ISSN (Print): 3078-4425 ISSN (Online): 3078-4425
International Journal of Engineering Fields Official Publication of Octopus Publication, Hong Kong
Cover of July-September 2025
research article

Explainable Anomaly Detection for Secure CI/CD Pipelines: A Shapley Additive Explanations (SHAP) Approach

  • Abhishek Kumar
    India

Vol. 3 , Issue 3 (2025) · pp. 30-44

Country: India

DOI: 10.64180/ijef.332504

Abstract

The integration of machine learning into DevSecOps pipelines has enabled automated detection of anomalous activities, yet the opacity of these “black-box” models remains a significant barrier to adoption. Security analysts and developers require not only alerts but also understandable explanations of why a specific commit or pipeline event was flagged as suspicious. This paper presents a framework for explainable anomaly detection in CI/CD environments that combines deep autoencoders with Shapley Additive Explanations (SHAP). The system leverages commit metadata—including timing patterns, file entropy, and modification magnitude—to model normal developer behavior through unsupervised learning. Simultaneously, SHAP values quantify the marginal contribution of each feature to the anomaly score, providing transparent, feature-level explanations. Experimental evaluation on a real-world commit dataset demonstrates that the proposed framework achieves an F1-score exceeding 0.91, substantially outperforming Isolation Forest (0.78) and One-Class SVM baselines. The explainability layer enables security teams to distinguish between true threats and benign anomalies while reducing false positive investigation overhead. By bridging the gap between high-performance detection and human interpretability, this work advances the practical deployment of AI-driven security controls in DevSecOps workflows.

Keywords: Explainable AI Anomaly Detection CI/CD Security DevSecOps SHAP Deep Autoencoder
4 views 0 downloads

How to Cite

Cite this article