured from real infrastructures, processed in real time, and analyzed using a Python-based implementation of a Random Forest classifier combined with SHAP for explainability. The experiments are conducted at the network monitoring level, not on terminal devices, and do not assume deployment on resource-constrained endpoints. While the article does not target a specific operational placement (terminal, edge, or cloud), the experimental setup reflects a centralized monitoring architecture consistent with SOC-oriented traffic analysis environments. The network traffic used for experimentation resulted from capturing, filtering, and segmenting the hourly intervals with the highest density of relevant events from the two analyzed networks, comprising approximately 1400 flows from each network, corresponding to 12,240 packets for the secure Ethernet network and 11,460 packets for the BYOD Wi-Fi network.
The corresponding capture for the secure Ethernet network is dominated by benign traffic associated with standard services used in a controlled environment, such as DNS, HTTPS, administrative SSH access, NTP, syslog, and VPN connection maintenance mechanisms. Malicious traffic occurs infrequently and is characterized by isolated scanning events or limited unauthorized authentication attempts. In contrast, the capture on the BYOD Wi-Fi network shows a much wider variety of traffic patterns, generated by the simultaneous use of multiple devices and applications. This includes both benign heterogeneous traffic and a higher density of malicious activity, such as port scans, UDP flood attacks, and repeated SSH authentication attempts.
From a software perspective, the SHAP method was selected to be applied to an AI model, and implemented in the Python programming language, version 3.13.7, with the SKLearn, Scapy, and Shap libraries.

4.1. Network Traffic Processing and Flow Definition

Network traffic is analyzed from PCAP files using the Scapy library for packet parsing. Only packets containing an IP layer are considered. Each packet is characterized by its timestamp, packet length, transport-layer protocol, and, when applicable, source and destination ports.
Packets are aggregated into unidirectional flows defined by the tuple
( I P s r c , I P d s t , p o r t s r c , p o r t d s t , p r o t o c o l ) .
This flow-based aggregation reduces the overall data volume while preserving communication patterns relevant to attack detection. For each flow, cumulative and temporal statistics are maintained, including the timestamps of the first and last packets, the total number of packets, and the total amount of data transferred. For TCP traffic, control flags (SYN, ACK, RST, FIN, PSH, and URG) are explicitly recorded because they provide critical insight into the state and behavior of network connections.

Mathematical Formalization

Let the captured network traffic be represented as an ordered sequence of packets:
P = { p 1 , p 2 , , p N } .
Each packet p i is defined by the tuple:
p i = ( t i , I P s r c i , I P d s t i , p o r t s r c i , p o r t d s t i , p r o t o i , l e n i , f l a g s i ) ,
where t i denotes the packet timestamp, l e n i the packet length, p r o t o i the transport-layer protocol, and f l a g s i the set of TCP control flags when applicable.
Packets are grouped into unidirectional flows according to the equivalence relation:
p i p j ( I P s r c i , I P d s t i , p o r t s r c i , p o r t d s t i , p r o t o i ) = ( I P s r c j , I P d s t j , p o r t s r c j , p o r t d s t j , p r o t o j ) .
Each equivalence class defines a flow F k :
F k = { p i P p i θ k } ,
where
θ k = ( I P s r c , I P d s t , p o r t s r c , p o r t d s t , p r o t o ) .
For each flow F k , the temporal boundaries are defined as:
t s t a r t ( k ) = min p i F k t i , t e n d ( k ) = max p i F k t i ,
resulting in the flow duration:
d u r a t i o n ( k ) = t e n d ( k ) t s t a r t ( k ) .
The total number of packets and total transferred bytes are computed as:
N ( k ) = | F k | , b y t e s ( k ) = p i F k l e n i .
To capture traffic dynamics, rate-based features are defined as:
p k t _ r a t e ( k ) = N ( k ) d u r a t i o n ( k ) + ϵ , b y t e _ r a t e ( k ) = b y t e s ( k ) d u r a t i o n ( k ) + ϵ ,
where ϵ > 0 is a small constant introduced to avoid division by zero.
The average packet length within a flow is given by:
m e a n _ l e n ( k ) = 1 N ( k ) p i F k l e n i .
For TCP flows, the control flag vector is defined as:
f ( k ) = ( # S Y N ( k ) , # A C K ( k ) , # R S T ( k ) , # F I N ( k ) , # P S H ( k ) , # U R G ( k ) ) ,
and ratio-based features are computed to normalize these values with respect to the flow size:
s y n _ r a t i o ( k ) = # S Y N ( k ) N ( k ) , r s t _ r a t i o ( k ) = # R S T ( k ) N ( k ) .
Finally, each flow F k is mapped to a fixed-dimensional feature vector:
x ( k ) = g ( F k ) R M ,
which serves as input to the machine learning classifier and the subsequent explainability analysis.

4.2. Feature Extraction

Following the flow construction process described in the previous section, each network flow is transformed into a fixed-dimensional numerical representation suitable for machine learning-based classification. Feature extraction is performed at the flow level to summarize packet-level information into statistically meaningful descriptors that capture traffic behavior.

4.3. Relevance for Classification and Explainability

The extracted feature set is designed to balance descriptive power and interpretability. Each feature corresponds to a well-defined network characteristic, enabling both accurate classification and post-hoc explainability using SHAP. By operating at the flow level, the feature extraction process reduces noise, improves class separability, and facilitates the interpretation of model decisions in security-critical environments.

