TabNet for Intrusion Detection: Bridging Accuracy and Interpretability in Tabular

Research output: Chapter in Book/Published conference outputConference publication

Abstract

Intrusion Detection Systems (IDS) must balance accuracy with interpretability, yet existing approaches often sacrifice one for the other. Classical machine learning methods such as Logistic Regression and Random Forest provide solid accuracy but limited transparency, while deep learning models like CNNs act as black boxes. This paper evaluates TabNet, a deep neural architecture designed for tabular data, as a candidate for IDS. TabNet leverages sequential attention and sparse feature selection, enabling both high performance and feature-level interpretability. We test TabNet on UNSW-NB15, BoT-IoT, and KDD CUP and compare it with Logistic Regression, Random Forest, SVM, and Naïve Bayes. Results show that TabNet achieves near-perfect detection on BoT-IoT (99.98%) and KDD (99.98%), while remaining highly competitive on UNSW-NB15 (99.30%). Its attention masks highlight meaningful features such as flow duration and packet rate, providing actionable insights for analysts. TabNet thus offers a practical trade-off between accuracy and explainability, making it well-suited for next-generation IDS.
Original languageEnglish
Title of host publicationTrends in Sustainable Computing and Machine Intelligence: Proceedings of ICTSM 2025
EditorsSurekha Lanka, Antonio Sarasa Cabezuelo, Alexandru Tugui
Pages470-484
Number of pages15
ISBN (Electronic)9783032131775 (ebk)
DOIs
Publication statusPublished - 17 Jan 2026

Publication series

NameLecture Notes in Networks and Systems (LNNS)
PublisherSpringer Cham
Volume1755
ISSN (Print)2367-3370
ISSN (Electronic)2367-3389

Keywords

  • IDS
  • Naive Bayes
  • SVM
  • TabNet

Fingerprint

Dive into the research topics of 'TabNet for Intrusion Detection: Bridging Accuracy and Interpretability in Tabular'. Together they form a unique fingerprint.

Cite this