Cyber threats are becoming increasingly advanced, which raises the the development of Intrusion Detection Systems (IDS) is a cornerstone for the protection of network infrastruc-tures; however, they suffer from class imbalance, model overfitting, and low interpretability. This paper presents a composite pipeline for cyber threat detection by combining three technical improvements: 1) Synthetic Minority Over-sampling Technique (SMOTE) to deal with class imbalance, 2) Bayesian optimization for hyper-parameter tuning, and 3) SHAP (SHapley Additive exPlanations) for providing model explanations. The research novelty residesin the integration of these techniques in an Artificial Neural Network (ANN) model and the establishment of an IDS framework that is both scalable and interpretable. The proposed model is tested on the CICIDS2017 dataset and attains an accuracy of 92.00%, precision 97.99%, recall of 90.00%, and AUC 1.00. It has a lifting of 2.03% (precision) and 1.21% (recall) in comparison to the baseline ANN model. The model shows a small hit on F1-score (from 92.23 to 90.99%) when trained on the entire training data, which is a compromise between precision and recall. The statistical significance of performance improvement is being further validated. SHAP visualizations offer interpretable insights into decision boundaries for support to security analysts in threat investigations. While performing well on CICIDS2017,the approach is, however, not tested against cross-domain or adversarial datasets, hence the generalization claims are limited. The synthetic sampling of SMOTE can also potentially leadto overfitting in high-dimensional feature spaces. Future works involve real-time streaming applications with Apache Kafka and testing on more recent datasets as BoT-IoT or UNSW-NB15
No takes yet. Share an insight, caveat, or question.
Saare et al. (2026) studied this question.