CLEAR-IDS: Leakage-Free Adaptive Resampling and Diversity-Weighted Explainable Ensemble Learning for Network Intrusion Detection
Main Article Content
Abstract
Reliable network intrusion detection requires more than high aggregate accuracy because data leakage, severe class imbalance, unstable feature selection, redundant ensemble decisions, and poorly calibrated probabilities can produce optimistic yet operationally weak results. This study presents CLEAR-IDS, a cross-fold leakage-free explainable framework that integrates fold-contained preprocessing, stability-aware multi-attribution feature selection, class-aware adaptive resampling, diversity-weighted ensemble learning, threshold optimization, and multi-level explanations. The framework was evaluated on the official UNSW-NB15 partitions using stratified five-fold model development and an untouched test set. SHAP, permutation importance, and mutual information were combined with redundancy control; Borderline-SMOTE, SMOTE-ENN, SMOTE-Tomek, ADASYN, and no resampling were assessed only within training folds; and random forest, XGBoost, and multilayer perceptron models were aggregated according to out-of-fold quality, diversity, and stability. For binary detection, the optimized CLEAR-IDS decision rule achieved 87.94% accuracy, 86.83% balanced accuracy, 87.45% Macro-F1, and a 24.08% false-positive rate, improving Macro-F1 by 0.96 percentage points over the strongest tested binary baseline. In ten-class detection, CLEAR-IDS achieved 52.00% Macro-F1 and did not surpass XGBoost (52.42%), revealing persistent difficulty for Analysis and Backdoor. The controller selected Borderline-SMOTE in three folds and no resampling in two, while the final 25-feature subset showed strong cross-fold stability (mean Jaccard 0.8803; mean Spearman 0.9421). Temperature scaling worsened NLL, Brier score, and ECE, underscoring the importance of reporting negative calibration results. The findings indicate that leakage control and adaptive decision design improve binary reliability, although rare overlapping attack classes remain an open challenge.
Article Details
Section

This work is licensed under a Creative Commons Attribution 4.0 International License.
How to Cite
References
[1] M. Keshk, N. Koroniotis, N. Pham, N. Moustafa, B. Turnbull, and A. Y. Zomaya, “An explainable deep learning-enabled intrusion detection framework in IoT networks,” Information Sciences, vol. 639, Art. no. 119000, 2023, doi: 10.1016/j.ins.2023.119000.
[2] M. M. Alani, “An explainable efficient flow-based Industrial IoT intrusion detection system,” Computers & Electrical Engineering, vol. 108, Art. no. 108732, 2023, doi: 10.1016/j.compeleceng.2023.108732.
[3] B. Sharma, L. Sharma, C. Lal, and S. Roy, “Explainable artificial intelligence for intrusion detection in IoT networks: A deep learning based approach,” Expert Systems with Applications, vol. 238, Art. no. 121751, 2024, doi: 10.1016/j.eswa.2023.121751.
[4] C. E. Ben Ncir, M. A. Ben HajKacem, and M. Alattas, “Enhancing intrusion detection performance using explainable ensemble deep learning,” PeerJ Computer Science, vol. 10, e2289, 2024, doi: 10.7717/peerj-cs.2289.
[5] Y. Yin, J. Jang-Jaccard, W. Xu, A. Singh, J. Zhu, F. Sabrina, and J. Kwak, “IGRF-RFE: A hybrid feature selection method for MLP-based network intrusion detection on UNSW-NB15 dataset,” Journal of Big Data, vol. 10, Art. no. 15, 2023, doi: 10.1186/s40537-023-00694-8.
[6] S. Sadhwani, A. Navare, A. Mohan, R. Muthalagu, and P. M. Pawar, “IoT-based intrusion detection system using explainable multiclass deep learning approaches,” Computers & Electrical Engineering, vol. 123, Art. no. 110256, 2025, doi: 10.1016/j.compeleceng.2025.110256.
[7] S. Bagui, D. Mink, S. Bagui, S. Subramaniam, and D. Wallace, “Resampling imbalanced network intrusion datasets to identify rare attacks,” Future Internet, vol. 15, no. 4, Art. no. 130, 2023, doi: 10.3390/fi15040130.
[8] Z. Zoghi and G. Serpen, “Building an intrusion detection system on UNSW-NB15: Reducing the margin of error to deal with data overlap and imbalance,” Concurrency and Computation: Practice and Experience, vol. 36, no. 25, e8242, 2024, doi: 10.1002/cpe.8242.
[9] V. Shanmugam, R. Razavi-Far, and E. Hallaji, “Addressing class imbalance in intrusion detection: A comprehensive evaluation of machine learning approaches,” Electronics, vol. 14, no. 1, Art. no. 69, 2025, doi: 10.3390/electronics14010069.
