VLDB 2026 Research / reviewers in the wild / expert
Rajesh Kalakoti
dblp:328/9551
· DBLP profile ↗
9ranked-venue papers
6as first author
9since 2021 · last 2026
0000-0001-7390-8034ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 1 first-author · 4 since 2021Computer networks · 3 · 3 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 2 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Incremental Federated Learning for Intrusion Detection in IoT Networks under Evolving Threat LandscapeabstractInternational audience Muaan ur Rehman, Hayretdin Bahsi, Rajesh Kalakoti |
ICISSP (1) | 3 |
| 2026 | Synthetic Data-Driven Explainability for Federated Learning-Based Intrusion Detection SystemabstractAn Intrusion Detection System (IDS) is vital for monitoring network traffic and alerting users to threats. Unlike traditional IDS, which relies on centralized data processing and raises privacy concerns, Federated Learning (FL)-based IDSs enable collaborative model training among multiple clients while keeping user data private. However, explaining model behavior in FL using Explainable AI (XAI) is challenging due to its distributed nature and lack of access to client data. Traditional XAI methods like LIME and SHAP require input data, which conflicts with FL’s privacy constraints. In this work, we develop a deep neural network (DNN)-based IDS in FL setup in Non-IID (non-independent and identically distributed) settings. Our FL-DNN model achieves high performance in binary classification for detecting malicious network traffic. In this work, we propose a novel privacy-preserving, explainable federated learning framework that uses high-quality synthetic data to enable explainability of the Global DNN model without exposing client data to the server. To generate synthetic data, we train multiple federated generative models in Non-IID settings. Among them, the Federated Wasserstein Conditional GAN with Gradient Penalty (FL-WCGAN-GP) produces synthetic samples with high data quality at the server. These synthetic samples on the server side are then used as reference inputs for post-hoc XAI methods for explaining the global DNN model. We assess the sufficiency of synthetic data-based explanations for the Global DNN model using SHAP, showing that Synthetic data-based explanations closely approximate the explanations derived from real client data. Further, we quantitatively evaluate post-local explanations of LIME and SHAP based on faithfulness and robustness. Results show that SHAP provides more faithful and robust explanations than LIME for client-side models using real data and server-side models using synthetic data, supporting privacy-preserving explainability in trustworthy FL-based IDS. Rajesh Kalakoti, Hayretdin Bahsi, Sven Nomm |
IEEE Internet Things J. | 1 |
| 2025 | Evaluating Explainable AI for Deep Learning-Based Network Intrusion Detection System Alert ClassificationabstractA Network Intrusion Detection System (NIDS) monitors networks for cyber attacks and other unwanted activities. However, NIDS solutions often generate an overwhelming number of alerts daily, making it challenging for analysts to prioritize high-priority threats. While deep learning models promise to automate the prioritization of NIDS alerts, the lack of transparency in these models can undermine trust in their decision-making. This study highlights the critical need for explainable artificial intelligence (XAI) in NIDS alert classification to improve trust and interpretability. We employed a real-world NIDS alert dataset from Security Operations Center (SOC) of TalTech (Tallinn University Of Technology) in Estonia, developing a Long Short-Term Memory (LSTM) model to prioritize alerts. To explain the LSTM model's alert prioritization decisions, we implemented and compared four XAI methods: Local Interpretable Model-Agnostic Explanations (LIME), SHapley Additive exPlanations (SHAP), Integrated Gradients, and DeepLIFT. The quality of these XAI methods was assessed using a comprehensive framework that evaluated faithfulness, complexity, robustness, and reliability. Our results demonstrate that DeepLIFT consistently outperformed the other XAI methods, providing explanations with high faithfulness, low complexity, robust performance, and strong reliability. In collaboration with SOC analysts, we identified key features essential for effective alert classification. The strong alignment between these analyst-identified features and those obtained by the XAI methods validates their effectiveness and enhances the practical applicability of our approach. Rajesh Kalakoti, Risto Vaarandi, Hayretdin Bahsi, Sven Nomm |
ICISSP (1) | 1 |
| 2025 | Comprehensive Feature Selection for Machine Learning-Based Intrusion Detection in Healthcare IoMT NetworksabstractInternational audience Muaan ur Rehman, Rajesh Kalakoti, Hayretdin Bahsi |
ICISSP (2) | 2 |
