OptiXID: An optimized and eXplainable AI framework for intrusion detection in IoT networks
摘要
The rapid proliferation of Internet of Things (IoT) networks has increased their susceptibility to advanced cyberattacks, necessitating robust and flexible security measures. This study introduces OptiXID, an explainable Intrusion Detection System (IDS) framework that leverages Atom Search Optimization (ASO) for optimal feature selection, employs Safe-Level SMOTE to mitigate class imbalance, and incorporates SHAP (SHapley Additive exPlanations) to enhance model interpretability. Although many machine learning models achieve high accuracy, they often operate as opaque ‘black box" systems, which complicates the understanding of the rationale behind classifying network events as malicious. This opacity poses significant challenges in critical security scenarios, where model explainability is essential for building trust in AI-driven security systems. By providing comprehensive insights into feature significance, OptiXID demystifies model decisions and empowers network administrators to understand the factors driving detection outcomes. Our approach significantly improves detection accuracy by optimizing feature relevance and achieving balanced class representation. We validate our proposed OptiXID on two benchmark datasets: NF-UNSW-NB15 and CIC-IoT-2023. On NF-UNSW-NB15, XGBoost achieves 98.4% accuracy with strong consistency across all attack types. On CIC-IoT-2023, which features a wide range of real-world IoT threats and severe class imbalance, the framework achieves 99.48% accuracy, 99.47% precision, and a 99.47% F1-score. These results underscore OptiXID’s robustness. Overall, this explainable IDS framework not only enhances detection efficiency but also promotes transparency, offering a scientifically sound solution to safeguard complex IoT infrastructures against contemporary cyber threats.