Mehmet Özdem
Today, cyber threats are rapidly changing in both diversity and complexity, making traditional defense methods inadequate. This research presents a novel anomaly detection model based on Temporal Graph Networks supported by Explainable Artificial Intelligence in real-time network traffic. Live network data was collected using Wireshark to develop a balanced dataset covering different attack types. The proposed model can effectively identify intrusions with high accuracy by fusing temporal and structural information. Explainable Artificial Intelligence is achieved through a gradient-based feature importance method that quantifies the contribution of numerical and textual features at the classification stage, providing transparency into the reasoning behind attack identification. The model achieved 96.8% accuracy in experiments conducted with a large test dataset and was able to process 50,000 packets with a detection latency of only 1.45 s, demonstrating its effectiveness for real-time deployment. Furthermore, the dataset generated in the study has been openly published on the HuggingFace platform and is available to researchers in similar fields. Using this methodology not only enables security analysts to provide fast and effective detection but also enables more effective threat response by providing explainability. This research represents a significant advancement towards creating autonomous, dynamic, and semantically rich solutions for future cybersecurity systems. • Real-time network anomaly detection via Temporal Graph Networks with XAI. • Balanced dataset of diverse attacks captured with Wireshark; released open access. • Model hits 96.8% accuracy; processes 50k packets with 1.45s latency. • Gradient-based feature importance adds transparency for faster threat response.