Uppsats

Explainable Machine Learning for Darknet Traffic Analysis: A Replication and Extension Study

Yrkesexamen på grundnivå

Örebro universitet/Institutionen för naturvetenskap och teknik

Publicerad: 2026

Språk: Engelska

Sammanfattning

The increasing use of anonymization technologies such as Tor and Virtual Private Networks (VPNs) has made network traffic classification a critical challenge in modern cybersecurity. While machine learning models have demonstrated high accuracy in distinguishing between different types of darknet traffic, their black-box nature limits trust, interpretability, and operational usability. Explainable Artificial Intelligence (XAI) techniques have been proposed to address this limitation by providing insights into model decision-making. However, existing studies largely focus on feature attribution and do not fully capture model behavior in complex and ambiguous classification scenarios. This thesis presents a replication and extension of the study XAITrafficIntell: Interpretable Cyber Threat Intelligence for Darknet Traffic Analysis, with the goal of validating its results and enhancing the interpretability of network traffic classification models. The replication faithfully reproduces the datasets, preprocessing steps, machine learning models, evaluation metrics, and explainability methods of the original study using the ISCX-Tor 2016 and CIC-Darknet 2020 datasets. Experimental results closely match those reported in the original work, confirming the robustness and reproducibility of the baseline findings. Building upon this replication, the thesis extends the original study by introducing additional explainability techniques that address limitations of attribution-based methods. Partial Dependence Plots (PDP) and Individual Conditional Expectation (ICE) curves are applied to analyze how model predictions change as feature values vary, providing behavioral insights into non-linear decision patterns. Submodular Pick LIME (SP-LIME) is further employed to identify representative explanations that summarize global model behavior. These extensions are particularly valuable for the CIC-Darknet 2020 dataset, where overlapping characteristics between Tor and VPN traffic complicate interpretation. The results demonstrate that while attribution-based XAI methods such as SHAP and LIME are sufficient for simpler classification tasks, extended explainability techniques offer substantial additional insight in complex darknet scenarios. By combining global, local, behavioral, and representative explanations, this thesis contributes a more comprehensive and analyst-oriented understanding of machine learning decision-making in network traffic classification.

Information

Författare
Hashem, Edrees
Lärosäte / institution
Örebro universitet/Institutionen för naturvetenskap och teknik
Publiceringsdatum
2026
Uppsatstyp
Yrkesexamen på grundnivå
Språk
Engelska

Utforska vidare

Liknande uppsatser

Uppsatser med liknande ämnen och nyckelord.