An XGBoost ‐Based Cyber Threat Detection Framework for Enhancing Security in University E‐Government Systems
Yong Wang · Security and Privacy · 2025
ABSTRACT With academic digital infrastructures facing escalating cyber threats, this research introduces a specialized machine learning pipeline to enhance security in university e‐government systems. The study is motivated by the urgent need to protect sensitive data and maintain public trust, a challenge many existing models fail to address due to reliance on synthetic data. We propose an interpretable XGBoost‐based classification model trained on a real‐world dataset of 22 000 cyber threat incidents from a university network. Our approach leverages TF‐IDF for vectorizing textual threat descriptions, categorical encoding for contextual attributes, and SMOTE to resolve significant class imbalance. The XGBoost model achieves an accuracy of 0.98 and an F1‐score of 0.77, with a precision of 0.80 and a recall of 0.75, reflecting a deliberate balance optimized for minimizing missed threats. This performance significantly surpasses comparably tuned TabNet, CNN, DNN, and LSTM baselines. The model's transparency, demonstrated through SHAP (SHapley Additive exPlanations) analysis, provides a superior equilibrium of performance and domain alignment. This framework offers a tangible solution for enhancing threat detection, enabling security analysts to make informed decisions and bolstering institutional confidence in automated e‐governance security.