Explainable AI for Multi-stage Cyber Attack Detection Using SHAP Fingerprints

Authors

DOI:

https://doi.org/10.70917/ijcisim-2026-5186

Abstract

Conventional intrusion detection systems can identify malicious traffic, but they provide limited insight into how an attack progresses across its lifecycle. This research addresses this gap by proposing Explainable Attack Progression Prediction (EAPP), a framework that predicts cyber attack stages rather than simply flagging malicious traffic. Network traffic is categorized into seven classes, comprising normal traffic and six attack progression stages adapted from the Cyber Kill Chain: reconnaissance, initial access, exploitation, lateral movement, command-and-control/persistence, and data exfiltration. Multi-class machine learning models, XGBoost and Random Forest, are trained on 211,043 network flow samples from the TON_IoT dataset. The key innovation is the generation of stage-wise SHAP fingerprints that characterize feature-importance patterns associated with each attack stage, enabling security analysts to understand which network behaviors contribute to stage classification. Stage-wise evolution analysis further examines how feature importance changes across the attack lifecycle, producing distinctive progression signatures for different stages. On the test set, XGBoost achieved 99.27% accuracy, while Random Forest achieved 99.29% accuracy. Stage-specific analysis showed that normal traffic emphasizes destination ports, reconnaissance highlights connection attempts, exploitation reflects data-transfer anomalies, C2/persistence emphasizes connection-state indicators, and data exfiltration is associated with high-volume data transfers. Overall, EAPP extends conventional binary IDS analysis toward interpretable multi-stage attack understanding by combining attack-stage prediction with SHAP-based fingerprints and stage-wise progression analysis.

Downloads

Download data is not yet available.

Downloads

Published

2026-08-26

How to Cite

Maryam Nageen, & Muhammad Ammad Idrees. (2026). Explainable AI for Multi-stage Cyber Attack Detection Using SHAP Fingerprints. International Journal of Computer Information Systems and Industrial Management Applications, 18(20s), 362–372. https://doi.org/10.70917/ijcisim-2026-5186

Issue

Section

Original Articles