Multi-Level Distributional Entropy for Explainable Network Intrusion Detection
This work addresses the limitations of existing network intrusion detection systems that rely on aggregated flow statistics, which discard distributional structure, and conventional entropy-based methods that require raw packets and are thus inapplicable to pre-aggregated data. The authors propose a Multilevel Distributional Entropy (MDE) framework that, for the first time, directly constructs interpretable, multilayer entropy features from flow-level summary statistics—specifically, intra-flow Gaussian differential entropy, inter-directional Jensen–Shannon divergence, and TCP flag Shannon entropy—without needing raw packets or training samples. Evaluated on four benchmark datasets, MDE alone achieves weighted F1 scores ranging from 0.708 to 0.989. SHAP analysis demonstrates high feature stability (Spearman ρ = 0.80–0.95) and reveals that fixed thresholds suffer severe performance degradation under temporal shifts, with detection rates plummeting to 0.082, thereby substantially enhancing detection transparency and robustness.