4.4. Data Labeling

Flow labeling is based on the source IP address, assuming there are known sources that generate malicious traffic. Each flow is associated with one of the following classes: benign traffic, SYN scan attack, UDP flood attack, or SSH brute-force attack. This approach allows the construction of a labeled dataset for controlled evaluation, but requires prior knowledge of the attack sources. In accordance with the flow construction and feature extraction processes described in the previous sections, each network flow is assigned a class label in order to enable supervised learning and controlled evaluation. Each flow F k is assigned one of the following class labels:
Y = { benign ,   syn _ scan ,   udp _ flood ,   ssh _ bruteforce } .
Let I P s r c ( k ) denote the source IP address of flow F k . The labeling function is defined as:
( F k ) = syn _ scan , if I P s r c ( k ) S s y n , udp _ flood , if I P s r c ( k ) S u d p , ssh _ bruteforce , if I P s r c ( k ) S s s h , benign , otherwise .
Following labeling, each flow is represented as a labeled sample:
( x ( k ) , y ( k ) ) , y ( k ) = ( F k ) ,
and the resulting dataset is defined as:
D = { ( x ( k ) , y ( k ) ) } k = 1 N .
This labeling strategy provides reliable ground truth for supervised classification, but assumes prior knowledge of attack sources in the experimental setup.

4.5. Classification Model

Based on the flow-based representation, extracted features, and labeled dataset introduced in the previous sections, a supervised classification model is employed to discriminate between benign and malicious network traffic. The objective of this stage is to learn a mapping between flow-level feature vectors and traffic classes, enabling automated detection of different attack types.
A Random Forest classifier is selected for its ability to model nonlinear relationships among features, its robustness to noise, and its effectiveness with heterogeneous and potentially imbalanced datasets. All implementation and experiments are conducted in Python.

4.6. Model Formulation

Let each network flow be represented by a feature vector
x ( k ) R M ,
as defined in the feature extraction stage, and let the corresponding class label be
y ( k ) Y ,
where
Y = { benign ,   syn _ scan ,   udp _ flood ,   ssh _ bruteforce } .
The Random Forest classifier learns a decision function
f : R M Y ,
by aggregating the predictions of an ensemble of decision trees trained on random subsets of the training data and feature space.
The labeled dataset is partitioned into training and test sets using a stratified split to preserve class distributions:
D = D t r a i n D t e s t , D t r a i n D t e s t = .
Class imbalance is addressed by incorporating adaptive class weights during training.

4.7. Model Evaluation

The performance of the trained classifier is evaluated on the test set using standard classification metrics derived from the confusion matrix. Let the test dataset be defined as
D t e s t = { ( x ( k ) , y ( k ) ) } k = 1 N .
The confusion matrix C N | Y | × | Y | is defined as:
C i j = k y ( k ) = i f ( x ( k ) ) = j .
Figure 7 presents the confusion matrix for the Random Forest classifier, demonstrating a perfect classification rate across all four traffic categories. The model correctly identified 929 benign instances, 2250 syn_scan attacks, 1731 udp_flood events, and 369 ssh_bruteforce attempts. With all off-diagonal elements set to zero, the classifier achieved 100% accuracy, precision, and recall, indicating that the selected flow-based features provide distinct, non-overlapping signatures for each traffic type in this dataset.
The confusion matrix obtained on the test set, where each sample corresponds to a network flow represented by the feature vector x ( k ) R M . The strictly diagonal structure observed in the matrix indicates that all test samples are correctly classified:
f ( x ( k ) ) = y ( k ) , k { 1 , , N } .
From a mathematical perspective, this result implies a strong separability of the flow-level feature representations in the feature space R M , induced by the aggregation and feature extraction process described in the previous sections. The absence of off-diagonal elements further leads to perfect class-wise precision and recall, as well as an empirical classification risk of
R ^ ( f ) = 1 N k = 1 N I f ( x ( k ) ) y ( k ) = 0 ,
where I ( · ) denotes the indicator function.
These results demonstrate that the proposed flow-based feature representation enables effective discrimination between benign traffic and the attack categories considered in the experimental setup.

4.8. Discussion and Transition to Explainability

Although the confusion matrix in Figure 8 confirms excellent detection performance on the test set, it does not provide insight into the model’s internal decision-making process. In particular, it does not reveal which flow-level features most contribute to classifying different attack types.
To address this limitation, the next section presents an explainable AI (XAI) analysis using SHAP. Using the SHAP library in Python, model predictions are decomposed into feature-level contributions, enabling both global and local interpretation of the Random Forest decisions.

4.9. Explainable Decision Analysis (SHAP)

To interpret the decisions of the trained classification model, the SHAP (SHapley Additive exPlanations) framework is employed. SHAP provides a theoretically grounded approach for attributing a quantitative contribution to each input feature for a given model prediction, based on concepts from cooperative game theory. Given the multiclass nature of the problem, SHAP values are computed and analyzed separately for each traffic class. All explainability results presented in this section are obtained using the SHAP library in Python, applied to the trained Random Forest classifier.

4.9.1. Theoretical Background

Let the classifier output for a given flow-level feature vector x ( k ) R M be denoted by f ( x ( k ) ) . SHAP approximates the model prediction using an additive explanation model of the form:
f ( x ( k ) ) = ϕ 0 + i = 1 M ϕ i ( k ) ,
where ϕ 0 = E [ f ( X ) ] represents the expected model output over a background dataset, and ϕ i ( k ) denotes the Shapley value associated with feature i for flow k. Each Shapley value quantifies a feature’s marginal contribution to the prediction, averaged over all possible feature coalitions.

4.9.2. Global Feature Importance

To interpret the trained classification model’s decisions, a SHAP-based analysis is used to quantify the contribution of each flow-level feature to the model output. At the global level, feature importance is assessed by computing the mean absolute SHAP value for each feature:
I i = 1 N k = 1 N ϕ i ( k ) ,
where ϕ i ( k ) denotes the SHAP value associated with feature i for flow k, and N is the number of flows in the test set.

4.10. Short Comparative Graphical Analysis of Secure Ethernet and BYOD Wi-Fi Traffic

To avoid visual overload and preserve interpretability, only a representative subset of traffic classes was selected for detailed graphical analysis. The benign class was included as a reference baseline, while SYN scan and SSH brute-force attacks were chosen due to their distinct operational characteristics. SYN scans exhibit highly structured traffic patterns, whereas SSH brute-force traffic often overlaps with legitimate administrative activity, particularly in BYOD environments.

