An LLM-Based Agentic Network Traffic Incident-Report Approach Towards Explainable-AI Network Defense
Publication Date
4-7-2026
Document Type
Article
Publication Title
Journal of Sensor and Actuator Networks
Volume
15
Issue
2
DOI
10.3390/jsan15020032
Abstract
Traditional intrusion detection systems for IoT networks achieve high classification accuracy but lack interpretability and actionable incident-response capabilities, limiting their operational value in security-critical environments. This paper presents a graph-based multi-agent framework that integrates ensemble machine learning with Large Language Model (LLM)-powered incident report generation via Retrieval-Augmented Generation (RAG). The system employs a three-phase architecture: (1) a lightweight Random Forest binary pre-detection, achieving 99.49% accuracy with a 6 MB model size for edge deployment; (2) ensemble classification combining Multi-Layer Perceptron, Random Forest, and XGBoost with soft voting and SHAP-based feature attribution for explainability; and (3) a ReAct-based summary agent that synthesizes classification results with external threat intelligence from Web search and scholarly databases to generate evidence-grounded incident reports. To address the challenge of evaluating non-deterministic LLM outputs, we introduce custom RAG evaluation metrics—faithfulness and groundedness implemented via the LLM-as-Judge framework. Experimental validation on the ACI IoT Network Dataset 2023 demonstrates ensemble accuracy exceeding 99.8% across 11 attack classes; perfect groundedness scores (1.0), indicating all generated claims derive from the retrieved context; and moderate faithfulness (0.64), reflecting appropriate analytical synthesis. The ensemble approach mitigates individual model weaknesses, improving the UDP Flood F1 score from 48% (MLP alone) to 95% through soft voting. This work bridges the gap between high-accuracy detection and trustworthy, actionable security analysis for automated incident-response systems.
Funding Number
2244597
Funding Sponsor
National Science Foundation
Keywords
agentic system, ensemble learning, explainable AI, intrusion detection, IoT security, large language model, retrieval-augmented generation, SHAP
Creative Commons License

This work is licensed under a Creative Commons Attribution 4.0 License.
Department
Computer Engineering
Recommended Citation
Chia Hong Chou, Arjun Sudheer, and Younghee Park. "An LLM-Based Agentic Network Traffic Incident-Report Approach Towards Explainable-AI Network Defense" Journal of Sensor and Actuator Networks (2026). https://doi.org/10.3390/jsan15020032
Comments
This article belongs to the Special Issue Feature Papers in the Section of Network Security and Privacy