Network Intrusion Detection Systems are critical for safeguarding network security in the face of increasingly advanced cyber threats. This study investigates the application of AI explainability in understanding what features drive AI decisions across different classes of network traffic within NIDS. Using the LITNET-2020 and CICIDS2018 datasets, the analysis identifies key features that consistently influence model decisions. However, instead of a standard local or global usage of SHAP, the novelty of this paper is in approaching the traffic by class and contrasting what features are important semi-globally. The local explainability measures are stacked against the values on the semi-global level, both for the entire class of similar attacks and with the Benign class. This contrast of SHAP values per class allows to better emphasize what features take part in the classification decision in each class. The findings highlight the variability in feature importance across different traffic clusters, emphasizing the need for a comprehensive approach to model interpretation. Discrepancies between the explainability tools underscore the value of employing multiple interpretability methods to gain a comprehensive understanding of feature relevance. These insights have significant implications for the development of more effective and transparent NIDS.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Class-Based SHAP Analysis for Improved Explainability Insights in NIDS

  • Marek Pawlicki,
  • Aleksandra Pawlicka,
  • Sebastian Szelest,
  • Rafał Kozik,
  • Michał Choraś

摘要

Network Intrusion Detection Systems are critical for safeguarding network security in the face of increasingly advanced cyber threats. This study investigates the application of AI explainability in understanding what features drive AI decisions across different classes of network traffic within NIDS. Using the LITNET-2020 and CICIDS2018 datasets, the analysis identifies key features that consistently influence model decisions. However, instead of a standard local or global usage of SHAP, the novelty of this paper is in approaching the traffic by class and contrasting what features are important semi-globally. The local explainability measures are stacked against the values on the semi-global level, both for the entire class of similar attacks and with the Benign class. This contrast of SHAP values per class allows to better emphasize what features take part in the classification decision in each class. The findings highlight the variability in feature importance across different traffic clusters, emphasizing the need for a comprehensive approach to model interpretation. Discrepancies between the explainability tools underscore the value of employing multiple interpretability methods to gain a comprehensive understanding of feature relevance. These insights have significant implications for the development of more effective and transparent NIDS.