4.10.1. Confusion Matrix Comparison

The confusion matrices displayed above in Figure 8 depict the level of accuracy by which a model classifies network traffic upon the following criteria: benign, sys_scan, udp_flood, and ssh_bruteforce. The comparison analyzes model performance across two network environments applicable to digital critical infrastructures. While the left matrix indicates a disorganized environment with higher noise and an accuracy of 0.973, the right matrix shows a controlled, organized environment with higher accuracy. Moreover, the secure Ethernet network traffic scenario shows near-perfect classification with negligible confusion between classes.
In contrast, the BYOD Wi-Fi network traffic scenario shows increased misclassification, primarily between benign traffic and low-intensity attacks. This difference reflects the higher variability and lower predictability of wireless BYOD traffic, as shown in Figure 8, whereas Ethernet traffic is characterized by greater stability and higher predictability. In standardized, secure networks, consistent normal traffic makes anomalies easier to detect, unlike the unpredictable patterns in public or BYOD environments, where occasionally flagged safe traffic can be considered uncertain.

4.10.2. Global Feature Importance (SHAP)

The figures below analyze data traffic volume to identify benign traffic, TCP protocol behavior to detect scans (SYS scans), and traffic intensity and speed to recognize brute-force attacks. In the secure Ethernet scenario, presented in Figure 9, classification decisions are dominated by a small set of features, such as SYN ratio, packet rate, and flow duration.
In the BYOD Wi-Fi scenario, as shown in Figure 10, feature importance is more evenly distributed, indicating reduced discriminative power due to heterogeneous device behavior.

4.10.3. SHAP Summary and Local Explanations

SHAP summary and waterfall plots, depicted in Figure 11, show minimal feature overlap in the secure Ethernet scenario, enabling clear decision boundaries. Conversely, for the BYOD Wi-Fi traffic, Figure 12 exhibits significant overlap between benign and attack-related feature values, leading to competing feature contributions and ambiguous decisions.
The difference in feature importance profiles between the Ethernet and the Wi-Fi network datasets reflects how the model’s decision boundaries are influenced by the traffic characteristics produced within each topology, rather than by any adaptive behavior of the model itself. In the Wi-Fi dataset, certain characteristics appear to be more influential because wireless communication introduces greater variability in packet timing characteristics (e.g., retransmissions, delays caused by collisions, and channel interference effects). This variability increases the relative discriminatory power of specific flow-level features, not because Wi-Fi is inherently “noisy,” but because the statistical properties of packet timing differ from those observed in wired Ethernet. SYN Scan detection remains stable, with syn_ratio as a predictor in both environments, confirming that TCP-level protocol anomalies are indicators independent of the physical network support. In the case of brute-force attacks, differences arise between the two infrastructures. While in Secure Ethernet the model is based on pkt_rate and duration, identifying the attack by the intensity of the packet flow, in BYOD Wi-Fi the focus shifts to the destination port (dport) and the byte rate (byte_rate). The higher importance of packet-frequency-related features in the Wi-Fi dataset indicates that the model is based on those variables that best capture the specific variations in traffic patterns in this dataset, rather than on any adaptive mechanism or change in the analysis method. In conclusion, the model maintains high intrusion detection accuracy, but in environments such as BYOD Wi-Fi it requires additional calibration to reduce the rate of false alarms caused by the diversity of legitimate traffic. The model’s ability to recalibrate features in unstable environments confirms the flexibility of machine learning-based architecture in the face of modern network challenges.
Feature-importance analysis has concrete practical value in network-traffic monitoring, especially in operational and security-focused environments. It helps analysts understand why a model raises an alert and which traffic attributes most strongly contribute to detecting malicious behavior. This improves transparency, supports rapid incident triage, and reduces false-positive investigations by highlighting the most influential flow characteristics.
From an operational perspective, feature-importance results guide security teams in: prioritizing relevant features when monitoring high-volume traffic, interpreting model decisions, and validating whether detected anomalies reflect genuine threats, identifying patterns associated with specific attacks (e.g., unusual packet rates, abnormal port usage, or atypical flow durations), optimizing monitoring configurations, and focusing on features that consistently contribute to accurate detections.
Overall, feature-importance analysis enhances both explainability and operational usability of machine-learning-based network-security systems, enabling more informed and defensible cybersecurity decisions.
The experimental results demonstrated that the transition from “black-box” models to transparent systems enables not only proactive threat detection but also the validation of human-operator decisions, thereby strengthening trust in automated security processes.
The SHAP tool is a useful, versatile instrument for error analysis, compatible with a wide variety of models, including tree-based, linear, and deep learning models, and it provides both local and global explanations that are easy to interpret and implement.
Specifically, this article applies the SHAP method to an ML framework based on a random forest classifier, which accurately identifies the characteristics that determine specific attacks, i.e., the SYN packet ratio for scan attacks and the destination port combined with the packet rate for SSH brute-force attacks. For operational decisions in SOC, a major advantage is the integration of explanations, which reduces mean time to response (MTTR) by eliminating the need for laborious manual alert validation, allowing analysts to focus on threats with major impact.
Moreover, in less controlled environments, XAI techniques are essential for distinguishing genuine traffic fluctuations from malicious anomalies.
Another significant advantage of this approach is its robust ability to interpret and visualize the resulting data, offering unparalleled flexibility. This is achieved by using diverse, customizable plots and graphical representations. These visualization tools are essential for transforming complex numerical outputs into easily digestible and insightful formats. For instance, basic statistical summaries can be augmented with detailed histograms to show data distribution, scatter plots to illustrate relationships between variables, or sophisticated heatmaps and 3D plots for multivariate analysis. Selecting the most appropriate plot can dramatically enhance understanding of the underlying phenomena, allowing researchers and analysts to quickly identify trends, anomalies, and critical patterns that might be obscured in raw data tables. This interpretive power is crucial for effective decision-making and for communicating findings clearly to a broad audience, regardless of their technical background.
Although the use of private data can provide valuable insights for automated decision-making, its handling requires rigorous management and strict security protocols to prevent exposure to vulnerabilities or cyberattacks. The absence of clear guidelines for handling sensitive information increases the risk of compromising confidentiality, underscoring the need for XAI methods that prioritize data protection alongside system accuracy and predictability.
Despite the identified advantages, implementing XAI must account for the real challenges of resource consumption, increased computational time, and providing explanations in easily understandable forms for user groups with varying levels of training.

