TY - EJOU
AU - Suhaimee, Md. Nahian
AU - Shakil, Farhan
AU - Khan, Md. Rifat Al Amin
AU - Faruq, Md. Omar
AU - Hossen, Md. Jakir
AU - Mridha, M. F.
TI - Temporal Explainable Machine Learning for Insider Threat Detection in Intelligent Transportation Systems
T2 - Computers, Materials \& Continua
PY -
VL -
IS -
SN - 1546-2226
AB - Insider threats in Intelligent Transportation Systems (ITS) pose significant risks to operational safety and service continuity, as malicious actions often originate from users with legitimate access and evade traditional signature-based detection methods. This study proposes a temporal and explainable machine learning framework that models activity as sequential patterns and provides interpretable insights for each detection decision. The proposed approach integrates recurrent neural networks and attention-based encoders to capture short- and long-term temporal dependencies. To enhance interpretability, a hybrid explanation module combines temporal attention, SHapley Additive exPlanations (SHAP), and counterfactual analysis to identify influential time steps, key risk factors, and actionable changes. Experiments are conducted using a two-stage design: insider-threat modeling on a public insider behavior dataset and ITS-domain transferability evaluation on CICIoV2024 CAN-bus data. Across five folds on the insider dataset, the proposed model achieves precision of , recall of , F1-score of , accuracy of , ROC-AUC of , and PR-AUC of . It also demonstrates robustness under class imbalance (MCC = 0.69), reduces average time-to-detect from 5.4 days to 3.7 days, and improves probability reliability with a Brier score of 0.123. The CICIoV2024 evaluation further shows that the same temporal explainable architecture can process ITS-native IoV packet sequences and distinguish benign, DoS, and spoofing behavior. The generated explanations exhibit high fidelity, stability, and sparsity, enabling efficient analyst interpretation and decision support; CICIoV2024 is used for transferability testing rather than direct insider-threat validation.
KW - Intelligent transportation systems; insider threat detection; explainable AI; temporal modeling; CAN-bus security; anomaly detection
DO - 10.32604/cmc.2026.083705