A Privacy-Preserving Explainable Artificial Intelligence Hybrid Framework for Abnormal Network Traffic Identification and Intelligent Threat Detection

  • Onuma Divine Anele Department of Computer Science, Rivers State University, Nkpolu-Oroworukwo, Port Harcourt, Rivers State, Nigeria.
  • D. Matthias Department of Computer Science, Rivers State University, Nkpolu-Oroworukwo, Port Harcourt, Rivers State, Nigeria.
  • O. E. Taylor Department of Computer Science, Rivers State University, Nkpolu-Oroworukwo, Port Harcourt, Rivers State, Nigeria.
Keywords: Hybrid Artificial Intelligence, Abnormal Network Traffic Identification, Intelligent Threat Detection, Intrusion Detection System, LSTM, Transformer, Random Forest, Explainable Artificial Intelligence, CKKS Homomorphic Encryption, Zero-Day Attack Detection

Abstract

The rapid evolution of cyber threats, the widespread adoption of encrypted communications, and the increasing complexity of enterprise, cloud, edge, and Internet of Things (IoT) environments have exposed the limitations of conventional intrusion detection systems in accurately identifying abnormal network traffic and detecting sophisticated cyberattacks. Existing hybrid deep learning frameworks, including that of Wang [54], achieve high detection accuracy but lack privacy-preserving computation, explainable artificial intelligence, intelligent threat prioritization, and adaptive operational capabilities. This study therefore designed and developed a Hybrid Artificial Intelligence Framework for Abnormal Network Traffic Identification and Intelligent Threat Detection by integrating Long Short-Term Memory (LSTM), Transformer, Random Forest, CKKS Homomorphic Encryption, Explainable Artificial Intelligence (SHAP/LIME), weighted ensemble decision fusion, intelligent threat prioritization, and adaptive feedback learning. The study adopted the Design Science Research Methodology (DSRM), while the proposed framework was implemented using Python, TensorFlow/Keras, Scikit-learn, Microsoft SEAL/TenSEAL, and evaluated using the CICIDS2017 and UNSW-NB15 benchmark datasets. Experimental evaluation was performed using accuracy, precision, recall, F1-score, false positive rate, detection latency, zero-day detection rate, throughput, scalability, explainability, and encryption overhead as performance metrics. The proposed framework achieved detection accuracies of 99.12% and 98.76% on the CICIDS2017 and UNSW-NB15 datasets, respectively, with precision values of 98.87% and 98.42%, recall values of 99.05% and 98.61%, F1-scores of 98.96% and 98.51%, false positive rates of 0.84% and 1.12%, and zero-day detection rates of 94.30% and 92.75%. Comparative analysis demonstrated improved detection accuracy, lower false-positive rates, reduced detection latency, enhanced interpretability, and stronger privacy preservation compared with the hybrid CNN–LSTM–Transformer framework of Wang [54]. The study concludes that integrating hybrid artificial intelligence, privacy-preserving computation, explainable artificial intelligence, and intelligent threat prioritization provides a robust, scalable, and adaptive solution for modern cybersecurity. The proposed framework is recommended for deployment in enterprise networks, cloud computing, IoT, edge computing, and critical infrastructure environments to strengthen real-time cyber threat detection and response.

Downloads

Download data is not yet available.

References

Abbasi, M., Shahraki, A., & Taherkordi, A. (2021). Deep learning for network traffic monitoring and analysis (NTMA): A survey. Computer Communications, 170, 19–41. https://doi.org/10.1016/j.comcom.2021.01.021

Aceto, G., Ciuonzo, D., Montieri, A., & Pescapé, A. (2023). Deep learning for encrypted traffic classification: An overview. IEEE Communications Magazine, 61(4), 74–80.

Anis, F. M., Alabdullatif, M., Aljbli, S., & Hammoudeh, M. (2025). A survey on the applications of deep learning in network intrusion detection systems to enhance network security. IEEE Access, 13, 185357–185373. https://doi.org/10.1109/ACCESS.2025.3624952

Arrieta, A. B., Díaz-Rodríguez, N., Del Ser, J., Bennetot, A., Tabik, S., Barbado, A., García, S., Gil-López, S., Molina, D., Benjamins, R., Chatila, R., & Herrera, F. (2020). Explainable artificial intelligence (XAI): Concepts, taxonomies, opportunities and challenges toward responsible AI. Information Fusion, 58, 82–115. https://doi.org/10.1016/j.inffus.2019.12.012

Atzori, L., Iera, A., & Morabito, G. (2010). The Internet of Things: A survey. Computer Networks, 54(15), 2787–2805.

