HuntGPT: Integrating Machine Learning-Based Anomaly Detection and Explainable AI with Large Language Models (LLMs)

HuntGPT: интеграция обнаружения аномалий на основе машинного обучения и объяснимого искусственного интеллекта с большими языковыми моделями (LLM)
Panos Kostakos, Tarek Ali, Saeid Sheikhi
2026-06-08

Explainable AI (XAI)GPT-3.5 TurboHuntGPTRandom Forest classifiernetwork anomaly detection
Machine learning (ML) methods for network anomaly detection are emerging as effective proactive strategies in threat hunting, substantially reducing the time required for threat detection and response. However, the challenges in training and maintaining ML models, coupled with frequent false positives, diminish their acceptance and trustworthiness. In response, Explainable AI (XAI) techniques have been introduced to enable cybersecurity operations teams to assess alerts generated by AI systems more confidently. Despite these advancements, XAI tools have encountered limited acceptance from incident responders and have struggled to meet the decision-making needs of both analysts and model maintainers. Large Language Models (LLMs) offer a unique approach to tackling these challenges. Through tuning, LLMs have the ability to discern patterns across vast amounts of information and meet varying functional requirements. In this research, we introduce the development of HuntGPT, a specialized intrusion detection dashboard created to implement a Random Forest classifier trained utilizing the KDD99 dataset. The tool incorporates XAI frameworks like SHAP and Lime, enhancing user-friendliness and intuitiveness of the model. When combined with a GPT-3.5 Turbo conversational agent, HuntGPT aims to deliver detected threats in an easily explainable format, emphasizing user understanding and offering a smooth interactive experience. We investigate the system’s comprehensive architecture and its diverse components, assess the prototype’s technical accuracy using the Certified Information Security Manager (CISM) Practice Exams, and analyze the quality of response readability across six unique metrics. Our results indicate that conversational agents, underpinned by LLM technology and integrated with XAI, can enable a robust mechanism for generating explainable and actionable AI solutions, especially within the realm of intrusion detection systems.
1
HuntGPT integrates a Random Forest intrusion detector trained on the KDD99 dataset with SHAP and LIME explainability frameworks.
2
Results indicate that integrating LLM-based conversational agents with XAI can support robust, actionable, and explainable intrusion-detection solutions.
3
The approach targets persistent barriers to ML-based threat hunting, including model-maintenance challenges, false positives, and limited acceptance of conventional XAI tools.
4
The prototype architecture was evaluated for technical accuracy using CISM Practice Exams and for response readability across six distinct metrics.
5
The system combines XAI outputs with a GPT-3.5 Turbo conversational agent to present detected threats in an accessible, interactive, and explainable format.

HuntGPT, a specialized intrusion detection dashboard integrating a Random Forest classifier, XAI frameworks, and a GPT-3.5 Turbo conversational agent

the system’s architecture, technical accuracy, explainability, user readability, and interactive effectiveness for network threat detection and response

Publication Details
Publication Date
2026-06-08
Journal
Publisher
ISSN
Cited by
40
Access Type
Author Information
Authors
Panos Kostakos
Tarek Ali
Saeid Sheikhi
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%