Title: Cross-year cyber-attack detection and temporal generalisation: an explainable machine learning approach
Authors: Archana R. Laddhad; Gurveen Vaseer
Addresses: Faculty of Computer Science, Oriental University, Indore – Madhya Pradesh 453555, India ' Faculty of Computer Science, Oriental University, Indore – Madhya Pradesh 453555, India
Abstract: The rapid evolution of cyber threats presents significant challenges for intrusion detection systems (IDS), particularly when it comes to adapting to new and unseen attack patterns. This study investigates the effectiveness of cross-year cyber-attack classification, with a focus on explainable machine learning (ML) to diagnose and understand the evolving nature of cyber threats. Specifically, we leverage decision trees as an interpretable model to identify critical features that contribute to the classification of network traffic, allowing for a transparent understanding of the decision-making process. By analysing and comparing the attack patterns across two years, we explore the changes in feature importance and the shifting characteristics of emerging threats. The findings highlight the challenges posed by evolving attacks and demonstrate how explainable ML methods can enhance the interpretability of IDS models, improving their ability to adapt to new threats. This work contributes valuable insights into the dynamic nature of cyber threats and emphasises the need for IDS systems that are both adaptive and transparent in their operation.
Keywords: cybersecurity; intrusion detection systems; IDS; explainable machine learning; decision trees; cross-year analysis.
DOI: 10.1504/IJICS.2026.154856
International Journal of Information and Computer Security, 2026 Vol.30 No.3, pp.394 - 420
Received: 15 Nov 2025
Accepted: 12 Mar 2026
Published online: 16 Jul 2026 *