5. Conclusions

This research demonstrates that integrating XAI methods into network traffic monitoring is essential for securing critical digital infrastructures. The goal of this paper was to analyze alert interpretability and reduce false positives by applying the SHAP method to real-time traffic datasets from two networks. The comparative analysis demonstrates that secure Ethernet networks offer greater predictability and clearer decision boundaries, whilst BYOD Wi-Fi environments are more random. In less controlled scenarios, XAI methods become indispensable for differentiating legitimate traffic variability from malicious anomalies. In conclusion, a recommended solution for digital critical infrastructures with high security requirements is to adopt an Ethernet network. Despite the identified advantages, implementing XAI must account for the real challenges of resource consumption and providing explanations in easily understandable forms for user groups with varying levels of training. Thus, the SHAP XAI solution offers predictability, accuracy, and formal interpretability. A multilevel framework that tailors explainability across all levels can certainly be developed by integrating it with Large Language Model-based approaches, making it much more accessible to end users. Among future directions for development, we consider integrating LLM approaches with XAI methods and deploying and assessing these techniques in other critical environments, such as secure radio networks, cloud computing, and edge computing. In terms of network-security analysis, the diversification of the types of cyberattacks on network traffic is another venue for LLM-XAI-based behavior analysis.

Supplementary Materials

The following supporting information can be downloaded at: https://www.mdpi.com/article/10.3390/telecom7020034/s1.

Author Contributions

Conceptualization, C.-E.B. and G.C.; methodology, C.-E.B. and G.C.; software, E.-G.R.-V. and I.-N.M.; validation, E.-G.R.-V. and I.-N.M.; formal analysis, C.-E.B. and G.C.; investigation, C.-E.B., G.C. and E.-G.R.-V.; resources, C.-E.B., G.C. and E.-G.R.-V.; data curation, I.-N.M.; writing—original draft preparation, C.-E.B., G.C. and E.-G.R.-V.; writing—review and editing, A.R.; visualization, C.-E.B., G.C. and E.-G.R.-V.; supervision, A.R.; project administration, A.R. All authors have read and agreed to the published version of the manuscript.

Funding

This research received no external funding.

Institutional Review Board Statement

Not applicable for studies not involving humans or animals.

Informed Consent Statement

Not applicable.

Data Availability Statement

The original contributions presented in this study are included in the Supplementary Materials. Further inquiries can be directed to the corresponding authors. This research is limited to explainable artificial intelligence and civilian network traffic monitoring, with the aim of improving transparency, accountability, and trust in cybersecurity systems used in commercial and public digital infrastructures. The proposed methods are intended for defensive and diagnostic purposes and do not pose a threat to public health or national security. The authors acknowledge the potential dual-use nature of network monitoring technologies and confirm that all necessary precautions have been taken to prevent misuse. As an ethical responsibility, the authors strictly adhere to relevant national and international regulations governing dual-use research of concern (DURC) and advocate for responsible deployment, regulatory compliance, ethical oversight, and transparent reporting to mitigate risks of misuse and promote beneficial outcomes.

Conflicts of Interest

The authors declare no conflicts of interest.

