PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
May 31, 2026PeerJ Computer Science0 citationsOpen Access

Explainable artificial intelligence techniques for hierarchical classification of diversified darknet traffic flows

View Full Paper
RWRegis Anne W.KGKirubavathi GanapathiyappanHRHarshanth Ravindran

Key Points

  • This research aims to develop a resilient explainable AI framework for detecting malicious behaviors in encrypted darknet traffic.
  • Integrates transformer architecture with adversarial and interpretability models.
  • Utilizes SMOTE, ADASYN, and Borderline-SMOTE for data imbalance mitigation.
  • Assesses various machine learning and deep learning models for performance under adversarial conditions.
  • Achieves an accuracy of up to 98% with the proposed framework under adversarial conditions.
  • TabPFN demonstrated an accuracy of 98.8%, outperforming other models.
  • Utilizing SHAP, the framework achieved an AUC of 99.32%, indicating strong explainability.

Abstract

Encrypted darknet traffic utilizes robust encryption and obfuscation techniques to evade traditional signature-based Deep Packet Inspection (DPI) methods. Therefore, the detection systems rely on Machine Learning (ML) and Deep Learning (DL) to operate in real-time and identify malicious behaviour in encrypted traffic patterns. However, prior research ignored class imbalance, model resilience, and generalization, which resulted in biased classifiers that performed poorly on new data or under adversarial situations. To address these challenges, we propose a novel Resilient Explainable Artificial Intelligence (XAI) framework for darknet traffic detection by integrating transformer architecture with adversarial and interpretability models. Data imbalance is handled using Synthetic Minority Over-Sampling Technique (SMOTE), Adaptive Synthetic Sampling (ADASYN), and Borderline-SMOTE, combined through a soft-voting ensemble. This method achieves an accuracy of up to 98% while lowering bias and enhancing model stability. Among the ML models assessed, Light Gradient Boosting Machine (LightGBM) and Random Forest attained the highest accuracies of 99.93% and 99.91%, respectively, but their performance degraded under adversarial conditions. Therefore, Hybrid DL architectures like Convolutional Neural Network (CNN) combined with Long Short-Term Memory (LSTM) and a Sparse Autoencoder (SAE) integrated with a Support Vector Machine (SVM), and the recent transformer-based architecture Tabular Prior Data Fitted Network (TabPFN) were assessed. TabPFN outperformed with an accuracy of 98.8%, demonstrating strong potential for darknet traffic detection. Therefore, we propose a novel framework that has TabPFN as a foundation model, and it is integrated with adversarial learning techniques such as Fast Gradient Sign Method (FGSM) and Projected Gradient Descent (PGD) to evaluate resilience. The proposed framework outpaced other conventional architectures with an accuracy of 98% under FGSM and 99% under PGD, proving adversarial robustness and detecting zero-day threats. Also, the proposed framework demonstrated superior cross-data generalisation, yielding accuracies of 99.73% and 99.01% when trained on CIC-Darknet2020 and tested on BCCC-Darknet-2025 under FGSM and PGD, respectively. Finally, to make the framework interpretable, it is experimented with SHapley Additive exPlanations (SHAP), Local Interpretable Model-agnostic Explanations (LIME), and Permutation Feature Importance (PFI) to enhance explainability in threat detection. The proposed framework with SHAP provided the most consistent and interpretable explanations, achieving an Area Under Curve (AUC) of 99.32%. This proposed end-to-end framework combines transformer-based learning with class imbalance mitigation, adversarial robustness, and XAI for real-time darknet traffic detection in encrypted environments.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

W. et al. (2026) studied this question.

synapsesocial.com/papers/6a1bd2375783ba022b6fdabahttps://doi.org/10.7717/peerj-cs.3809
Ask AI
Helpful
Bookmark
Share
View Full Paper

Also Consider

Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context:

  1. 1An Explainable Deep Learning Framework for Intrusion Detection2026
  2. 2An Explainable Deep Learning Framework for Intrusion Detection2026
  3. 3XAI-Enhanced adversarial resilient deep learning framework for transparent and secure edge deployment in consumer Internet of Things/Industrial Internet of Things environments2026 · 8 citations
  4. 4A domain-agnostic explainable framework for network attack detection across diverse traffic datasets2026
  5. 5A Privacy-Preserving Explainable Artificial Intelligence Hybrid Framework for Abnormal Network Traffic Identification and Intelligent Threat Detection2026