Hierarchical Transformer-Based Intrusion Detection System with Explainable Artificial Intelligence: A Network Security Framework for Binary Classification on CIC-IDS2017
Contributors
Dr Sanjith Sathya Joseph
Dr S K Manju Bargavi
Keywords
Proceeding
Track
General Track
License
Copyright (c) 2026 Sustainable Global Societies Initiative

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.
Abstract
But, most of the black-box machine learning models used in network intrusion detection are unreliable due to the lack of regulatory compliance and limited insights. In this paper, the use of integrated explainable AI (XAI) techniques and hierarchical transformers (HT) based intrusion detection system (IDS) is proposed. The architecture contains a 9-dimensional input of traffic which is mapped to a multi-view feature hierarchy of temporal (2 dims) and spatial (2 dims) traffic properties at the packet level, flow level and session level. The accuracy of the trained model is 84.64% on CIC-IDS2017, while the precision is 87.08%, recall is 84.64%, F1 score is 84.38%, AUC-ROC is 93.93%, and false positive rate is 15.36% on the CIC-IDS2017 test set. XAI analyst dashboard that provides four complementary XAI methods in one place to provide instance-level, feature-level and temporal-attention explanations. We found that transformer-based models can be competitive in maintaining a property of a human readable decision path, allowing for safe use of AI in the production IDS system.