References

  1. Hao, H.; Xu, C.; Zhang, W.; Chen, X.; Yang, S.; Muntean, G.M. Reliability-Aware Optimization of Task Offloading for UAV-Assisted Edge Computing. IEEE Trans. Comput. 2025, 74, 3832–3844. [Google Scholar] [CrossRef]
  2. Tang, B.; Du, S.; Smith, A.J. A Review on AI Miniaturization: Trends and Challenges. Appl. Sci. 2025, 15, 958. [Google Scholar] [CrossRef]
  3. Boussetta, M.; Ababou, M.; Faquir, S.; Rabiai, S. Artificial Intelligence and Digital Infrastructure for Sustainable Industry and Enhanced Corporate Performance: A Bibliometric Analysis of Smart Optimization Technologies. In Proceedings of the Innovative Technologies on Electrical Power Systems for Smart Cities Infrastructure; Aboudrar, I., Ilahi Bakhsh, F., Nayyar, A., Ouachtouk, I., Eds.; Springer: Cham, Switzerland, 2025; pp. 93–102. [Google Scholar]
  4. Chen, X.; Wang, X.; Colacelli, A.; Lee, M.; Xie, L. Electricity Demand and Grid Impacts of AI Data Centers: Challenges and Prospects. arXiv 2025, arXiv:2509.07218. [Google Scholar] [CrossRef]
  5. Rashid, A.B.; Kausik, M.A.K. AI revolutionizing industries worldwide: A comprehensive overview of its diverse applications. Hybrid Adv. 2024, 7, 100277. [Google Scholar] [CrossRef]
  6. Dwivedi, Y.K.; Sharma, A.; Rana, N.P.; Giannakis, M.; Goel, P.; Dutot, V. Evolution of artificial intelligence research in Technological Forecasting and Social Change: Research topics, trends, and future directions. Technol. Forecast. Soc. Change 2023, 192, 122579. [Google Scholar] [CrossRef]
  7. Rjoub, G.; Bentahar, J.; Abdel Wahab, O.; Mizouni, R.; Song, A.; Cohen, R.; Otrok, H.; Mourad, A. A Survey on Explainable Artificial Intelligence for Cybersecurity. IEEE Trans. Netw. Serv. Manag. 2023, 20, 5115–5140. [Google Scholar] [CrossRef]
  8. Srivastava, G.; Jhaveri, R.H.; Bhattacharya, S.; Pandya, S.; Rajeswari; Maddikunta, P.K.R.; Yenduri, G.; Hall, J.G.; Alazab, M.; Gadekallu, T.R. XAI for Cybersecurity: State of the Art, Challenges, Open Issues and Future Directions. arXiv 2022, arXiv:2206.03585. [Google Scholar] [CrossRef]
  9. Moyle, S.; Martin, A.; Allott, N. XAI Human-Machine collaboration applied to network security. Front. Comput. Sci. 2024, 6, 1321238. [Google Scholar] [CrossRef]
  10. Aysel, H.I.; Cai, X.; Prugel-Bennett, A. Explainable Artificial Intelligence: Advancements and Limitations. Appl. Sci. 2025, 15, 7261. [Google Scholar] [CrossRef]
  11. Achuthan, K.; Ramanathan, S.; Srinivas, S.; Raman, R. Advancing cybersecurity and privacy with artificial intelligence: Current trends and future research directions. Front. Big Data 2024, 7, 1497535. [Google Scholar] [CrossRef]
  12. Masud, M.T.; Keshk, M.; Moustafa, N.; Linkov, I.; Emge, D.K. Explainable Artificial Intelligence for Resilient Security Applications in the Internet of Things. IEEE Open J. Commun. Soc. 2025, 6, 2877–2906. [Google Scholar] [CrossRef]
  13. Wawrowski, Ł.; Michalak, M.; Białas, A.; Kurianowicz, R.; Sikora, M.; Uchroński, M.; Kajzer, A. Detecting anomalies and attacks in network traffic monitoring with classification methods and XAI-based explainability. Procedia Comput. Sci. 2021, 192, 2259–2268. [Google Scholar] [CrossRef]
  14. Singh, K.; Kashyap, A.; Cherukuri, A.K. Interpretable Anomaly Detection in Encrypted Traffic Using SHAP with Machine Learning Models. arXiv 2025, arXiv:2505.16261. [Google Scholar] [CrossRef]
  15. ARAMIDE, O.O. Explainable AI (XAI) for Network Operations and Troubleshooting. Int. J. Res. Publ. Semin. 2025, 16, 533–554. [Google Scholar] [CrossRef]
  16. Rajagopalan, N. Federated learning and explainable AI-driven intrusion detection with hyperband optimization. J. Comput. Virol. Hacking Tech. 2025, 21, 1–25. [Google Scholar] [CrossRef]
  17. Ayoub, O.; Di Cicco, N.; Ezzeddine, F.; Bruschetta, F.; Rubino, R.; Nardecchia, M.; Milano, M.; Musumeci, F.; Passera, C.; Tornatore, M. Explainable Artificial Intelligence in communication networks: A use case for failure identification in microwave networks. Comput. Netw. 2022, 219, 109466. [Google Scholar] [CrossRef]
  18. Nascita, A.; Montieri, A.; Aceto, G.; Ciuonzo, D.; Persico, V.; Pescapé, A. Improving Performance, Reliability, and Feasibility in Multimodal Multitask Traffic Classification with XAI. IEEE Trans. Netw. Serv. Manag. 2023, 20, 1267–1289. [Google Scholar] [CrossRef]
  19. Arreche, O.; Guntur, T.; Abdallah, M. XAI-IDS: Toward Proposing an Explainable Artificial Intelligence Framework for Enhancing Network Intrusion Detection Systems. Appl. Sci. 2024, 14, 4170. [Google Scholar] [CrossRef]
  20. Arreche, O.; Guntur, T.; Abdallah, M. XAI-based Feature Selection for Improved Network Intrusion Detection Systems. arXiv 2024, arXiv:2410.10050. [Google Scholar] [CrossRef]
  21. Morichetta, A.; Casas, P.; Mellia, M. EXPLAIN-IT: Towards Explainable AI for Unsupervised Network Traffic Analysis. In Proceedings of the 3rd ACM CoNEXT Workshop on Big DAta, Machine Learning and Artificial Intelligence for Data Communication Networks, Big-DAMA ’19, Orlando, FL, USA, 9 December 2019; pp. 22–28. [Google Scholar] [CrossRef]
  22. Barnard, P.; Marchetti, N.; DaSilva, L.A. Robust Network Intrusion Detection Through Explainable Artificial Intelligence (XAI). IEEE Netw. Lett. 2022, 4, 167–171. [Google Scholar] [CrossRef]
  23. Altaf, T.; Wang, X.; Ni, W.; Yu, G.; Liu, R.P.; Braun, R. GNN-Based Network Traffic Analysis for the Detection of Sequential Attacks in IoT. Electronics 2024, 13, 2274. [Google Scholar] [CrossRef]
  24. Lakhina, A.; Crovella, M.; Diot, C. Mining anomalies using traffic feature distributions. In Proceedings of the 2005 Conference on Applications, Technologies, Architectures, and Protocols for Computer Communications, SIGCOMM ’05, Philadelphia, PA, USA, 22–26 August 2005; pp. 217–228. [Google Scholar] [CrossRef]
  25. Ness, S.; Eswarakrishnan, V.; Sridharan, H.; Shinde, V.; Venkata Prasad Janapareddy, N.; Dhanawat, V. Anomaly Detection in Network Traffic Using Advanced Machine Learning Techniques. IEEE Access 2025, 13, 16133–16149. [Google Scholar] [CrossRef]
  26. Alwhbi, I.A.; Zou, C.C.; Alharbi, R.N. Encrypted Network Traffic Analysis and Classification Utilizing Machine Learning. Sensors 2024, 24, 3509. [Google Scholar] [CrossRef] [PubMed]
  27. Yaseen, N. From Counters to Telemetry: A Survey of Programmable Network-Wide Monitoring. Network 2025, 5, 38. [Google Scholar] [CrossRef]
  28. Gutiérrez-Galeano, L.; Domínguez-Jiménez, J.J.; Schäfer, J.; Medina-Bulo, I. LLM-Based Cyberattack Detection Using Network Flow Statistics. Appl. Sci. 2025, 15, 6529. [Google Scholar] [CrossRef]
  29. Liu, H.; Wang, X.; He, F.; Zheng, Z. Automated Network Defense: A Systematic Survey and Analysis of AutoML Paradigms for Network Intrusion Detection. Appl. Sci. 2025, 15, 389. [Google Scholar] [CrossRef]
  30. Xu, Z.; Liu, Y. Robust Anomaly Detection in Network Traffic: Evaluating Machine Learning Models on CICIDS2017. arXiv 2025, arXiv:2506.19877. [Google Scholar] [CrossRef]