Bamber, S., Katkuri, A. V., Sharma, S., & Angurala, M. (2024). A hybrid CNN-LSTM approach for intelligent cyber intrusion detection system. Computers & Security, 134, Article 104146. https://doi.org/10.1016/j.cose.2024.104146

Biau, G., & Scornet, E. (2016). A random forest guided tour. TEST, 25(2), 197–227. https://doi.org/10.1007/s11749-016-0481-7

Biggio, B., & Roli, F. (2018). Wild patterns: Ten years after the rise of adversarial machine learning. Pattern Recognition, 84, 317–331. https://doi.org/10.1016/j.patcog.2018.07.023

Biggio, B., Nelson, B., & Laskov, P. (2012). Poisoning attacks against support vector machines. Proceedings of the 29th International Conference on Machine Learning, 1807–1814.

Bilge, L., & Dumitraș, T. (2012). Before we knew it: An empirical study of zero-day attacks in the real world. Proceedings of the ACM Conference on Computer and Communications Security, 833–844.

Brakerski, Z. (2012). Fully homomorphic encryption without modulus switching from classical GapSVP. In Advances in Cryptology – CRYPTO 2012 (Lecture Notes in Computer Science, Vol. 7417, pp. 868–886). Springer.

Breiman, L. (2001). Random forests. Machine Learning, 45(1), 5–32. https://doi.org/10.1023/A:1010933404324

Buczak, A. L., & Guven, E. (2016). A survey of data mining and machine learning methods for cyber security intrusion detection. IEEE Communications Surveys & Tutorials, 18(2), 1153–1176.

Cawthra, J., Ekstrom, M., Lusty, L., Sexton, J., & Sweetnam, J. (2020). Data integrity: Detecting and responding to ransomware and other destructive events (NIST Special Publication 1800-26A). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.1800-26

Chandola, V., Banerjee, A., & Kumar, V. (2009). Anomaly detection: A survey. ACM Computing Surveys, 41(3), 1–58.

Cheon, J. H., Kim, A., Kim, M., & Song, Y. (2017). Homomorphic encryption for arithmetic of approximate numbers. In T. Takagi & T. Peyrin (Eds.), Advances in Cryptology – ASIACRYPT 2017 (Lecture Notes in Computer Science, Vol. 10624, pp. 409–437). Springer. https://doi.org/10.1007/978-3-319-70694-8_15

Cho, K., Van Merriënboer, B., Bahdanau, D., & Bengio, Y. (2014). Learning phrase representations using RNN encoder–decoder for statistical machine translation. In Proceedings of the 2014 Conference on Empirical Methods in Natural Language Processing (pp. 1724–1734).

Denning, D. E. (1987). An intrusion-detection model. IEEE Transactions on Software Engineering, 13(2), 222–232.

Fan, J., & Vercauteren, F. (2012). Somewhat practical fully homomorphic encryption. IACR Cryptology ePrint Archive, 2012, Article 144.

Ferrag, M. A., Maglaras, L., Ahmim, A., Derdour, M., & Janicke, H. (2022). Deep learning for cyber security intrusion detection: Approaches, datasets, and comparative study. Journal of Information Security and Applications, 62, 102989.

Gentry, C. (2009). A fully homomorphic encryption scheme (Doctoral dissertation, Stanford University). Stanford University.

Goodfellow, I. J., Shlens, J., & Szegedy, C. (2015). Explaining and harnessing adversarial examples. International Conference on Learning Representations (ICLR). https://arxiv.org/abs/1412.6572

Goodfellow, I., Bengio, Y., & Courville, A. (2016). Deep learning. MIT Press.

Guidotti, R., Monreale, A., Ruggieri, S., Turini, F., Giannotti, F., & Pedreschi, D. (2018). A survey of methods for explaining black box models. ACM Computing Surveys, 51(5), Article 93. https://doi.org/10.1145/3236009

Hassan, M. M., Gumaei, A., Alsanad, A., Alrubaian, M., & Fortino, G. (2020). A hybrid deep learning model for efficient intrusion detection in big data environment. Information Sciences, 513, 386–396. https://doi.org/10.1016/j.ins.2019.10.069

Hochreiter, S., & Schmidhuber, J. (1997). Long short-term memory. Neural Computation, 9(8), 1735–1780.

