Class-Based SHAP Analysis for Improved Explainability Insights in NIDS
摘要
Network Intrusion Detection Systems are critical for safeguarding network security in the face of increasingly advanced cyber threats. This study investigates the application of AI explainability in understanding what features drive AI decisions across different classes of network traffic within NIDS. Using the LITNET-2020 and CICIDS2018 datasets, the analysis identifies key features that consistently influence model decisions. However, instead of a standard local or global usage of SHAP, the novelty of this paper is in approaching the traffic by class and contrasting what features are important semi-globally. The local explainability measures are stacked against the values on the semi-global level, both for the entire class of similar attacks and with the Benign class. This contrast of SHAP values per class allows to better emphasize what features take part in the classification decision in each class. The findings highlight the variability in feature importance across different traffic clusters, emphasizing the need for a comprehensive approach to model interpretation. Discrepancies between the explainability tools underscore the value of employing multiple interpretability methods to gain a comprehensive understanding of feature relevance. These insights have significant implications for the development of more effective and transparent NIDS.