1 Department of Computer Engineering, Faculty of Engineering and the Built Environment, State University of Medical and Applied Sciences, Igbo-Eno, Enugu State, Nigeria.
2 Department of Electrical and Electronic Engineering, Faculty of Engineering and the Built Environment, State University of Medical and Applied Sciences, Igbo-Eno, Enugu State, Nigeria.
3 Department of Biomedical Engineering, Faculty of Engineering and the Built Environment, State University of Medical and Applied Sciences, Igbo-Eno, Enugu State, Nigeria.
4 Department of Mechanical Engineering, Faculty of Engineering and the Built Environment, State University of Medical and Applied Sciences, Igbo-Eno, Enugu State, Nigeria.
5 Department of Civil Engineering, Faculty of Engineering and the Built Environment, State University of Medical and Applied Sciences, Igbo-Eno, Enugu State, Nigeria.
* Corresponding Author
ORCID Details
Kingsley I. Chibueze: https://orcid.org/0009-0008-9387-0297
World Journal of Advanced Engineering Technology and Sciences, 2026, 20(03), 103–108
Article DOI: 10.30574/wjaets.2026.20.3.0442
Received on 08 June 2026; revised on 16 September 2026; accepted on 18 September 2026
Machine-learning intrusion detection systems can provide strong predictive performance while offering limited evidence for why an individual network-flow record was classified as suspicious. This study examines the integration of SHapley Additive exPlanations (SHAP) with a LightGBM-based network intrusion detector trained on HIKARI-2021. The work is extracted from an implemented intelligent hybrid intrusion detection system (IDS), but this paper isolates the explainability contribution rather than treating the complete hybrid architecture as its subject. HIKARI-2021 contains 555,278 records and 83 original columns in the project dataset; after preprocessing, 81 features were retained. LightGBM was configured with 250 estimators, a learning rate of 0.05, 48 leaves, class weighting, and a tuned decision threshold of 0.7987. On the held-out test set, the classifier achieved 90.60% accuracy, 94.63% weighted precision, 90.60% weighted recall, 92.01% weighted F1-score, and an ROC AUC of 0.9522. Suspicious-class precision was 40.50% and recall was 81.89%. SHAP was integrated into the suspicious-prediction pathway to attribute predictions to input features, while a fallback textual explanation was implemented when SHAP output was unavailable. The source experiment did not include a formal quantitative evaluation of explanation fidelity, stability, completeness, or analyst usefulness. Accordingly, this paper reports SHAP as an implemented explainability mechanism and does not claim that SHAP itself improves predictive accuracy or reduces false positives.
Explainable Artificial Intelligence; SHAP; Lightgbm; Intrusion Detection; HIKARI-2021; Feature Attribution; Network-Flow Classification
Get Your e Certificate of Publication using below link
Preview Article PDF
Kingsley I. Chibueze, Okika Stephen Sunday, Onyeabo Uzoamaka Agatha, Emeka Augustine Chinachi and C.O. Ugwoke. EXPLAINABLE MACHINE LEARNING FOR NETWORK INTRUSION DETECTION USING LIGHTGBM AND SHAP: AN IMPLEMENTATION STUDY ON HIKARI-2021. World Journal of Advanced Engineering Technology and Sciences, 2026, 20(03), 103–108. Article DOI: https://doi.org/10.30574/wjaets.2026.20.3.0442