Authors:
Alycia Sebastian, S. Silvia Priscila, B. M. Praveen
Addresses:
Department of Information Technology, Al Zahra College for Women, Madinat Al-Irfan, Muscat, Oman. Department of Computer Science, Bharath Institute of Higher Education and Research, Chennai, Tamil Nadu, India. Institute of Engineering and Technology, Srinivas University, Mangaluru, Karnataka, India.
The speed of cyberattack evolution and the growing sophistication of new attacks have revealed critical limitations of traditional IDS, specifically in terms of adaptability and interpretability. Although modern machine learning models are highly accurate at detection, their black-box nature makes them opaque, reducing analysts' trust and limiting their practical deployment in security-critical environments. To address this issue, this study proposes an interpretable and adaptive intrusion detection framework that achieves high detection performance and explainable decision-making. The proposed framework is built on a SHAP-enhanced ensemble learning architecture that incorporates heterogeneous classifiers, including tree-based and deep neural network models, to effectively capture complex and diverse attack behaviors. SHAP provide global and instance-level feature attributions, allowing security analysts to understand, validate, and trust model predictions. In addition, adaptive learning mechanisms are introduced to address concept drift in streaming network traffic, making it more robust under changing threat conditions. The framework is tested on benchmark intrusion detection datasets, such as NSL-KDD and CICIDS, with realistic multi-class attack scenarios. Experimental results show that the proposed approach achieves over 98% detection accuracy, an F1-score of more than 0.97, and approximately a 20% reduction in the false positive rate compared with state-of-the-art methods. Overall, the study validates the use of combining ensemble learning with SHAP-based explainability to achieve highly accurate, transparent and adaptive IDS that can be used in next-generation cybersecurity environments.
Keywords: Adaptive Learning; Cybersecurity Environments; Intrusion Detection Systems (IDS); Concept Drift; Heterogeneous Classifiers; Cyberattack Evolution; Practical Deployment; Feature Attribution; Shapley Additive Explanations (SHAP).
Received on: 16/06/2025, Revised on: 07/09/2025, Accepted on: 24/09/2025, Published on: 09/08/2026
DOI: 10.69888/FTSCL.2026.000748
FMDB Transactions on Sustainable Computer Letters, 2026 Vol. 4 No. 3, Pages: 138-150