Hutchins, E. M., Cloppert, M. J., & Amin, R. M. (2011). Intelligence-driven computer network defense informed by analysis of adversary campaigns and intrusion kill chains. Lockheed Martin Corporation.

Ji, I. H., Lee, J. H., Kang, M. J., Park, W. J., & Jeon, S. H. (2024). Artificial intelligence-based anomaly detection technology over encrypted traffic: A systematic literature review. Sensors, 24(3), 898. https://doi.org/10.3390/s24030898

Khan, S., Naseer, M., Hayat, M., Zamir, S. W., Khan, F. S., & Shah, M. (2022). Transformers in vision: A survey. ACM Computing Surveys, 54(10S), 1–41.

Kimanzi, R., Kimanga, P., Cherori, D., & Gikunda, P. K. (2024). Deep learning algorithms used in intrusion detection systems: A review (arXiv:2402.17020). arXiv. https://doi.org/10.48550/arXiv.2402.17020

Kingma, D. P., & Welling, M. (2014). Auto-encoding variational Bayes. International Conference on Learning Representations (ICLR).

Kumar, N., & Sharma, S. (2023). A hybrid modified deep learning architecture for intrusion detection system with optimal feature selection. Electronics, 12(19), 4050. https://doi.org/10.3390/electronics12194050

Kurose, J. F., & Ross, K. W. (2022). Computer networking: A top-down approach (8th ed.). Pearson.

LeCun, Y., Bottou, L., Bengio, Y., & Haffner, P. (1998). Gradient-based learning applied to document recognition. Proceedings of the IEEE, 86(11), 2278–2324.

Lundberg, S. M., & Lee, S.-I. (2017). A unified approach to interpreting model predictions. In I. Guyon, U. V. Luxburg, S. Bengio, H. Wallach, R. Fergus, S. Vishwanathan, & R. Garnett (Eds.), Advances in Neural Information Processing Systems (Vol. 30). Curran Associates, Inc. https://doi.org/10.48550/arXiv.1705.07874

Mell, P., & Grance, T. (2011). The NIST definition of cloud computing (NIST Special Publication 800-145). National Institute of Standards and Technology.

Minaee, S., Kalchbrenner, N., Cambria, E., Nikzad, N., Chenaghlu, M., & Gao, J. (2024). Large language models: A survey. ACM Computing Surveys, 57(2), 1–44.

National Institute of Standards and Technology. (2022). Developing cyber-resilient systems: A systems security engineering approach (NIST Special Publication 800-160, Vol. 2, Rev. 1). U.S. Department of Commerce. https://doi.org/10.6028/NIST.SP.800-160v2r1

National Institute of Standards and Technology. (2024). Cybersecurity Framework (CSF) 2.0. National Institute of Standards and Technology.

Ramesh, G., Palanisami, D., Dhamotharan, G., & Mohan, N. (2026). A low-light color image enhancement model with a trainable intuitionistic fuzzy generator. International Journal of Computer Applications, 187(112), 1–13. https://doi.org/10.5120/ijca00ec39863324

Ribeiro, M. T., Singh, S., & Guestrin, C. (2016). "Why should I trust you?": Explaining the predictions of any classifier. In Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (pp. 1135–1144). https://doi.org/10.1145/2939672.2939778

Rivest, R. L., Adleman, L., & Dertouzos, M. L. (1978). On data banks and privacy homomorphisms. In Foundations of Secure Computation (pp. 169–180). Academic Press.

Russell, S., & Norvig, P. (2021). Artificial intelligence: A modern approach (4th ed.). Pearson.

Samek, W., Montavon, G., Lapuschkin, S., Anders, C. J., & Müller, K.-R. (2021). Explaining deep neural networks and beyond: A review of methods and applications. Proceedings of the IEEE, 109(3), 247–278. https://doi.org/10.1109/JPROC.2021.3060483

Sattar, S., Khan, S., Khan, M. I., Akhmediyarova, A., Mamyrbayev, O., Kassymova, D., Oralbekova, D., & Alimkulova, J. (2025). Anomaly detection in encrypted network traffic using self-supervised learning. Scientific Reports, 15, Article 26585. https://doi.org/10.1038/s41598-025-08568-0

Scarfone, K., & Mell, P. (2007). Guide to intrusion detection and prevention systems (IDPS) (NIST Special Publication 800-94). National Institute of Standards and Technology.

