Feature-Level Interpretability of a Hybrid Ensemble for Multi-Category Cyber Threat Classification: A SHAP-Based Analysis of the ADCTI-AR Framework
Contributors
Sesha Bhargavi
Upendra Kumar
Keywords
Proceeding
Track
General Track
License
Copyright (c) 2026 Sustainable Global Societies Initiative

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.
Abstract
High detection accuracy alone does not make a cyber-threat intelligence (CTI) system operationally trustworthy: Security Operations Center (SOC) analysts must also understand why a given event was classified as malicious before acting on automated recommendations. Stage II of the ADCTI-AR (AI-Driven Cyber Threat Intelligence and Adaptive Response) research programme reported a hybrid ensemble—combining Deep Neural Networks, Random Forests, Long Short-Term Memory networks, and autoencoder-based anomaly detection—that achieved 99.31% detection accuracy and 0.43% false positive rate across a 92-dimensional, three-category feature space (statistical, behavioral, and contextual). That work included a single, brief SHAP-based observation that behavioral features dominate Advanced Persistent Threat (APT) classification while statistical volume features dominate volumetric Denial-of-Service (DoS) detection. This paper isolates, extends, and rigorously develops that observation into a dedicated feature-level interpretability analysis. We examine SHAP attributions and Random Forest impurity-based importance side by side across attack categories, analyze their convergence as a cross-validation of interpretability itself, and derive concrete implications for feature engineering priorities and SOC analyst triage workflows. This analysis constitutes a distinct methodological contribution—an interpretability study in its own right—rather than a restatement of the detection-accuracy results already reported in Stage II.