Feature-Level Interpretability of a Hybrid Ensemble for Multi-Category Cyber Threat Classification: A SHAP-Based Analysis of the ADCTI-AR Framework


Date Published : 2 August 2026

Contributors

Sesha Bhargavi

Postdoctoral Researcher, LINCOLN UNIVERSITY COLLEGE
Author

Upendra Kumar

Assistant Professor, Institute of Engineering and Technology, Lucknow, India
Author

Keywords

Explainable AI SHAP Feature Importance Random Forest Interpretability Cyber Threat Intelligence ADCTI-AR Intrusion Detection Feature Engineering APT Detection.

Proceeding

Track

General Track

License

Copyright (c) 2026 Sustainable Global Societies Initiative

Creative Commons License

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.

Abstract

High detection accuracy alone does not make a cyber-threat intelligence (CTI) system operationally trustworthy: Security Operations Center (SOC) analysts must also understand why a given event was classified as malicious before acting on automated recommendations. Stage II of the ADCTI-AR (AI-Driven Cyber Threat Intelligence and Adaptive Response) research programme reported a hybrid ensemble—combining Deep Neural Networks, Random Forests, Long Short-Term Memory networks, and autoencoder-based anomaly detection—that achieved 99.31% detection accuracy and 0.43% false positive rate across a 92-dimensional, three-category feature space (statistical, behavioral, and contextual). That work included a single, brief SHAP-based observation that behavioral features dominate Advanced Persistent Threat (APT) classification while statistical volume features dominate volumetric Denial-of-Service (DoS) detection. This paper isolates, extends, and rigorously develops that observation into a dedicated feature-level interpretability analysis. We examine SHAP attributions and Random Forest impurity-based importance side by side across attack categories, analyze their convergence as a cross-validation of interpretability itself, and derive concrete implications for feature engineering priorities and SOC analyst triage workflows. This analysis constitutes a distinct methodological contribution—an interpretability study in its own right—rather than a restatement of the detection-accuracy results already reported in Stage II.

References

No References

Downloads

How to Cite

Velagaleti, D. S. B., & Dr. Upendra Kumar, D. U. K. (2026). Feature-Level Interpretability of a Hybrid Ensemble for Multi-Category Cyber Threat Classification: A SHAP-Based Analysis of the ADCTI-AR Framework. Sustainable Global Societies Initiative, 1(6). https://vectmag.com/sgsi/paper/view/927