Abstract
<title>Abstract</title> <p>DNS over HTTPS (DoH) enhances privacy but also enables covert tunneling and data exfiltration. This paper proposes a density-aware hybrid framework, positioned as a batch-processing analyser, combining XGBoost with unsupervised anomaly scoring from Isolation Forest and Local Outlier Factor, interpreted via SHAP; an ablation study shows deep generative components add no measurable benefit. Evaluated on the CIRA-CIC-DoHBrw-2020 benchmark, the framework improves Recall over the baseline in the Standard and Full Data scenarios (F1 = 96.11% vs. 95.96%, p = 0.024), with a tied Cross-Scenario result. In a fifteen-configuration Leave-One-Attack-Out evaluation, the framework reduced false negatives by 70.8–74.1% (Wilcoxon p = 0.031). A companion Leave-One-Tool-Out evaluation across three structurally different tools confirms the same maximal significance, though performance remains limited for one tool (dns2tcp) by a genuine feature-domain gap. These results show anomaly scoring provides a statistically validated safety net for unseen variants at the batch level.</p>