Deteksi Serangan DDoS Menggunakan Explainable Ensemble Learning dan Analisis SHAP

Authors

  • Sutrisno Sutrisno Universitas Pamulang
  • Okta Irawati Universitas Pamulang

DOI:

https://doi.org/10.30606/rjti.v5i2.4702

Keywords:

Explainable AI, DDoS, SHAP, Ensemble Learning, Intrusion Detection System.

Abstract

Distributed Denial of Service (DDoS) attacks remain a major threat to network service availability due to their ability to generate massive traffic volumes that closely resemble legitimate activities. This study proposes an Explainable Ensemble Learning approach for DDoS detection using the CIC-DDoS2019 dataset. The proposed framework integrates Mutual Information-based feature selection to identify the 20 most relevant features, Synthetic Minority Over-sampling Technique (SMOTE) for class balancing, and a Voting Ensemble of Random Forest, XGBoost, and LightGBM classifiers. Model performance was evaluated using a 70:30 train-test split with Accuracy, Precision, Recall, F1-score, and ROC-AUC metrics. Experimental results achieved 99.80% Accuracy, 99.79% F1-score, and 0.9999 ROC-AUC. SHAP analysis identified Avg_Packet_Size and packet-length-related features as the most influential predictors, improving both detection performance and model interpretability. These findings demonstrate that integrating Ensemble Learning with Explainable Artificial Intelligence provides an accurate and transparent solution for DDoS detection interpretability.

Downloads

Download data is not yet available.

References

D. Patel, “Quantitative and Visual Exploratory Data Analysis for Machine Intelligence,” 2021, pp. 97–117. doi: https://10.4018/978-1-7998-7701-1.ch006.

I. Sharafaldin, A. H. Lashkari, S. Hakak, and A. A. Ghorbani, “Developing realistic distributed denial of service (DDoS) attack dataset and taxonomy,” in 2019 international carnahan conference on security technology (ICCST)Developing realistic distributed denial of service (DDoS) attack dataset and taxonomy, 2019, pp. 1–8. doi: https://10.1109/CCST.2019.8888419.

M. C. P. Saheb, M. S. Yadav, S. Babu, J. J. Pujari, and J. B. Maddala, “A review of DDoS evaluation dataset: CICDDoS2019 dataset,” in International Conference on Energy Systems, Drives and Automations, 2021, pp. 389–397. doi: https://doi.org/10.1007/978-981-99-3691-5_34.

A. A. Alahmadi et al., “DDoS attack detection in IoT-based networks using machine learning models: a survey and research directions,” Electronics (Basel)., vol. 12, no. 14, p. 3103, 2023, doi: https://doi.org/10.3390/electronics12143103.

M. Aljebreen, H. A. Mengash, M. A. Arasi, S. S. Aljameel, A. S. Salama, and M. A. Hamza, “Enhancing DDoS attack detection using snake optimizer with ensemble learning on internet of things environment,” IEEE Access, vol. 11, pp. 104745–104753, 2023, doi: 10.1109/ACCESS.2023.3318316.

V. Gaur and R. Kumar, “Analysis of Machine Learning Classifiers for Early Detection of DDoS Attacks on IoT Devices,” Arab. J. Sci. Eng., vol. 47, no. 2, pp. 1353–1374, 2022, doi: https://10.1007/s13369-021-05947-3.

O. Ebrahem, S. Dowaji, and S. Alhammoud, “A lightweight machine learning approach for DDoS detection and classification,” Sci. Rep., 2026, doi: https://doi.org/10.1038/s41598-026-48535-x.

A. Hamarshe, H. I. Ashqar, and M. Hamarsheh, “Detection of DDoS attacks in software defined networking using machine learning models,” in International Conference on Advances in Computing Research, 2023, pp. 640–651. doi: https://10.1109/CSNT51715.2021.9509634.

A. Alsarhan, M. Barhoush, B. Khassawneh, M. Al-Essa, M. Aljaidi, and Q. Al-Na’amneh, “Deep Learning Utilization for DDoS Attack Detection with Federated Learning: A Case Study on the CICDDoS2019 Dataset,” Engineering, Technology & Applied Science Research, vol. 16, no. 1, pp. 31203–31208, 2026.

F. S. de Lima Filho, F. A. F. Silveira, A. de Medeiros Brito Junior, G. Vargas-Solar, and L. F. Silveira, “Smart Detection: An Online Approach for DoS/DDoS Attack Detection Using Machine Learning,” Security and Communication Networks, vol. 2019, no. 1, p. 1574749, 2019, doi: https://doi.org/10.1155/2019/1574749.

H. Patel, “Feature selection via gans (ganfs): Enhancing machine learning models for ddos mitigation,” arXiv preprint arXiv:2504.18566, 2025, doi: https://10.1109/ACCESS.2024.3384398.

B. M. Kouassi, A. B. Ballo, K. J. Ayikpa, D. Mamadou, and M. Z. J. Coulibaly, “Top-K Feature Selection for IoT Intrusion Detection: Contributions of XGBoost, LightGBM, and Random Forest,” Future Internet, vol. 17, no. 11, p. 529, 2025, doi: https://doi.org/10.3390/fi17110529.

N. Ahmed, G. Saleem, A. Naveed, and M. I. Zaman, “A Resource-Efficient Machine Learning Pipeline for DDoS Attack Detection: A Comparative Study on CIC-IDS2018 and CIC-DDoS2019,” ICCK Transactions on Information Security and Cryptography, vol. 2, no. 1, pp. 55–69, 2026, doi: 10.62762/TISC.2025.438083.

and A. S. H. A. Salman, A. Kalakech, “Random Forest Algorithm Overview,” Babylonian Journal of Machine Learning, vol. 2024, pp. 69–79, 2024, doi: 10.58496/BJML/2024/007.