Shi, W., Cao, J., Zhang, Q., Li, Y., & Xu, L. (2016). Edge computing: Vision and challenges. IEEE Internet of Things Journal, 3(5), 637–646. https://doi.org/10.1109/JIOT.2016.2579198

Singh, A., Chouhan, P. K., & Aujla, G. S. (2024). SecureFlow: Knowledge and data-driven ensemble for intrusion detection and dynamic rule configuration in software-defined IoT environment. Ad Hoc Networks, 156, 103404. https://doi.org/10.1016/j.adhoc.2024.103404

Sommer, R., & Paxson, V. (2010). Outside the closed world: On using machine learning for network intrusion detection. In 2010 IEEE Symposium on Security and Privacy (pp. 305–316). IEEE. https://doi.org/10.1109/SP.2010.25

Stallings, W. (2020). Data and computer communications (11th ed.). Pearson.

Tanenbaum, A. S., & Wetherall, D. J. (2021). Computer networks (6th ed.). Pearson.

Tsigos, K., Apostolidis, E., Baxevanakis, S., Papadopoulos, S., & Mezaris, V. (2024). Towards quantitative evaluation of explainable AI methods for deepfake detection. In Proceedings of the 3rd ACM International Workshop on Multimedia AI against Disinformation (MAD '24) (pp. 37–45). Association for Computing Machinery. https://doi.org/10.1145/3643491.3660292

Vaswani, A., Shazeer, N., Parmar, N., Uszkoreit, J., Jones, L., Gomez, A. N., Kaiser, Ł., & Polosukhin, I. (2017). Attention is all you need. In I. Guyon, U. V. Luxburg, S. Bengio, H. Wallach, R. Fergus, S. Vishwanathan, & R. Garnett (Eds.), Advances in Neural Information Processing Systems (Vol. 30). Curran Associates, Inc. https://doi.org/10.48550/arXiv.1706.03762

Wang, J., Huang, N., Zhang, H., Liu, L., Fu, Q., Cao, K., Guo, X., & Jung, H. (2025). Self-learning model fusion for network anomaly detection: A hybrid CNN–LSTM–Transformer framework. PLOS ONE, 20(10), e0332502. https://doi.org/10.1371/journal.pone.0332502

Wang, J., Si, C., Wang, Z., & Fu, Q. (2024). A new industrial intrusion detection method based on CNN-BiLSTM. Computers, Materials & Continua, 79(3), 4297–4318. https://doi.org/10.32604/cmc.2024.050223

Yang, K., Wang, J., & Li, M. (2024). An improved intrusion detection method for IIoT using attention mechanisms, BiGRU, and Inception-CNN. Scientific Reports, 14, 19339. https://doi.org/10.1038/s41598-024-70094-2

Zhang, C., Bengio, S., Hardt, M., Recht, B., & Vinyals, O. (2023). Understanding deep learning (still) requires rethinking generalization. Communications of the ACM, 66(3), 107–115. https://doi.org/10.1145/3583857

Zhou, Y., Chen, X., Li, H., & Wang, Z. (2023). Artificial intelligence for cloud-edge-IoT security: A survey. IEEE Access, 11, 114256–114281. https://doi.org/10.1109/ACCESS.2023.3326437

Zhou, Z.-H. (2021). Ensemble methods: Foundations and algorithms (2nd ed.). CRC Press.

Alshahrani, A., Alghamdi, W., Alsubai, S., Aljameel, S. S., Alharbi, A., & Alshamrani, A. (2024). Explainable artificial intelligence: A survey of needs, techniques, applications, and future direction. Neurocomputing, 599, 128111. https://doi.org/10.1016/j.neucom.2024.128111

Published
2026-08-08
How to Cite
Anele, O., Matthias, D., & Taylor, O. E. (2026). A Privacy-Preserving Explainable Artificial Intelligence Hybrid Framework for Abnormal Network Traffic Identification and Intelligent Threat Detection. GPH-International Journal of Computer Science and Engineering, 8(01), 62-103. https://doi.org/10.5281/zenodo.21849331