Dual view explainability-aware log preprocessing for robust anomaly detection toward ER-CyRIS
Indonesian Journal of Electrical Engineering and Computer Science
Abstract
Machine learning based intrusion detection can achieve strong benchmark performance yet remain fragile under operational telemetry changes. This paper proposes a dual-view, explainability-aware log preprocessing layer for robust anomaly detection toward ER-CyRIS. The novelty is the use of dynamic-token preservation together with feature stability score (FSS), which turns SHapley additive exPlanations (SHAP)-ranking stability into a preprocessing-level evaluation criterion rather than a post-hoc explanation only. The layer preserves structural log patterns and contextual dynamic tokens, and is evaluated through detection performance, noise degradation, and SHAP-ranking stability. A leakage-controlled ablation on HDFS, BGL, CICIDS2018, and UNSW-NB15 shows that the CICIDS2018 baseline reached F1 = 0.9999 but degraded by 68.1% for XGBoost and 93.9% for random forest under small Gaussian noise. Contextual preprocessing reduced degradation to 58.7%, 54.9%, and 53.6% in selected settings. FSS reached 100% for XGBoost on HDFS and CICIDS2018. The results show that preprocessing mitigates, but does not eliminate, operational brittleness.
Discover Our Library
Embark on a journey through our expansive collection of articles and let curiosity lead your path to innovation.





