Explainable Intrusion Detection in Software-Defined Networks Using TabNet-Enhanced XGBoost Ensemble

U. Vanitha, J. Rejina Parvin · International Journal of Software Engineering and Knowledge Engineering · 2025

Software-Defined Networking (SDN) enhances network flexibility through centralized control but introduces new vulnerabilities to cyberattacks. This study presents an explainable intrusion detection framework that integrates TabNet for attention-based feature learning with XGBoost for gradient-boosted classification. The CICIDS2017 benchmark dataset is used to evaluate the proposed approach. After comprehensive preprocessing and feature analysis, TabNet alone achieved an F1-score of 0.83 and a ROC-AUC of 0.86, demonstrating strong capability in learning tabular network patterns but limited recall for minority attack classes. To improve sensitivity, the latent embeddings generated by TabNet were provided as input to an XGBoost classifier, resulting in enhanced precision (0.93), recall (0.96), F1-score (0.95), and ROC-AUC (0.97). While traditional models such as Random Forest and Logistic Regression achieved competitive scores, their results indicated potential overfitting. The proposed hybrid model provides a balanced trade-off between accuracy, generalization, and interpretability. Furthermore, SHAP analysis was applied to explain feature contributions, enabling transparent decision-making suitable for deployment in security-critical SDN environments. Generally, the framework indicates that a combination of attentionbased representation learning and gradient boosting is a strong and explainable remedy to current intrusion detection.

Read the paper · More papers on PaperTik