Dual view explainability-aware log preprocessing for robust anomaly detection toward ER-CyRIS

Fathoni Mahardika, Ema Utami, Kusrini Kusrini, Ferry Wahyu Wibowo

Abstract


Machine learning based intrusion detection can achieve strong benchmark performance yet remain fragile under operational telemetry changes. This paper proposes a dual-view, explainability-aware log preprocessing layer for robust anomaly detection toward ER-CyRIS. The novelty is the use of dynamic-token preservation together with feature stability score (FSS), which turns SHapley additive exPlanations (SHAP)-ranking stability into a preprocessing-level evaluation criterion rather than a post-hoc explanation only. The layer preserves structural log patterns and contextual dynamic tokens, and is evaluated through detection performance, noise degradation, and SHAP-ranking stability. A leakage-controlled ablation on HDFS, BGL, CICIDS2018, and UNSW-NB15 shows that the CICIDS2018 baseline reached F1 = 0.9999 but degraded by 68.1% for XGBoost and 93.9% for random forest under small Gaussian noise. Contextual preprocessing reduced degradation to 58.7%, 54.9%, and 53.6% in selected settings. FSS reached 100% for XGBoost on HDFS and CICIDS2018. The results show that preprocessing mitigates, but does not eliminate, operational brittleness.

Keywords


Anomaly detection; Dynamic token preservation; Explainability intrusion detection; Feature stability score; Noise robustness; SHAP stability

Full Text:

PDF


DOI: http://doi.org/10.11591/ijeecs.v43.i3.pp871-879

Refbacks

  • There are currently no refbacks.


Creative Commons License
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.

Indonesian Journal of Electrical Engineering and Computer Science (IJEECS)
p-ISSN: 2502-4752, e-ISSN: 2502-4760
This journal is published by the Institute of Advanced Engineering and Science (IAES).

shopify stats IJEECS visitor statistics