<p>Artificial intelligence (AI)-based intrusion detection systems (IDSs) markedly advance network security by leveraging machine learning (ML) and deep learning (DL) models for accurate, adaptive threat detection. Their main drawback, however, is an inherent “black-box” character that impedes trust, traceability, and regulatory compliance. To overcome this limitation, we propose an efficient explainable-AI (XAI) framework that enhances both robustness and interpretability. The two-stage process first couples a statistical selector (ANOVA) with global SHAP scores to retain only the ten most informative features, an approximately 70% dimensionality reduction, then retrains a lightweight XGBoost detector whose decisions are explained locally by SHAP and LIME. Cross-validating the two explanation modalities adds a reliability check absent from earlier hybrids, while the inclusion of a time-efficiency evaluation for explanation generation provides a new performance dimension that prior XAI-IDS studies have not addressed. To our knowledge, this is the first framework to jointly apply dual-stage statistical–model-based feature selection and SHAP–LIME cross-validation in IDS, enabling near-real-time explainability without sacrificing accuracy. Comprehensive experiments on three representative traces, CIC-DDoS2019 (legacy IP DDoS), CICIoT2023 (IoT malware), and 5&#xa0;G PFCP (control-plane attacks), confirm the framework’s versatility: it sustains an F1 Score of at least 99 % while accelerating LIME explanation time from 36 to 4.9&#xa0;s, an 87 % speed-up. These results demonstrate that high detection accuracy and transparent, near-real-time interpretability can be achieved simultaneously in modern IDS deployments.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A versatile XAI-based framework for efficient and explainable intrusion detection systems

  • Beny Nugraha,
  • Abhishek Venkatesh Jnanashree,
  • Thomas Bauschert

摘要

Artificial intelligence (AI)-based intrusion detection systems (IDSs) markedly advance network security by leveraging machine learning (ML) and deep learning (DL) models for accurate, adaptive threat detection. Their main drawback, however, is an inherent “black-box” character that impedes trust, traceability, and regulatory compliance. To overcome this limitation, we propose an efficient explainable-AI (XAI) framework that enhances both robustness and interpretability. The two-stage process first couples a statistical selector (ANOVA) with global SHAP scores to retain only the ten most informative features, an approximately 70% dimensionality reduction, then retrains a lightweight XGBoost detector whose decisions are explained locally by SHAP and LIME. Cross-validating the two explanation modalities adds a reliability check absent from earlier hybrids, while the inclusion of a time-efficiency evaluation for explanation generation provides a new performance dimension that prior XAI-IDS studies have not addressed. To our knowledge, this is the first framework to jointly apply dual-stage statistical–model-based feature selection and SHAP–LIME cross-validation in IDS, enabling near-real-time explainability without sacrificing accuracy. Comprehensive experiments on three representative traces, CIC-DDoS2019 (legacy IP DDoS), CICIoT2023 (IoT malware), and 5 G PFCP (control-plane attacks), confirm the framework’s versatility: it sustains an F1 Score of at least 99 % while accelerating LIME explanation time from 36 to 4.9 s, an 87 % speed-up. These results demonstrate that high detection accuracy and transparent, near-real-time interpretability can be achieved simultaneously in modern IDS deployments.