Araştırma Makalesi

A Comparative Study of Explainable (XAI) Deep and Ensemble Learning Models for a Web Application Firewall Using the FWAF Dataset

Cilt: 13 Sayı: 3 7 Eylül 2026
PDF İndir
EN TR

A Comparative Study of Explainable (XAI) Deep and Ensemble Learning Models for a Web Application Firewall Using the FWAF Dataset

Öz

Bridging the gap between predictive accuracy and interpretability in web application security, this study benchmarks machine learning (ML) and deep learning (DL) models for intrusion detection using the publicly available FWAF dataset. We evaluate six widely used classifiers—Logistic Regression, Decision Tree, Random Forest, XGBoost, 1D-CNN, and LSTM—under a highly imbalanced setting (benign-dominant traffic). All models are trained on identical data using a unified pipeline with stratified train/validation/test splits (64%/16%/20%) and class-weight balancing to ensure a fair comparison. Models are assessed using accuracy, precision, recall, F1-score, and imbalance-aware measures (Macro-F1, PRAUC, and MCC). To improve transparency, we integrate Explainable Artificial Intelligence (XAI) techniques—specifically SHAP (SHapley Additive ExPlanations) and LIME (Local Interpretable Model-Agnostic Explanations)—to quantify feature contributions and highlight decision patterns relevant to WAF operation. An ablation study confirms that attack-indicator features (is_xss, is_lfi, is_oci, is_sqli) are derived independently from labels via regex matching, with their removal causing only marginal performance degradation (1–2% Macro-F1). Experimental results show that Random Forest achieves the strongest overall performance (99.3% accuracy, 0.949 Macro-F1, 0.935 PR-AUC), while the feature-based LSTM provides comparable results (99.2% accuracy, 0.937 Macro-F1, 0.928 PR-AUC). Ultimately, the study emphasizes the value of balancing performance with interpretability, empowering Security Operations Centers (SOC) to validate automated decisions and foster trustworthy AI-driven web application firewalls

Anahtar Kelimeler

Kaynakça

  1. [1] I. H. Sarker, "Machine Learning for Intrusion Detection: A Comparative Analysis," Computers & Security, vol. 108, p. 102433, 2022.
  2. [2] C. Yin, Y. Zhu, J. Fei, and X. He, "A Deep Learning Approach for Intrusion Detection Using Recurrent Neural Networks," IEEE Access, vol. 5, pp. 21954-21961, 2017.
  3. [3] G. Kim, S. Lee, and S. Kim, "A Novel Hybrid Intrusion Detection Method Integrating Anomaly Detection with Misuse Detection," Expert Systems with Applications, vol. 41, no. 4, pp. 1690-1700, 2014.
  4. [4] S. J. Almheiri, A. A. Shah, S. Abbas, M. Ahmad, and M. A. Khan, "Smart sustainable cyber security: modelling an interpretable and transparent threat detection with explainable artificial intelligence," Discover Sustainability, vol. 6, no. 1, p. 442, 2025/05/24 2025.
  5. [5] N. Faizan, "FWAF: Machine Learning-driven Web Application Firewall Dataset," 2020.
  6. [6] A. Sharma, S. Rani, and M. Shabaz, "A comprehensive review of explainable AI in cybersecurity: Decoding the black box," ICT Express, vol. 11, no. 6, pp. 1200-1219, 2025/12/01/ 2025.
  7. [7] P. Hermosilla, S. Berríos, and H. Allende-Cid, "Explainable AI for Forensic Analysis: A Comparative Study of SHAP and LIME in Intrusion Detection Models," Applied Sciences, vol. 15, no. 13, p. 7329, 2025.
  8. [8] V. Z. Mohale and I. C. Obagbuwa, "A systematic review on the integration of explainable artificial intelligence in intrusion detection systems to enhancing transparency and interpretability in cybersecurity," (in English), Frontiers in Artificial Intelligence, Systematic Review vol. Volume 8 - 2025, 2025-January-28 2025.

Ayrıntılar

Birincil Dil

İngilizce

Konular

Mühendislik Uygulaması ve Eğitim (Diğer)

Bölüm

Araştırma Makalesi

Yayımlanma Tarihi

7 Eylül 2026

Gönderilme Tarihi

31 Temmuz 2025

Kabul Tarihi

17 Haziran 2026

Yayımlandığı Sayı

Yıl 2026 Cilt: 13 Sayı: 3

Kaynak Göster

APA
Ünlü, F., Sönmez, Y., & Dener, M. (2026). A Comparative Study of Explainable (XAI) Deep and Ensemble Learning Models for a Web Application Firewall Using the FWAF Dataset. El-Cezeri, 13(3), 438-453. https://doi.org/10.31202/ecjse.1742467
AMA
1.Ünlü F, Sönmez Y, Dener M. A Comparative Study of Explainable (XAI) Deep and Ensemble Learning Models for a Web Application Firewall Using the FWAF Dataset. ECJSE. 2026;13(3):438-453. doi:10.31202/ecjse.1742467
Chicago
Ünlü, Fatih, Yusuf Sönmez, ve Murat Dener. 2026. “A Comparative Study of Explainable (XAI) Deep and Ensemble Learning Models for a Web Application Firewall Using the FWAF Dataset”. El-Cezeri 13 (3): 438-53. https://doi.org/10.31202/ecjse.1742467.
EndNote
Ünlü F, Sönmez Y, Dener M (01 Eylül 2026) A Comparative Study of Explainable (XAI) Deep and Ensemble Learning Models for a Web Application Firewall Using the FWAF Dataset. El-Cezeri 13 3 438–453.
IEEE
[1]F. Ünlü, Y. Sönmez, ve M. Dener, “A Comparative Study of Explainable (XAI) Deep and Ensemble Learning Models for a Web Application Firewall Using the FWAF Dataset”, ECJSE, c. 13, sy 3, ss. 438–453, Eyl. 2026, doi: 10.31202/ecjse.1742467.
ISNAD
Ünlü, Fatih - Sönmez, Yusuf - Dener, Murat. “A Comparative Study of Explainable (XAI) Deep and Ensemble Learning Models for a Web Application Firewall Using the FWAF Dataset”. El-Cezeri 13/3 (01 Eylül 2026): 438-453. https://doi.org/10.31202/ecjse.1742467.
JAMA
1.Ünlü F, Sönmez Y, Dener M. A Comparative Study of Explainable (XAI) Deep and Ensemble Learning Models for a Web Application Firewall Using the FWAF Dataset. ECJSE. 2026;13:438–453.
MLA
Ünlü, Fatih, vd. “A Comparative Study of Explainable (XAI) Deep and Ensemble Learning Models for a Web Application Firewall Using the FWAF Dataset”. El-Cezeri, c. 13, sy 3, Eylül 2026, ss. 438-53, doi:10.31202/ecjse.1742467.
Vancouver
1.Fatih Ünlü, Yusuf Sönmez, Murat Dener. A Comparative Study of Explainable (XAI) Deep and Ensemble Learning Models for a Web Application Firewall Using the FWAF Dataset. ECJSE. 01 Eylül 2026;13(3):438-53. doi:10.31202/ecjse.1742467