Analyzing encrypted traffic analysis using explainable AI
DOI:
https://doi.org/10.56947/amcs.v31.660Keywords:
Explainable AI, Machine Learning, LIME, Network traffic Classification, SHAPAbstract
The increasing reliance on machine learning (ML) for network traffic classification highlights a critical need for not only predictive accuracy but also transparent, interpretable models that foster trust and accountability in cybersecurity applications. This study presents a reproducible framework that applies tree-based and kernel-based classifiers—Random Forest, Decision Tree, and Support Vector Machine—to widely used VPN, phishing, and botnet traffic datasets. By systematically integrating both SHAP (SHapley Additive exPlanations) and LIME (Local Interpretable Model-Agnostic Explanations), we provide detailed, actionable insights into model decision processes and dominant feature contributions. Unlike prior works, our approach consolidates and validates established domain knowledge while mapping global and local model explanations to specific network protocol behaviors and attack vectors. Furthermore, we discuss the practical implications of our findings for feature engineering and lightweight model design. While the use of legacy datasets offers continuity with existing benchmarks, we directly address their limitations and outline paths for future work using contemporary data. This work serves as a transparent, practitioner-oriented interpretability guide for deploying ML-based traffic classifiers in evolving security environments.
Downloads
Downloads
Published
Issue
Section
License
Copyright (c) 2025 Annals of Mathematics and Computer Science

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.