Nasim Nezhadsistani, Mohsen Tajgardan, Mahdi Rabbani, Weijie Niu, Burkhard Stiller
As Fifth-generation (5G) networks advance towards future 6G technology, they provide enhanced capabilities in terms of data rates, latency, and connectivity. The expanding and heterogeneous landscape further extends the attack surface with increasing vulnerability to a wide range of dynamic cyber threats. Traditional Intrusion Detection Systems, relying on static signature-based methods, face significant challenges in detecting novel attacks in such complex environments. This paper proposes an explainable hybrid AE-XGBoost framework to address these gaps. In this proposed framework, the deep autoencoder serves as the backbone for two primary tasks: learning robust features from high-dimensional traffic data and synthesizing high-quality samples for minority, underrepresented attack classes. It effectively forms a class-balanced dataset. This is further extended to integrate Shapley Additive Explanations (SHAP), which provide needed interpretability. The framework robustness is determined by an extensive evaluation strategy. Extensive experiments are conducted using a 5-fold cross-validation and cross-dataset validation using three different datasets. The experimental results demonstrate the model effectiveness and promising generalization across the different datasets. Across these settings, the proposed IDS achieves F1-scores between approximately 0.96 and 0.999 and AUC values above 0.97, with only minor performance differences between original and synthetic test samples. SHAP-based analysis further reveals that a small subset of 5G- and TCP-level features consistently dominates the predictions, offering actionable explanations for security analysts. This provides a successful, scalable, and reliable security measure that proves effective and appropriate for 6G mobile network implementations in the near future.