Explainable Hybrid Framework for Network Intrusion Detection Using Graph Attention Networks and Advanced Feature Engineering
Jobin P Mathew, Nirmal Varghese Babu · 2025
Network intrusion detection systems have been of key importance in ensuring the protection of computer networks against any malicious activities. However, most NIDS face difficulties such as poor detection accuracy often resulting from class imbalance and lack of model transparency. To overcome such challenges, an innovative approach in multiclass network intrusion detection was developed using more advanced techniques involving data preprocessing, feature extraction, feature selection, and classification. This approach is called Hybrid Statistical-Principal-Clustering (HSPC), which combines domain-specific statistical features with those derived from Principal Component Analysis (PCA) and clustering methods. Another algorithm, Hybrid Recursive Importance Feature Selection (HRIFS), is proposed, which integrates recursive feature elimination with feature importance scores obtained from the Random Forest algorithm. The methodology uses Explainable AI (XAI) in conjunction with Graph Attention Networks (GAT) to ensure high detection accuracy while maintaining transparency. The method was tested on the NF-UNSW-NB15 dataset, with the result of accuracy being 98.6%. This result will validate its applicability to provide accurate and transparent identification of intrusions into a network while the model remains explainable. Therefore, the developed methodology will have a major step forward in building explainable yet accurate NIDS, thus having real-world applications and strengthening security measures. The proposed research contributes a comprehensive framework toward solving the problem of multiclass network intrusion detection. It serves as a valuable resource for researchers and practitioners in the domain of cybersecurity.