Journal Of Network security Original Research
Enhancing Explainability in Machine Learning Based Spam Email Detection Using LIME and SHAP
Abstract
Spam emails represent a continual and irritating cybersecurity issue due to the fast expansion of cyberspace communication. These messages are unwanted and, in some cases, dangerous, such as phishing schemes, identity theft, and the propagation of malware. They cause severe financial and data security threats to individuals and organizations. Conventional spam detection techniques, such as rule-based spamming, blacklisting, and keyword classification, are techniques that find it difficult to match adaptive spamming schemes that include manipulation of text, dynamic generation of content, and concealment of information. Machine learning methods like support vector machines (SVM), random forest, and Naive Bayes have significantly enhanced detection accuracy. This paper introduces a machine learning model for a spam email detector that is non-technical. It pays equal attention to the interpretability of the model as well as the prediction power of the model. The system uses explainable artificial intelligence (XAI) methods, namely, Local Interpretable Model-Agnostic Explanations (LIME) and SHAP, to complement the conventional machine learning classifiers. With this combination, one can get insight into the decision-making of the model in a manner that can be understood by humans. The model relies on text representation in the form of TF-IDF, which is useful in extracting features, as well as an optimized SVM that is used to classify spam. The experimental findings show that this model can be used to achieve 96.4% accuracy that is better than the standard baseline systems yet can be understood using visual and quantitative explanation modules. Along with the accuracy of classification, the use of XAI enhances the credibility of the model significantly. This enables end-users and cybersecurity analysts to know and verify the reason as to why specific emails are This interpretability stimulates more appropriate decision-making, compliance with data transparency rules, and makes the system constantly improve due to explainability feedback. The research ultimately. This fills the disconnect that exists between high-performance machine learning models and user trust, showing that augmenting XAI within spam detection systems can make them not opaque black-box applications, but transparent, responsible, and trustworthy cybersecurity solutions that can be deployed in practice. Bridges the gap between high-performance machine learning (ML) models and user-centered trust, demonstrating that integrating XAI into spam detection frameworks can transform them from opaque “black-box” systems into transparent, accountable, and reliable cybersecurity solutions suitable for real-world deployment.
Keywords
References (25)
- Alzahrani A. Explainable AI-based framework for efficient detection of spam from text using an enhanced ensemble technique. Eng Technol Appl Sci Res. 2024;14:15596-601. doi:10.48084/etasr.7901.
- Bouke MA, Alramli OI, Abdullah A. XAIRF-WFP: a novel XAI-based random forest classifier for advanced email spam detection. Int J Inf Secur. 2025;24:5. doi:10.1007/s10207-024-00920-1.
- Alsuwit MH, Haq MA, Aleisa MA. Advancing email spam classification using machine learning and deep learning techniques. Eng Technol Appl Sci Res. 2024;14:14994-5001. doi:10.48084/etasr.7631.
- Lim B, Huerta R, Sotelo A, Quintela A, Kumar P. Explicate: enhancing phishing detection through explainable AI and LLM-powered interpretability [Preprint]. 2025 Mar 22. arXiv:2503.20796.
- Ribeiro MT, Singh S, Guestrin C. “Why should I trust you?” Explaining the predictions of any classifier. In: Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining; 2016. p. 97-101. doi:10.18653/v1/N16-3020.
- Ahern I, Noack A, Guzman-Nateras L, Dou D, Li B, Huan J. NormLIME: a new feature importance metric for explaining deep neural networks [Preprint]. 2019 Sep 10. arXiv:1909.04200.
- Gaspar D, Silva P, Silva C. Explainable AI for intrusion detection systems: LIME and SHAP applicability on multi-layer perceptron. IEEE Access. 2024;12:30164-75. doi:10.1109/ACCESS.2024.3368377.
- Hermosilla P, Berríos S, Allende-Cid H. Explainable AI for forensic analysis: a comparative study of SHAP and LIME in intrusion detection models. Appl Sci (Basel). 2025;15:7329. doi:10.3390/app15137329.
- Tian Y, Dai X, Li Z, Guo H, Mao X. Improving the accuracy of cybersecurity spam email detection using ensemble techniques: a stacking approach machine learning for spam email detection. PLoS One. 2025;20:e0331574. doi:10.1371/journal.pone.0331574. PMID:40901898.
