
@Article{cmc.2026.083705,
AUTHOR = {Md. Nahian Suhaimee, Farhan Shakil, Md. Rifat Al Amin Khan, Md. Omar Faruq, Md. Jakir Hossen, M. F. Mridha},
TITLE = {Temporal Explainable Machine Learning for Insider Threat Detection in Intelligent Transportation Systems},
JOURNAL = {Computers, Materials \& Continua},
VOLUME = {},
YEAR = {},
NUMBER = {},
PAGES = {{pages}},
URL = {http://www.techscience.com/cmc/online/detail/28323},
ISSN = {1546-2226},
ABSTRACT = {Insider threats in Intelligent Transportation Systems (ITS) pose significant risks to operational safety and service continuity, as malicious actions often originate from users with legitimate access and evade traditional signature-based detection methods. This study proposes a temporal and explainable machine learning framework that models activity as sequential patterns and provides interpretable insights for each detection decision. The proposed approach integrates recurrent neural networks and attention-based encoders to capture short- and long-term temporal dependencies. To enhance interpretability, a hybrid explanation module combines temporal attention, SHapley Additive exPlanations (SHAP), and counterfactual analysis to identify influential time steps, key risk factors, and actionable changes. Experiments are conducted using a two-stage design: insider-threat modeling on a public insider behavior dataset and ITS-domain transferability evaluation on CICIoV2024 CAN-bus data. Across five folds on the insider dataset, the proposed model achieves precision of <math id="mml-ieqn-1"><mn>0.89</mn><mo>±</mo><mn>0.010</mn></math>, recall of <math id="mml-ieqn-2"><mn>0.87</mn><mo>±</mo><mn>0.012</mn></math>, F1-score of <math id="mml-ieqn-3"><mn>0.88</mn><mo>±</mo><mn>0.011</mn></math>, accuracy of <math id="mml-ieqn-4"><mn>0.90</mn><mo>±</mo><mn>0.010</mn></math>, ROC-AUC of <math id="mml-ieqn-5"><mn>0.94</mn><mo>±</mo><mn>0.009</mn></math>, and PR-AUC of <math id="mml-ieqn-6"><mn>0.91</mn><mo>±</mo><mn>0.010</mn></math>. It also demonstrates robustness under class imbalance (MCC = 0.69), reduces average time-to-detect from 5.4 days to 3.7 days, and improves probability reliability with a Brier score of 0.123. The CICIoV2024 evaluation further shows that the same temporal explainable architecture can process ITS-native IoV packet sequences and distinguish benign, DoS, and spoofing behavior. The generated explanations exhibit high fidelity, stability, and sparsity, enabling efficient analyst interpretation and decision support; CICIoV2024 is used for transferability testing rather than direct insider-threat validation.},
DOI = {10.32604/cmc.2026.083705}
}



