Transparent DDoS defense by combining Kolmogorov–Arnold networks and XAI for real-time protection in cloud environments
Mohamed Ouhssini, Karim Afdel, Mohamed Akouhar, El hafed Agherrabi, Abdallah Abarda, Mohamed El Fatini, Hasna Mahmoud · Telematics and Informatics Reports · 2025
Cloud computing environments face persistent threats from sophisticated Distributed Denial of Service (DDoS) attacks. Effective defense requires not only high accuracy but also real-time performance and transparent decision-making, a combination that challenges conventional security solutions. To address these challenges, a novel framework is introduced for real-time DDoS detection. It integrates a hybrid ensemble feature selection pipeline, combining statistical analysis with metaheuristic algorithms (GA, ACO, PSO, Aquila, GWO) to isolate the most critical traffic features. The Synthetic Minority Oversampling Technique (SMOTE) is employed to rectify class imbalance inherent in real-world network data. At the core of the framework, a comparative analysis evaluates the efficacy of deep learning models, with a focus on Kolmogorov–Arnold Networks (KAN) against established architectures like CNN, LSTM, and GRU. For model transparency and to foster operator trust, Explainable AI (XAI) techniques, specifically SHAP and LIME, are integrated to interpret detection results. The system’s performance is rigorously validated on public benchmark datasets (CICIDS2017, CICIDS2018, CICDDoS2019) and a custom dataset generated within a realistic OpenStack simulation environment. Results demonstrate that the KAN-based model significantly outperforms its counterparts, achieving superior detection accuracy while maintaining the lowest inference latency, confirming its suitability for real-time defense. Furthermore, the XAI component successfully provides clear, actionable insights into the model’s decision-making process, enhancing the framework’s overall reliability for modern cloud security operations.