- Muhammad JM, Hasan AB, Farrukh M. Classification and prediction of spam emails based on AI enabling models using deep and machine learning techniques. In: Proceedings of the International Conference on Emerging Technologies in Electronics, Computing and Communication (ICETECC); 2022. p. 1-6. doi:10.1109/ICETECC56662.2022.10069229.
- Dafali SM, Kissi M, El Beggar O. Comparative study between global and local explainable models. In: Proceedings of the 14th International Conference on Intelligent Systems: Theories and Applications (SITA); 2023. p. 1-8. doi:10.1109/SITA60746.2023.10373599.
- Contreras J, Winterfeld A, Popp J, Bocklitz T. Spectral zones-based SHAP/LIME: enhancing interpretability in spectral deep learning models through grouped feature analysis. Anal Chem. 2024;96:15588-97. doi:10.1021/acs.analchem.4c02329. PMID:39289923.
- Salih AM, Raisi-Estabragh Z, Galazzo IB, Radeva P, Petersen SE, Lekadir K, et al. A perspective on explainable artificial intelligence methods: SHAP and LIME. Adv Intell Syst. 2025;7:2400304. doi:10.1002/aisy.202400304.
- Nakanishi T. Approximate inverse model explanations (AIME): unveiling local and global insights in machine learning models. IEEE Access. 2023;11:101020-44. doi:10.1109/ACCESS.2023.3314336.
- Moulaei K, Afrash MR, Parvin M, Shadnia S, Rahimi M, Mostafazadeh B, et al. Explainable artificial intelligence (XAI) for predicting the need for intubation in methanol-poisoned patients: a study comparing deep and machine learning models. Sci Rep. 2024;14:15751. doi:10.1038/s41598-024-66481-4. PMID:38977750.
- Das Guptta S, Shahriar KT, Alqahtani H, Alsalman D, Sarker IH. Modeling hybrid feature-based phishing websites detection using machine learning techniques. Ann Data Sci. 2022:1-26. doi:10.1007/s40745-022-00379-8. PMID:40479161.
- Jamal S, Wimmer H, Sarker IH. An improved transformer-based model for detecting phishing, spam and ham emails: a large language model approach. Secur Priv. 2024;7:e402. doi:10.1002/spy2.402.
- Bhagat PM, Waghmare S, Waje M, Patil R, Joshi K, Bakuli M. Feature classification and extreme learning machine based detection of phishing websites. Int J Recent Innov Trends Comput Commun. 2023;11:132-6. doi:10.17762/ijritcc.v11i8s.7182.
- Tesfom B, Belay F, Daniel S, Salem R, Otoum S. Phishing detection using deep learning and machine learning algorithms: comparative analysis. In: Proceedings of the IEEE International Conference on Dependable, Autonomic and Secure Computing, International Conference on Pervasive Intelligence and Computing, International Conference on Cloud and Big Data Computing, Cyber Science and Technology Congress; 2023. p. 684-9. doi:10.1109/DASC/PiCom/CBDCom/Cy59711.2023.10361457.
- Chen Z, Liu SZ, Huang J, Xiu YH, Zhang H, Long HX. Ethereum phishing scam detection based on data augmentation method and hybrid graph neural network model. Sensors (Basel). 2024;24:4022. doi:10.3390/s24124022. PMID:38931803.
- Vo HT, Thien NN, Mui KC, Tien PP. Securing networks: an in-depth analysis of intrusion detection using machine learning and model explanations. Int J Adv Comput Sci Appl. 2024;15. doi:10.14569/IJACSA.2024.01505143.
- Zaware S. AI-based phishing detection and automated response: a multi-channel security framework for modern communication platforms. Panam Math J. 2024;35:250-63. doi:10.52783/pmj.v35.i1s.2312.
- Ghosh SK, Khandoker AH. Investigation on explainable machine learning models to predict chronic kidney diseases. Sci Rep. 2024;14:3687. doi:10.1038/s41598-024-54375-4. PMID:38355876.
- Khanom F, Uddin MS, Mostafiz R. PD_EBM: an integrated boosting approach based on selective features for unveiling Parkinson's disease diagnosis with global and local explanations. Eng Rep. 2025;7:e13091. doi:10.1002/eng2.13091.
- Zieni R, Massari L, Calzarossa MC. Phishing or not phishing? A survey on the detection of phishing websites. IEEE Access. 2023;11:18499-519. doi:10.1109/ACCESS.2023.3247135.