Dual view explainability-aware log preprocessing for robust anomaly detection toward ER-CyRIS
Abstract
Machine learning based intrusion detection can achieve strong benchmark performance yet remain fragile under operational telemetry changes. This paper proposes a dual-view, explainability-aware log preprocessing layer for robust anomaly detection toward ER-CyRIS. The novelty is the use of dynamic-token preservation together with feature stability score (FSS), which turns SHapley additive exPlanations (SHAP)-ranking stability into a preprocessing-level evaluation criterion rather than a post-hoc explanation only. The layer preserves structural log patterns and contextual dynamic tokens, and is evaluated through detection performance, noise degradation, and SHAP-ranking stability. A leakage-controlled ablation on HDFS, BGL, CICIDS2018, and UNSW-NB15 shows that the CICIDS2018 baseline reached F1 = 0.9999 but degraded by 68.1% for XGBoost and 93.9% for random forest under small Gaussian noise. Contextual preprocessing reduced degradation to 58.7%, 54.9%, and 53.6% in selected settings. FSS reached 100% for XGBoost on HDFS and CICIDS2018. The results show that preprocessing mitigates, but does not eliminate, operational brittleness.
Keywords
Anomaly detection; Dynamic token preservation; Explainability intrusion detection; Feature stability score; Noise robustness; SHAP stability
Full Text:
PDFDOI: http://doi.org/10.11591/ijeecs.v43.i3.pp871-879
Refbacks
- There are currently no refbacks.

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
Indonesian Journal of Electrical Engineering and Computer Science (IJEECS)
p-ISSN: 2502-4752, e-ISSN: 2502-4760
This journal is published by the Institute of Advanced Engineering and Science (IAES).