TY - EJOU AU - Suhaimee, Md. Nahian AU - Shakil, Farhan AU - Khan, Md. Rifat Al Amin AU - Faruq, Md. Omar AU - Hossen, Md. Jakir AU - Mridha, M. F. TI - Temporal Explainable Machine Learning for Insider Threat Detection in Intelligent Transportation Systems T2 - Computers, Materials \& Continua PY - VL - IS - SN - 1546-2226 AB - Insider threats in Intelligent Transportation Systems (ITS) pose significant risks to operational safety and service continuity, as malicious actions often originate from users with legitimate access and evade traditional signature-based detection methods. This study proposes a temporal and explainable machine learning framework that models activity as sequential patterns and provides interpretable insights for each detection decision. The proposed approach integrates recurrent neural networks and attention-based encoders to capture short- and long-term temporal dependencies. To enhance interpretability, a hybrid explanation module combines temporal attention, SHapley Additive exPlanations (SHAP), and counterfactual analysis to identify influential time steps, key risk factors, and actionable changes. Experiments are conducted using a two-stage design: insider-threat modeling on a public insider behavior dataset and ITS-domain transferability evaluation on CICIoV2024 CAN-bus data. Across five folds on the insider dataset, the proposed model achieves precision of 0.89±0.010, recall of 0.87±0.012, F1-score of 0.88±0.011, accuracy of 0.90±0.010, ROC-AUC of 0.94±0.009, and PR-AUC of 0.91±0.010. It also demonstrates robustness under class imbalance (MCC = 0.69), reduces average time-to-detect from 5.4 days to 3.7 days, and improves probability reliability with a Brier score of 0.123. The CICIoV2024 evaluation further shows that the same temporal explainable architecture can process ITS-native IoV packet sequences and distinguish benign, DoS, and spoofing behavior. The generated explanations exhibit high fidelity, stability, and sparsity, enabling efficient analyst interpretation and decision support; CICIoV2024 is used for transferability testing rather than direct insider-threat validation. KW - Intelligent transportation systems; insider threat detection; explainable AI; temporal modeling; CAN-bus security; anomaly detection DO - 10.32604/cmc.2026.083705