Home / Journals / CMC / Online First / doi:10.32604/cmc.2026.083705
Special Issues
Table of Content

Open Access

ARTICLE

Temporal Explainable Machine Learning for Insider Threat Detection in Intelligent Transportation Systems

Md. Nahian Suhaimee1, Farhan Shakil2, Md. Rifat Al Amin Khan3, Md. Omar Faruq4, Md. Jakir Hossen5,*, M. F. Mridha6
1 St. Louis Community College—Forest Park, 5600 Oakland Ave, St. Louis, MO, USA
2 George Herbert Walker School of Business & Technology, Webster University, 470 East Lockwood Avenue, Saint Louis, MO, USA
3 Electrical and Computer Engineering Department, Lamar University, 4400 MLK Blvd, Beaumont, TX, USA
4 Department of Computer and Information Sciences, Webster University, 470 E Lockwood Ave, Webster Groves, MO, USA
5 Center for Advanced Analytics (CAA), COE for Artificial Intelligence, Faculty of Engineering & Technology (FET), Multimedia University, Melaka, Malaysia
6 Department of Computer Science, American International University—Bangladesh (AIUB), Dhaka, Bangladesh
* Corresponding Author: Md. Jakir Hossen. Email: email

Computers, Materials & Continua https://doi.org/10.32604/cmc.2026.083705

Received 09 April 2026; Accepted 02 July 2026; Published online 17 September 2026

Abstract

Insider threats in Intelligent Transportation Systems (ITS) pose significant risks to operational safety and service continuity, as malicious actions often originate from users with legitimate access and evade traditional signature-based detection methods. This study proposes a temporal and explainable machine learning framework that models activity as sequential patterns and provides interpretable insights for each detection decision. The proposed approach integrates recurrent neural networks and attention-based encoders to capture short- and long-term temporal dependencies. To enhance interpretability, a hybrid explanation module combines temporal attention, SHapley Additive exPlanations (SHAP), and counterfactual analysis to identify influential time steps, key risk factors, and actionable changes. Experiments are conducted using a two-stage design: insider-threat modeling on a public insider behavior dataset and ITS-domain transferability evaluation on CICIoV2024 CAN-bus data. Across five folds on the insider dataset, the proposed model achieves precision of 0.89±0.010, recall of 0.87±0.012, F1-score of 0.88±0.011, accuracy of 0.90±0.010, ROC-AUC of 0.94±0.009, and PR-AUC of 0.91±0.010. It also demonstrates robustness under class imbalance (MCC = 0.69), reduces average time-to-detect from 5.4 days to 3.7 days, and improves probability reliability with a Brier score of 0.123. The CICIoV2024 evaluation further shows that the same temporal explainable architecture can process ITS-native IoV packet sequences and distinguish benign, DoS, and spoofing behavior. The generated explanations exhibit high fidelity, stability, and sparsity, enabling efficient analyst interpretation and decision support; CICIoV2024 is used for transferability testing rather than direct insider-threat validation.

Keywords

Intelligent transportation systems; insider threat detection; explainable AI; temporal modeling; CAN-bus security; anomaly detection
  • 32

    View

  • 9

    Download

  • 0

    Like

Share Link