Explainable Tabular Deep Learning for Network Anomaly Detection: A Comparative Study of AutoInt and DANet Architectures


ASAL B.

4th Cognitive Models and Artificial Intelligence Conference, AICCONF 2026, Prague, Çek Cumhuriyeti, 24 - 25 Nisan 2026, (Tam Metin Bildiri)

  • Yayın Türü: Bildiri / Tam Metin Bildiri
  • Doi Numarası: 10.1109/aicconf69182.2026.11600649
  • Basıldığı Şehir: Prague
  • Basıldığı Ülke: Çek Cumhuriyeti
  • Anahtar Kelimeler: AutoInt, DANet, explainable artificial intelligence (XAI), network anomaly detection, SHAP
  • Hacettepe Üniversitesi Adresli: Evet

Özet

This study addresses network anomaly detection as a supervised binary classification problem by using bandwidthbased telemetry features. Specifically, inbound and outbound traffic rates and bandwidth utilization percentages are utilized to identify abnormal network behavior. Two advanced deep learning architectures developed for tabular data, which are - AutoInt and DANet, are comprehensively tested and analyzed. Experimental results demonstrate that both models achieve strong classification performance, with DANet consistently outperforming AutoInt in terms of accuracy, F1-score, and Matthews Correlation Coefficient metrics. To further enhance transparency and interpretability, SHAP-based analysis is conducted, which reveals that bandwidth utilization features have the most significant influence on anomaly estimations, while raw traffic rates play a secondary role. Overall, the findings points out the effectiveness of deep tabular architectures for network anomaly detection and show the importance of explainable model behavior in security-critical applications.