Interpretable Anomaly Detection in Encrypted Traffic Using SHAP with Machine Learning Models

📅 2025-05-22
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
The widespread adoption of encrypted communication (e.g., TLS/HTTPS) renders traditional anomaly detection methods—relying on plaintext payload analysis—ineffective. To address this, we propose an interpretable machine learning framework for encrypted traffic analysis, integrating ensemble models (e.g., Random Forest, XGBoost) with SHAP-based post-hoc explanation to achieve model-agnostic, feature-level interpretability in anomaly detection—its first such realization. Our method leverages TLS handshake attributes and flow-level statistical features, operating without decryption while effectively identifying anomalous patterns. Evaluated on three public benchmark datasets, it achieves high classification accuracy. SHAP visualizations precisely identify discriminative features, significantly improving root-cause analysis efficiency and enhancing the credibility of security responses. The core contribution is the design and implementation of the first explainable system that unifies SHAP with multiple ML models for encrypted traffic anomaly detection, uniquely balancing detection accuracy, model generality, and decision transparency.

Technology Category

Machine Learning: Transparent, Interpretable, Explainable MLNatural Language Processing: Interpretability, Analysis, and Evaluation of NLP ModelsHumans and AI: Explainable AI (XAI) for Human Understanding

Application Category

Security and Privacy: Large-scale security measurementsUser Modeling, Personalization and Recommendation: Explainable and interpretable methods for personalizationResponsible Web: Measurement, analysis, and circumvention of Web censorship
📝 Abstract
The widespread adoption of encrypted communication protocols such as HTTPS and TLS has enhanced data privacy but also rendered traditional anomaly detection techniques less effective, as they often rely on inspecting unencrypted payloads. This study aims to develop an interpretable machine learning-based framework for anomaly detection in encrypted network traffic. This study proposes a model-agnostic framework that integrates multiple machine learning classifiers, with SHapley Additive exPlanations SHAP to ensure post-hoc model interpretability. The models are trained and evaluated on three benchmark encrypted traffic datasets. Performance is assessed using standard classification metrics, and SHAP is used to explain model predictions by attributing importance to individual input features. SHAP visualizations successfully revealed the most influential traffic features contributing to anomaly predictions, enhancing the transparency and trustworthiness of the models. Unlike conventional approaches that treat machine learning as a black box, this work combines robust classification techniques with explainability through SHAP, offering a novel interpretable anomaly detection system tailored for encrypted traffic environments. While the framework is generalizable, real-time deployment and performance under adversarial conditions require further investigation. Future work may explore adaptive models and real-time interpretability in operational network environments. This interpretable anomaly detection framework can be integrated into modern security operations for encrypted environments, allowing analysts not only to detect anomalies with high precision but also to understand why a model made a particular decision a crucial capability in compliance-driven and mission-critical settings.
Problem

Research questions and friction points this paper is trying to address.

Develop interpretable ML framework for encrypted traffic anomaly detection
Integrate SHAP with ML models to explain anomaly predictions
Enhance transparency in detecting anomalies in encrypted environments
Innovation

Methods, ideas, or system contributions that make the work stand out.

Model-agnostic framework with multiple ML classifiers
SHAP for post-hoc model interpretability
Visualizations reveal influential traffic features
K
Kalindi Singh
School of Computer Science Engineering and Information Systems, Vellore Institute of Technology, Vellore 632014, India
A
Aayush Kashyap
School of Computer Science Engineering and Information Systems, Vellore Institute of Technology, Vellore 632014, India
Aswani Kumar Cherukuri
Aswani Kumar Cherukuri
Vellore Institute of Technology, Vellore
Quantum ComputingInformation SecurityMachine Learning