  31. Zambare, P.; Thanikella, V.N.; Kottur, N.P.; Akula, S.A.; Liu, Y. NetMoniAI: An Agentic AI Framework for Network Security & Monitoring. In Proceedings of the 2025 3rd International Conference on Artificial Intelligence, Blockchain, and Internet of Things (AIBThings), Mt Pleasant, MI, USA, 6–7 September 2025; pp. 1–6. [Google Scholar]
  32. Hammoudeh, M.; Epiphaniou, G.; Pinto, P. Cyber-Physical Systems: Security Threats and Countermeasures. J. Sens. Actuator Netw. 2023, 12, 18. [Google Scholar] [CrossRef]
  33. Matey, H.A.; Danquah, P.; Koi-Akrofi, G.Y.; Asampana, I. Critical Infrastructure Cybersecurity Challenges: IoT In Perspective. Int. J. Netw. Secur. Its Appl. (IJNSA) 2021, 13, 41–58. [Google Scholar] [CrossRef]
  34. Ghafir, I.; Saleem, J.; Hammoudeh, M.; Faour, H.; Prenosil, V.; Jaf, S.; Jabbar, S.; Baker, T. Security threats to critical infrastructure: The human factor. J. Supercomput. 2018, 74, 4986–5002. [Google Scholar] [CrossRef]
  35. Alozie, C.; Eze, E. Developing a Cybersecurity Framework for Protecting Critical Infrastructure in Organizations. Iconic Res. Eng. J. 2024, 8, 562–576. [Google Scholar] [CrossRef]
  36. Aghazadeh Ardebili, A.; Lezzi, M.; Pourmadadkar, M. Risk Assessment for Cyber Resilience of Critical Infrastructures: Methods, Governance, and Standards. Appl. Sci. 2024, 14, 11807. [Google Scholar] [CrossRef]
  37. Paulraj, J.; Raghuraman, B.; Gopalakrishnan, N.; Otoum, Y. Autonomous AI-based Cybersecurity Framework for Critical Infrastructure: Real-Time Threat Mitigation. In Proceedings of the 2025 IEEE/ACIS 29th International Conference on Software Engineering, Artificial Intelligence, Networking and Parallel/Distributed Computing (SNPD), Busan, Republic of Korea, 25–27 June 2025; pp. 925–931. [Google Scholar] [CrossRef]
  38. Maglaras, L.; Janicke, H.; Ferrag, M.A. Cybersecurity of Critical Infrastructures: Challenges and Solutions. Sensors 2022, 22, 5105. [Google Scholar] [CrossRef] [PubMed]
  39. Lubis, M.; Safitra, M.F.; Fakhrurroja, H.; Muttaqin, A.N. Guarding Our Vital Systems: A Metric for Critical Infrastructure Cyber Resilience. Sensors 2025, 25, 4545. [Google Scholar] [CrossRef] [PubMed]
  40. Yigit, Y.; Ferrag, M.A.; Ghanem, M.C.; Sarker, I.H.; Maglaras, L.A.; Chrysoulas, C.; Moradpoor, N.; Tihanyi, N.; Janicke, H. Generative AI and LLMs for Critical Infrastructure Protection: Evaluation Benchmarks, Agentic AI, Challenges, and Opportunities. Sensors 2025, 25, 1666. [Google Scholar] [CrossRef]
  41. Mehta, M.; Palade, V.; Chatterjee, I. Explainable AI: Foundations, Methodologies and Applications; Springer International Publishing: Berlin/Heidelberg, Germany, 2023. [Google Scholar] [CrossRef]
  42. Hermosilla, P.; Berríos, S.; Allende-Cid, H. Explainable AI for Forensic Analysis: A Comparative Study of SHAP and LIME in Intrusion Detection Models. Appl. Sci. 2025, 15, 7329. [Google Scholar] [CrossRef]
  43. Liu, X.; Huang, D.; Yao, J.; Dong, J.; Song, L.; Wang, H.; Yao, C.; Chu, W. From Black Box to Glass Box: A Practical Review of Explainable Artificial Intelligence (XAI). AI 2025, 6, 285. [Google Scholar] [CrossRef]
  44. Bilal, A.; Ebert, D.; Lin, B. LLMs for Explainable AI: A Comprehensive Survey. arXiv 2025, arXiv:2504.00125. [Google Scholar] [CrossRef]
  45. Raj, M. Clarifying Model Transparency: Interpretability versus Explainability in Deep Learning with MNIST and IMDB Examples. arXiv 2025, arXiv:2509.10929. [Google Scholar] [CrossRef]
  46. Genuario, F.; Santoro, G.; Giliberti, M.; Bello, S.; Zazzera, E.; Impedovo, D. Machine Learning-Based Methodologies for Cyber-Attacks and Network Traffic Monitoring: A Review and Insights. Information 2024, 15, 741. [Google Scholar] [CrossRef]
  47. Devireddy, K. A Comparative Study of Explainable AI Methods: Model-Agnostic vs. Model-Specific Approaches. arXiv 2025, arXiv:2504.04276. [Google Scholar] [CrossRef]
  48. Nascita, A.; Aceto, G.; Ciuonzo, D.; Montieri, A.; Persico, V.; Pescapé, A. A Survey on Explainable Artificial Intelligence for Internet Traffic Classification and Prediction, and Intrusion Detection. IEEE Commun. Surv. Tutor. 2025, 27, 3165–3198. [Google Scholar] [CrossRef]
  49. Yang, J. Fast TreeSHAP: Accelerating SHAP Value Computation for Trees. arXiv 2021, arXiv:2109.09847. [Google Scholar] [CrossRef]
  50. Ponraj, R.; Durairajan, R.; Wang, Y. Building Transparency in Deep Learning-Powered Network Traffic Classification: A Traffic-Explainer Framework. arXiv 2025, arXiv:2509.18007. [Google Scholar] [CrossRef]
  51. Qureshi, A.U.H.; Larijani, H.; Yousefi, M.; Adeel, A.; Mtetwa, N. An Adversarial Approach for Intrusion Detection Systems Using Jacobian Saliency Map Attacks (JSMA) Algorithm. Computers 2020, 9, 58. [Google Scholar] [CrossRef]
  52. Galwaduge, V.; Samarabandu, J. Novel Actionable Counterfactual Explanations for Intrusion Detection Using Diffusion Models. J. Cybersecur. Priv. 2025, 5, 68. [Google Scholar] [CrossRef]
  53. Fumagalli, F.; Muschalik, M.; Hüllermeier, E.; Hammer, B. Incremental permutation feature importance (iPFI): Towards online explanations on data streams. Mach. Learn. 2023, 112, 4863–4903. [Google Scholar] [CrossRef]
  54. Ullah, I.; Rios, A.; Gala, V.; Mckeever, S. Explaining Deep Learning Models for Tabular Data Using Layer-Wise Relevance Propagation. Appl. Sci. 2022, 12, 136. [Google Scholar] [CrossRef]
  55. Binder, A.; Montavon, G.; Lapuschkin, S.; Müller, K.R.; Samek, W. Layer-Wise Relevance Propagation for Neural Networks with Local Renormalization Layers. In Proceedings of the Artificial Neural Networks and Machine Learning–ICANN 2016, Barcelona, Spain, 6–9 September 2016; Villa, A.E., Masulli, P., Pons Rivero, A.J., Eds.; Springer: Cham, Switzerland, 2016; pp. 63–71. [Google Scholar]
  56. Muschalik, M.; Fumagalli, F.; Jagtani, R.; Hammer, B.; Hüllermeier, E. iPDP: On Partial Dependence Plots in Dynamic Modeling Scenarios. In Proceedings of the Explainable Artificial Intelligence; Longo, L., Ed.; Springer: Cham, Switzerland, 2023; pp. 177–194. [Google Scholar]
  57. Biradar, J.; Shah, S.; Naik, T. Attention Augmented GNN RNN-Attention Models for Advanced Cybersecurity Intrusion Detection. arXiv 2025, arXiv:2510.25802. [Google Scholar] [CrossRef]
  58. Nishino, S.; Shiraishi, T.; Katsuoka, T.; Takeuchi, I. Statistical Test for Saliency Maps of Graph Neural Networks via Selective Inference. arXiv 2025, arXiv:2505.16893. [Google Scholar] [CrossRef]
Figure 1. Stages of Artificial Intelligence evolution and associated outcomes (adapted from [2]).
Figure 1. Stages of Artificial Intelligence evolution and associated outcomes (adapted from [2]).
Telecom 07 00034 g001
Figure 2. Levels of Artificial Intelligence progression in cybersecurity, highlighting human–AI involvement and associated benefits/risks.
Figure 2. Levels of Artificial Intelligence progression in cybersecurity, highlighting human–AI involvement and associated benefits/risks.
Telecom 07 00034 g002
Figure 3. XAI methods taxonomy.
Figure 3. XAI methods taxonomy.
Telecom 07 00034 g003
Figure 4. Workflow of Network Traffic Monitoring.
Figure 4. Workflow of Network Traffic Monitoring.
Telecom 07 00034 g004
Figure 5. LIME-based explainability workflow for Network Intrusion Detection Systems.
