Uppsats
Explainable Machine Learning for Darknet Traffic Analysis: A Replication and Extension Study
Yrkesexamen på grundnivå
Örebro universitet/Institutionen för naturvetenskap och teknik
Publicerad: 2026
Språk: Engelska
Sammanfattning
The increasing use of anonymization technologies such as Tor and Virtual Private Networks (VPNs) has made network traffic classification a critical challenge in modern cybersecurity. While machine learning models have demonstrated high accuracy in distinguishing between different types of darknet traffic, their black-box nature limits trust, interpretability, and operational usability. Explainable Artificial Intelligence (XAI) techniques have been proposed to address this limitation by providing insights into model decision-making. However, existing studies largely focus on feature attribution and do not fully capture model behavior in complex and ambiguous classification scenarios. This thesis presents a replication and extension of the study XAITrafficIntell: Interpretable Cyber Threat Intelligence for Darknet Traffic Analysis, with the goal of validating its results and enhancing the interpretability of network traffic classification models. The replication faithfully reproduces the datasets, preprocessing steps, machine learning models, evaluation metrics, and explainability methods of the original study using the ISCX-Tor 2016 and CIC-Darknet 2020 datasets. Experimental results closely match those reported in the original work, confirming the robustness and reproducibility of the baseline findings. Building upon this replication, the thesis extends the original study by introducing additional explainability techniques that address limitations of attribution-based methods. Partial Dependence Plots (PDP) and Individual Conditional Expectation (ICE) curves are applied to analyze how model predictions change as feature values vary, providing behavioral insights into non-linear decision patterns. Submodular Pick LIME (SP-LIME) is further employed to identify representative explanations that summarize global model behavior. These extensions are particularly valuable for the CIC-Darknet 2020 dataset, where overlapping characteristics between Tor and VPN traffic complicate interpretation. The results demonstrate that while attribution-based XAI methods such as SHAP and LIME are sufficient for simpler classification tasks, extended explainability techniques offer substantial additional insight in complex darknet scenarios. By combining global, local, behavioral, and representative explanations, this thesis contributes a more comprehensive and analyst-oriented understanding of machine learning decision-making in network traffic classification.
Information
- Författare
- Hashem, Edrees
- Lärosäte / institution
- Örebro universitet/Institutionen för naturvetenskap och teknik
- Publiceringsdatum
- 2026
- Uppsatstyp
- Yrkesexamen på grundnivå
- Språk
- Engelska
Utforska vidare
Liknande uppsatser
Uppsatser med liknande ämnen och nyckelord.
Master-uppsats, Lunds universitet/Institutionen för elektro- och informationsteknik
Müller, Arvid, Flynn Rosenberg, Elias
Publicerad: 2026
Master-uppsats, Göteborgs universitet/Graduate School
Enges, Emil, Lundgren, Olle
Publicerad: 2026-07-02
Kandidat-uppsats, Göteborgs universitet/Institutionen för data- och informationsteknik
Lindström Bermann,Freja Nicole Tiger, Edlund, Jennie, Rankanen Jason, Isac
Publicerad: 2026-02-23
Master-uppsats, Luleå tekniska universitet/Institutionen för system- och rymdteknik
Ali, Qasim
Publicerad: 2026
M1-uppsats, Jönköping University/JTH, Avdelningen för datateknik och informatik
Seyhani Porshekoh, Artin
Publicerad: 2026
Kandidat-uppsats, Högskolan i Skövde/Institutionen för handel och företagande
Kling, Ellen, Rakh, Shilan
Publicerad: 2026