Skip to main navigation Skip to search Skip to main content

An interpretable intrusion detection framework based on ensemble neural networks for dynamic network environments

  • Zhiqiang Zhang
  • , Haiyan Wang
  • , Liyi Zeng
  • , Dong Zhu
  • , Zhaohua Li
  • , Rongxin Hu
  • , Zhaoquan Gu*
  • *Corresponding author for this work
  • Harbin Institute of Technology
  • Pengcheng Laboratory
  • National University of Defense Technology
  • University of Electronic Science and Technology of China
  • Guangzhou University

Research output: Contribution to journalArticlepeer-review

Abstract

The increasing sophistication of cyber threats has made network intrusion detection systems (NIDS) indispensable components of modern defense infrastructures. However, conventional detection paradigms that separately process static and temporal traffic features often fail to capture the complex and nonlinear interactions between these features, leading to limited generalization in dynamic network environments. To address this limitation, this study proposes SGPKNET, an interpretable ensemble neural framework that integrates dual-perspective representation learning with knowledge-aware feature fusion. Specifically, SGPKNET employs a Gated Recurrent Unit (GRU)-based branch to encode temporal dependencies in network traffic sequences and a Backpropagation (BP)-based branch to model latent attribute patterns. Their high-dimensional embeddings are jointly optimized through a Kolmogorov-Arnold Network (KAN), enabling multilevel functional decomposition and nonlinear feature interaction modeling. Furthermore, a Network Crayfish Optimization Dimensionality Reduction (NCODR) algorithm is introduced to enhance discriminability and mitigate feature redundancy under nonlinear constraints. For interpretability, a Dynamic Adaptive Multi-Baseline Integrated Gradients (DAM-IG) Interpreter is developed to identify decision biases and reveal stealthy attack behaviors in learned representations. Comprehensive experiments on four benchmark datasets demonstrate that SGPKNET achieves superior detection accuracy and interpretability compared to existing methods, thereby providing a robust and transparent foundation for intelligent intrusion defense systems.

Original languageEnglish
Article number132353
JournalExpert Systems with Applications
Volume323
DOIs
StatePublished - 15 Aug 2026
Externally publishedYes

Keywords

  • Dual-perspective architecture
  • Intrusion detection
  • Kolmogorov-Arnold Networks
  • Multi-Baseline integrated gradients interpreter
  • Network Crayfish Optimization

Fingerprint

Dive into the research topics of 'An interpretable intrusion detection framework based on ensemble neural networks for dynamic network environments'. Together they form a unique fingerprint.

Cite this