A. J. Ibrahim, S. R. Répás, and N. Bektacs, “Feature-Optimized Machine Learning Approaches for Enhanced DDoS Attack Detection and Mitigation,” Computers, vol. 14, no. 11, p. 472, 2025, doi: https://https://doi.org/10.3390/computers14110472.

M. Temraz and M. T. Keane, “Solving the class imbalance problem using a counterfactual method for data augmentation,” Machine Learning with Applications, vol. 9, p. 100375, 2022, doi: https://doi.org/10.1016/j.mlwa.2022.100375.

G. Ranjbaran, D. R. Recupero, C. K. Roy, and K. A. Schneider, “C-SHAP: A Hybrid Method for Fast and Efficient Interpretability,” Applied Sciences (Switzerland), vol. 15, no. 2, 2025, doi: https://10.3390/app15020672.

M. Nalluri, M. Pentela, and N. R. Eluri, “A scalable tree boosting system: XG boost,” Int. J. Res. Stud. Sci. Eng. Technol, vol. 7, no. 12, pp. 36–51, 2020, doi: https://doi.org/10.22259/2349-476X.0712005.

J. Lascano-Banshuy, A. Sánchez-Zumba, and D. Robayo-Jácome, “Application of SMOTE for Improving the Training of Intrusion Detection Models with Imbalanced Classes,” EAI/Springer Innovations in Communication and Computing, pp. 115 – 134, 2026, doi: 10.1007/978-3-032-10310-9_8.

S. M. Kasongo, “Performance Analysis of Intrusion Detection Systems Using a Feature Selection Method on the UNSW-NB15 Dataset,” J. Big Data, vol. 7, no. 1, 2020, doi: 10.1186/s40537-020-00379-6.

I. F. Kilincer, “Machine learning methods for cyber security intrusion detection: Datasets and comparative study,” Computer Networks, vol. 188, 2021, doi: 10.1016/j.comnet.2021.107840.

N. Rane, S. P. Choudhary, and J. Rane, “Ensemble deep learning and machine learning: applications, opportunities, challenges, and future directions,” Studies in Medical and Health Sciences, vol. 1, no. 2, pp. 18–41, 2024, doi: 10.48185/smhs.v1i2.1225.

B. Lan, Y. Chen, and K. Wu, “A granular XGBoost classification algorithm,” Applied Intelligence, vol. 55, no. 13, 2025, doi: 10.1007/s10489-025-06762-1.

L. M. de Oliveira, F. S. de Menezes, M. A. Cirillo, A. V Saúde, F. M. Borém, and G. R. Liska, “Machine Learning techniques in muliclass problems with application in sensorial analysis,” Concurr. Comput., vol. 32, no. 7, 2020, doi: 10.1002/cpe.5579.

W. Jia, M. Sun, J. Lian, and S. Hou, “Feature dimensionality reduction: a review,” Complex & Intelligent Systems, vol. 8, no. 3, pp. 2663–2693, 2022, doi: 10.1007/s40747-021-00637-x.

C. Molnar, G. Casalicchio, and B. Bischl, “Interpretable Machine Learning -A Brief History, State-of-the-Art and Challenges,” in ECML PKDD 2020 Workshops, I. Koprinska, M. Kamp, A. Appice, C. Loglisci, L. Antonie, A. Zimmermann, R. Guidotti, Ö. Özgöbek, R. P. Ribeiro, R. Gavaldà, J. Gama, L. Adilova, Y. Krishnamurthy, P. M. Ferreira, D. Malerba, I. Medeiros, M. Ceci, G. Manco, E. Masciari, Z. W. Ras, P. Christen, E. Ntoutsi, E. Schubert, A. Zimek, A. Monreale, P. Biecek, S. Rinzivillo, B. Kille, A. Lommatzsch, and J. A. Gulla, Eds., Cham: Springer International Publishing, 2020, pp. 417–431. doi: https://doi.org/10.1007/978-3-030-65965-3_28.

D. Chicco and G. Jurman, “The Matthews correlation coefficient (MCC) should replace the ROC AUC as the standard metric for assessing binary classification,” BioData Min., vol. 16, no. 1, 2023, doi: https://10.1186/s13040-023-00322-4.

N. A. Supriadi, A. R. Manga, R. Adawiyah, and T. Hasanuddin, “Application of Ensemble Machine Learning for DDoS Detection in Complex Network Environments,” in Proceedings of the 2025 19th International Conference on Ubiquitous Information Management and Communication, IMCOM 2025, 2025. doi: 10.1109/IMCOM64595.2025.10857516.

K. Wadhwa, H. Babbar, and S. Rani, “Explainable artificial intelligence in threat detection,” in Explainable Artificial Intelligence (XAI) for Next Generation Cybersecurity: Concepts, Challenges and Applications, 2025, pp. 49–68. doi: 10.1049/PBSE027E_ch3.

C. Rudin, C. Chen, Z. Chen, H. Huang, L. Semenova, and C. Zhong, “Interpretable machine learning: Fundamental principles and 10 grand challenges,” Statistic Surveys, vol. 16, pp. 1–85, 2022.

Downloads

Published

2026-07-19

How to Cite

[1]
S. Sutrisno and O. Irawati, “Deteksi Serangan DDoS Menggunakan Explainable Ensemble Learning dan Analisis SHAP”, RJTI, vol. 5, no. 2, pp. 422–43, Jul. 2026.

Issue

Section

Articles

Similar Articles

<< < 1 2 3 4 5 6 7 > >> 

You may also start an advanced similarity search for this article.