| Titre : |
AI-IDS : A hierarchical two-stage network intrusion detection system with SHAP explainability |
| Type de document : |
document multimédia |
| Auteurs : |
Hassan Bachir Belhadj, Auteur ; Nacer Salaheddine Taleb, Auteur ; Yousra Cheriguene, Directeur de thèse |
| Editeur : |
Laghouat : Université Amar Telidji - Département d'informatique |
| Année de publication : |
2026 |
| Importance : |
46 p. |
| Accompagnement : |
1 disque optique numérique (CD-ROM) |
| Note générale : |
Option : Networks, systems and distributed applications |
| Langues : |
Anglais (eng) |
| Mots-clés : |
Intrusion detection Hierarchical classification Random forest XGBoost SHAP Explainability CICIDS2017 CSE-CIC-IDS2018 FastAPI React |
| Résumé : |
This thesis presents AI-IDS, a full-stack machine learning system for network intrusion detection combining a two-stage hierarchical pipeline, joint multi-dataset training, and integrated SHAP explainability. The system implements a two-stage cascade : a Random Forest binary classifier (Stage 1) separates normal from malicious traffic; an XGBoost multiclass classifier (Stage 2) identifies the specific attack category among 14 known attack types. Both models are trained jointly on a combined corpus of 562 731 flow records drawn from two public benchmarks: CICIDS2017 and CSE-CIC-IDS2018 after a rigorous preprocessing pipeline that unifies their heterogeneous column schemas, normalises labels, handles infinite values, and applies stratified sampling to preserve rare attack classes. SHAP (SHapley Additive exPlanations) via TreeExplainer provides global and per-flow feature attribution, bridging the gap between opaque model decisions and actionable analyst insight. The system is deployed as a full-stack application : a FastAPI backend exposes the complete ML pipeline through a REST + Web- Socket API, and a React frontend provides interactive dashboards for file management, batch analysis, live simulation, and model evaluation. Experimental evaluation on the held-out test set achieves 93.73% accuracy and 93.70% weighted F1-score on the binary classifier, and 96.49% accuracy and 96.40% weighted F1-score on the 14-class attack classifier. |
| note de thèses : |
Mémoire de master en informatique |
AI-IDS : A hierarchical two-stage network intrusion detection system with SHAP explainability [document multimédia] / Hassan Bachir Belhadj, Auteur ; Nacer Salaheddine Taleb, Auteur ; Yousra Cheriguene, Directeur de thèse . - Laghouat : Université Amar Telidji - Département d'informatique, 2026 . - 46 p. + 1 disque optique numérique (CD-ROM). Option : Networks, systems and distributed applications Langues : Anglais ( eng)
| Mots-clés : |
Intrusion detection Hierarchical classification Random forest XGBoost SHAP Explainability CICIDS2017 CSE-CIC-IDS2018 FastAPI React |
| Résumé : |
This thesis presents AI-IDS, a full-stack machine learning system for network intrusion detection combining a two-stage hierarchical pipeline, joint multi-dataset training, and integrated SHAP explainability. The system implements a two-stage cascade : a Random Forest binary classifier (Stage 1) separates normal from malicious traffic; an XGBoost multiclass classifier (Stage 2) identifies the specific attack category among 14 known attack types. Both models are trained jointly on a combined corpus of 562 731 flow records drawn from two public benchmarks: CICIDS2017 and CSE-CIC-IDS2018 after a rigorous preprocessing pipeline that unifies their heterogeneous column schemas, normalises labels, handles infinite values, and applies stratified sampling to preserve rare attack classes. SHAP (SHapley Additive exPlanations) via TreeExplainer provides global and per-flow feature attribution, bridging the gap between opaque model decisions and actionable analyst insight. The system is deployed as a full-stack application : a FastAPI backend exposes the complete ML pipeline through a REST + Web- Socket API, and a React frontend provides interactive dashboards for file management, batch analysis, live simulation, and model evaluation. Experimental evaluation on the held-out test set achieves 93.73% accuracy and 93.70% weighted F1-score on the binary classifier, and 96.49% accuracy and 96.40% weighted F1-score on the 14-class attack classifier. |
| note de thèses : |
Mémoire de master en informatique |
|  |