[10] R. Harini, N. Maheswari, S. Ganapathy, and M. Sivagami, “An effective technique for detecting minority attacks in NIDS using deep learning and sampling approach,” Alexandria Engineering Journal, vol. 78, pp. 469–482, 2023, doi: 10.1016/j.aej.2023.07.063.
[11] S. Kapoor and A. Narayanan, “Leakage and the reproducibility crisis in machine-learning-based science,” Patterns, vol. 4, no. 9, Art. no. 100804, 2023, doi: 10.1016/j.patter.2023.100804.
[12] M. A. Bouke and A. Abdullah, “An empirical study of pattern leakage impact during data preprocessing on machine learning-based intrusion detection models reliability,” Expert Systems with Applications, vol. 230, Art. no. 120715, 2023, doi: 10.1016/j.eswa.2023.120715.
[13] H. Bakır and Ö. Ceviz, “Empirical enhancement of intrusion detection systems: A comprehensive approach with genetic algorithm-based hyperparameter tuning and hybrid feature selection,” Arabian Journal for Science and Engineering, vol. 49, pp. 13025–13043, 2024, doi: 10.1007/s13369-024-08949-z.
[14] Y. Cao, Z. Wang, H. Ding, J. Zhang, and B. Li, “An intrusion detection system based on stacked ensemble learning for IoT network,” Computers & Electrical Engineering, vol. 110, Art. no. 108836, 2023, doi: 10.1016/j.compeleceng.2023.108836.
[15] T.-T.-H. Le, Y. Shin, M. Kim, and H. Kim, “Towards unbalanced multiclass intrusion detection with hybrid sampling methods and ensemble classification,” Applied Soft Computing, vol. 157, Art. no. 111517, 2024, doi: 10.1016/j.asoc.2024.111517.
[16] M. Al-Ajlan and M. Ykhlef, “GAN-AHR: A GAN-based adaptive hybrid resampling algorithm for imbalanced intrusion detection,” Electronics, vol. 14, no. 17, Art. no. 3476, 2025, doi: 10.3390/electronics14173476.
[17] P. Hermosilla, S. Berríos, and H. Allende-Cid, “Explainable AI for forensic analysis: A comparative study of SHAP and LIME in intrusion detection models,” Applied Sciences, vol. 15, no. 13, Art. no. 7329, 2025, doi: 10.3390/app15137329.
[18] V. Z. Mohale and I. C. Obagbuwa, “A systematic review on the integration of explainable artificial intelligence in intrusion detection systems to enhancing transparency and interpretability in cybersecurity,” Frontiers in Artificial Intelligence, vol. 8, Art. no. 1526221, 2025, doi: 10.3389/frai.2025.1526221.
[19] J. Talpini, F. Sartori, and M. Savi, “Enhancing trustworthiness in ML-based network intrusion detection with uncertainty quantification,” Journal of Reliable Intelligent Environments, vol. 10, pp. 501–520, 2024, doi: 10.1007/s40860-024-00238-8.
[20] S. Al and Ş. Sağıroğlu, “Explainable artificial intelligence models in intrusion detection systems,” Engineering Applications of Artificial Intelligence, vol. 144, Art. no. 110145, 2025, doi: 10.1016/j.engappai.2025.110145.
[21] U. Ahmed, Z. Jiangbin, A. Almogren, S. Khan, M. T. Sadiq, A. Altameem, and A. Ur Rehman, “Explainable AI-based innovative hybrid ensemble model for intrusion detection,” Journal of Cloud Computing, vol. 13, Art. no. 150, 2024, doi: 10.1186/s13677-024-00712-x.
[22] A. M. Alsaffar, M. Nouri-Baygi, and H. M. Zolbanin, “Shielding networks: Enhancing intrusion detection with hybrid feature selection and stack ensemble learning,” Journal of Big Data, vol. 11, Art. no. 133, 2024, doi: 10.1186/s40537-024-00994-7.
[23] S. Walling and S. Lodh, “Enhancing IoT intrusion detection through machine learning with AN-SFS: A novel approach to high performing adaptive feature selection,” Discover Internet of Things, vol. 4, Art. no. 16, 2024, doi: 10.1007/s43926-024-00074-5.
[24] S. More, M. Idrissi, H. Mahmoud, and A. T. Asyhari, “Enhanced intrusion detection systems performance with UNSW-NB15 data analysis,” Algorithms, vol. 17, no. 2, Art. no. 64, 2024, doi: 10.3390/a17020064.
[25] A. G. Ayad, N. A. Sakr, and N. A. Hikal, “A hybrid approach for efficient feature selection in anomaly intrusion detection for IoT networks,” Journal of Supercomputing, vol. 80, pp. 26942–26984, 2024, doi: 10.1007/s11227-024-06409-x.