Figure 5. LIME-based explainability workflow for Network Intrusion Detection Systems.
Telecom 07 00034 g005
Figure 6. Workflow of SHAP method.
Figure 6. Workflow of SHAP method.
Telecom 07 00034 g006
Figure 7. Confusion matrix of the Random Forest classifier evaluated on the test dataset, illustrating class-wise detection performance for flow-based traffic classification.
Figure 7. Confusion matrix of the Random Forest classifier evaluated on the test dataset, illustrating class-wise detection performance for flow-based traffic classification.
Telecom 07 00034 g007
Figure 8. (a) Confusion matrix for BYOD Wi-Fi network traffic. (b) Confusion matrix for Secure Ethernet network traffic.
Figure 8. (a) Confusion matrix for BYOD Wi-Fi network traffic. (b) Confusion matrix for Secure Ethernet network traffic.
Telecom 07 00034 g008
Figure 9. Global SHAP feature importance for: (a) benign, (b) SYN scan, (c) SSH brute-force classes (Secure Ethernet).
Figure 9. Global SHAP feature importance for: (a) benign, (b) SYN scan, (c) SSH brute-force classes (Secure Ethernet).
Telecom 07 00034 g009
Figure 10. Global SHAP feature importance for: (a) benign, (b) SYN scan, (c) SSH brute-force classes (BYOD Wi-Fi).
Figure 10. Global SHAP feature importance for: (a) benign, (b) SYN scan, (c) SSH brute-force classes (BYOD Wi-Fi).
Telecom 07 00034 g010
Figure 11. (a) SHAP summary (b) waterfall plots for SSH brute-force traffic (Secure Ethernet).
Figure 11. (a) SHAP summary (b) waterfall plots for SSH brute-force traffic (Secure Ethernet).
Telecom 07 00034 g011
Figure 12. (a) SHAP summary (b) waterfall plots for SSH brute-force traffic (BYOD Wi-Fi).
Figure 12. (a) SHAP summary (b) waterfall plots for SSH brute-force traffic (BYOD Wi-Fi).
Telecom 07 00034 g012
Table 1. Representative XAI methods and techniques applied to networking-related tasks.
Table 1. Representative XAI methods and techniques applied to networking-related tasks.
ReferencesXAI TechniqueNetworking TaskDevelopment Level
[13]XAI SHAPAnomaly detection in network trafficRandom Forests (RF), Neural Networks (NN), Logistic Regression (GLM), and Gradient Boosting (GBM) applied for anomaly and attacks detection in LAN infrastructures, using the RegSOC-KES2021 dataset; XAI is used to validate feature importance.
[14]XAI SHAPAnomaly detection in encrypted network trafficXGBoost, Random Forest, and Isolation Forest, applied on encrypted network traffic datasets including Tor-based encrypted traffic with diverse attacks like botnets and port scans (CIC-Darknet2020), TLS-encrypted flows (USTC-TFC2016), and encrypted attack scenarios in a realistic enterprise setting (CSE-CIC-IDS2018).
[15]XAI SHAP/LIMETroubleshooting network operationsLSTM Autoencoder for anomaly detection and Gradient Boosting Trees (GBRT) for predictive congestion control applied to generated traffic using a synthetic distributed training workload based on the MLPerf GPT-like benchmark; XAI is used for evaluating the fidelity metrics and to ensure the correctness of explanations in network operations.
[16]XAI LIME/SHAPNetwork Intrusion Detection Systems (IDS)Hybrid system combining Federated Learning (FL) for privacy with Hyperband-based optimization and XAI for interpretability, applied to the CICIDS2017 and CICIDS2018 datasets for intrusion detection in distributed environments.
[17]XAI SHAPAutomated failure-cause identification in microwave networksArtificial Neural Network (ANN), Random Forest (RF), and Extreme Gradient Boosting (XGB) applied on hand-labeled data by domain experts.
[18]XAI-based multimodal multitaskNetwork traffic classificationMultimodal multitask deep learning model applied to the ISCX VPN-nonVPN dataset for traffic classification (streaming, VoIP, file transfer, Email), using XAI for interpreting decisions between multiple tasks.
[19]XAI LIME/SHAPNetwork intrusion detectionBlack-box AI classification models, for intrusion detection, applied on RoEduNet-SIMARGL2021, CICIDS-2017, and NSL-KDD dataset, emphasizing transparency through both local and global interpretability.
[20]XAI SHAPNetwork intrusion detectionk-nearest neighbors (KNN), LightGBM, Adaptive Boosting (AdaBoost), support vector machine (SVM), random forest (RF), deep neural network (DNN), and multi-layer perceptron (MLP) using the CICIDS-2017 and RoEduNet-SIMARGL2021 datasets, optimized to identify critical attack vectors in high-speed network traffic.
[21]EXPLAIN-IT (unsupervised learning-based model)Media content in large repositories under encrypted traffic scenariosSoftware-implemented for unsupervised learning model, classifying multimedia content in encrypted streams and providing interpretative evidence for traffic management decisions.
[22]XAI SHAPSupervised network intrusion detection with Extreme Gradient Boosting (XGBoost)XGBoost algorithm applied to the NSL-KDD dataset, using SHAP to rank the characteristics of data packets that contribute most to identifying cyber attacks.
Table 2. XAI methodologies and their use cases in intrusion detection systems.
Table 2. XAI methodologies and their use cases in intrusion detection systems.
MethodologyUse CaseReference
Traffic-ExplainerDeep learning traffic classification: A model-agnostic, input-perturbation-based framework designed to explain complex traffic classifiers (e.g., Transformers and Graph Neural Networks) by identifying influential bytes and traffic patterns.[50]
Saliency Maps (JSMA)Adversarial robustness: Jacobian-based saliency maps are used to craft and analyze adversarial samples in intrusion detection systems, highlighting features that maximize perturbation impact and increase prediction confidence.[51]
Counterfactual ExplanationsActionable intrusion defence: Generates actionable explanations by identifying the minimal feature changes required to reclassify malicious network flows as benign, providing insight into attack decision boundaries.[52]
Incremental Permutation Feature Importance (iPFI)Real-time data streams: An incremental variant of permutation feature importance that enables online explanations of model behavior in streaming and non-stationary network-traffic environments.[53]
Layer-Wise Relevance Propagation (LRP)Deep learning forensics: Explains deep neural networks for tabular data by propagating relevance scores from the model output back to the input features, supporting forensic network traffic analysis.[54,55]
Incremental Partial Dependence Plots (iPDP)Concept drift analysis: Extends partial dependence plots to dynamic modeling scenarios, allowing visualization of feature effects over time in evolving network traffic.[56]
Attention MechanismsComplex attack detection: Attention-augmented architectures (e.g., GNN–RNN–Attention models) dynamically weight temporal and structural information, improving interpretability for DDoS and APT detection.[57]
Graph-Based SaliencyGNN interpretability: A statistically grounded saliency testing framework for graph neural networks that identifies statistically significant subgraphs with selective inference guarantees.[58]
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.

