A Hybrid Deep Learning Approach to Network Traffic Anomaly Detection Enhanced by SHAP and LIME Interpretability

Shashikant Verma, S. Prabakeran · 2025

The increasing complexity and volume of network traffic have made anomaly detection a critical challenge in cybersecurity. Traditional methods often struggle to balance accuracy and interpretability, this limits their efficacy in real-world applications. This study looks toward the improvement of anomalies. detection in network traffic by integrating SHAP and LIME interpretability techniques into hybrid deep learning models. The primary goal is to improve both the detection performance and the interpretability of these models, enabling security analysts to understand. The project's goal is to improve cybersecurity operations' usability and trust by offering clear and practical insights into the model's predictions. The hybrid deep learning model includes CNNs for spatial feature extraction with RNN for temporal pattern analysis, taking use of the capabilities of both architectures to better detect abnormalities. One of the main tactics used in this study is the preparation and feature extraction of network traffic data,developing,training a hybrid deep learning model for anomaly detection and integrating SHAP and LIME to comprehend the model's predictions. The dataset used for evaluation includes real-world network traffic with labelled anomalies, ensuring the relevance and applicability of the results. The model's detection abilities were tested using performance metrics such as accuracy, precision, recall and F1-score. The result's interpretability was assessed by qualitatively assessing SHAP and LIME outputs. The major results of the Research demonstrate that the hybrid deep learning model, enhanced with SHAP and LIME, achieves superior anomaly detection performance compared to traditional methods. These insights enable security analysts to validate and refine the model's decisions, reducing the risk of false alarms and improving overall system reliability. The findings demonstrate how hybrid models may attain high accuracy while preserving transparency, which makes them more useful for actual cybersecurity applications.

Read the paper · More papers on PaperTik