| 2025 | Exploring the Impact of Feature Selection on Non-Stationary Intrusion Detection Models in IoT NetworksabstractThe proliferation of Internet of Things (IoT) devices has increased the attack surface of networks, necessitating robust and adaptive security mechanisms such as machine learning (ML)-based intrusion detection systems (IDS). However, the effectiveness of these systems can degrade over time due to concept drift, where patterns in data evolve as attackers develop new techniques. This study investigates the role of feature selection in enhancing the long-term performance of non-stationary IDS models in IoT networks. Specifically, we apply a filter-based feature reduction technique, Mutual Information, in conjunction with XGBoost models, to evaluate two learning paradigms i.e. static (trained once) and dynamic (periodically retrained). Using the CICIoMT2024 dataset, which includes 18 attack variants across five major categories, we conduct multiclass classification to provide a granular analysis of security threats. Our results demonstrate how selected features perform under different drift conditions and highlight critical network features for evolving attack detection. The study offers new insights into the interplay between feature selection and model adaptability in dynamic IoT environments, aiming to inform the development of more resilient IDS solutions. Muaan ur Rehman, Hayretdin Bahsi, Rajesh Kalakoti |
PST | 3 |
| 2025 | Federated Learning of Explainable AI(FedXAI) for deep learning-based intrusion detection in IoT networks
Rajesh Kalakoti, Sven Nomm, Hayretdin Bahsi |
Comput. Networks | 1 |
| 2024 | Explainable Transformer-based Intrusion Detection in Internet of Medical Things (IoMT) NetworksabstractInternet of Medical Things (IoMT) systems have brought transformative benefits to patient monitoring and remote diagnosis in healthcare. However, these systems are prone to various cyber attacks that have a high impact on security and privacy. Detecting such attacks is crucial for implementing timely and effective countermeasures. Machine learning methods have been applied for intrusion detection tasks in various networks, but explaining the reasons for detection decisions remains an obstacle for security analysts. In this paper, we demonstrate that Transformer architecture, the core of the recent revolutionary large language models, constitutes a promising solution for intrusion detection in IoMT networks. We utilized a comprehensive dataset, CICIoMT2024, recently released specifically for these networks. We created a binary classification model for discriminating attacks from benign traffic and a multi-class model for the identification of specific attack types. We applied Explainable AI (XAi) methods such as LIME and SHAP to generate posthoc explanations for the model decisions. We evaluated and compared the quality of explanations based on three metrics: faithfulness, sensitivity, and complexity. Our findings demonstrate that the applied XAI methods enhance transparency in the predictions of Transformer-based intrusion detection models for IoMT networks, proving that both transparency and high performance can be achieved simultaneously. Rajesh Kalakoti, Sven Nomm, Hayretdin Bahsi |
ICMLA | 1 |
| 2024 | Improving IoT Security With Explainable AI: Quantitative Evaluation of Explainability for IoT Botnet DetectionabstractDetecting botnets is an essential task to ensure the security of IoT systems. Machine learning-based approaches have been widely used for this purpose, but the lack of interpretability and transparency of the models often limits their effectiveness. In this research paper, our aim is to improve the transparency and interpretability of high-performance machine learning models for IoT botnet detection by selecting higher-quality explanations using explainable artificial intelligence (XAI) techniques. We used three datasets to induce binary and multiclass classification models for IoT botnet detection, with Sequential Backward Selection employed as the feature selection technique. We then use two post hoc XAI techniques such as LIME and SHAP, to explain the behaviour of the models. To evaluate the quality of explanations generated by XAI methods, we employed faithfulness, monotonicity, complexity, and sensitivity metrics. ML models employed in this work achieve very high detection rates with a limited number of features. Our findings demonstrate the effectiveness of XAI methods in improving the interpretability and transparency of machine learning-based IoT botnet detection models. Specifically, explanations generated by applying LIME and SHAP to the XGBoost model yield high faithfulness, high Consistency, low complexity, and low sensitivity. Furthermore, SHAP outperforms LIME by achieving better results in these metrics. Rajesh Kalakoti, Hayretdin Bahsi, Sven Nomm |
IEEE Internet Things J. | 1 |
| 2023 | Improving Transparency and Explainability of Deep Learning Based IoT Botnet Detection Using Explainable Artificial Intelligence (XAI)abstractEnsuring the utmost security of loT systems is imperative, and robust botnet detection plays a pivotal role in achieving this goal. Deep learning-based approaches have been widely employed for botnet detection. However, the lack of interpretability and transparency in these models can limit these models' effectiveness. In this research, we present a Deep Neural Network (DNN) model specifically designed for the detection of loT botnet attack types. Our model performs exceptionally, demonstrating outstanding performance of classification metrics with 99% accuracy, F1 score, recall, and precision. To gain deeper insights into our DNN model's behaviour, we employ seven different post hoc explanation techniques to provide local expla-nations. We evaluate the quality of Explainable AI (XAI) methods using metrics such as high faithfulness, monotonicity, complexity, and sensitivity. Our findings highlight the effectiveness of XAI techniques in enhancing the interpretability and transparency of the DNN model for loT botnet detection. Specifically, our results indicate that DeepLIFT yields high faithfulness, high consistency, low complexity, and low sensitivity among all the explainers. Rajesh Kalakoti, Sven Nomm, Hayretdin Bahsi |
ICMLA | 1 |