Share and Cite

MDPI and ACS Style

Bucur, C.-E.; Crihan, G.; Rădoi, A.; Robe-Voinea, E.-G.; Moroșan, I.-N. Enhancing Network Traffic Monitoring Through eXplainable Artificial Intelligence Methodologies. Telecom 2026, 7, 34. https://doi.org/10.3390/telecom7020034

AMA Style

Bucur C-E, Crihan G, Rădoi A, Robe-Voinea E-G, Moroșan I-N. Enhancing Network Traffic Monitoring Through eXplainable Artificial Intelligence Methodologies. Telecom. 2026; 7(2):34. https://doi.org/10.3390/telecom7020034

Chicago/Turabian Style

Bucur, Cătălin-Eugen, Georgiana Crihan, Anamaria Rădoi, Elena-Grațiela Robe-Voinea, and Iustin-Nicolae Moroșan. 2026. "Enhancing Network Traffic Monitoring Through eXplainable Artificial Intelligence Methodologies" Telecom 7, no. 2: 34. https://doi.org/10.3390/telecom7020034

APA Style

Bucur, C.-E., Crihan, G., Rădoi, A., Robe-Voinea, E.-G., & Moroșan, I.-N. (2026). Enhancing Network Traffic Monitoring Through eXplainable Artificial Intelligence Methodologies. Telecom, 7(2), 34. https://doi.org/10.3390/telecom7020034

Article Metrics

Back to TopTop