Enhancing intrusion detection performance using explainable ensemble deep learning

被引:0
作者
Ncir, Chiheb Eddine Ben [1 ]
Hajkacem, Mohamed Aymen Ben [2 ]
Alattas, Mohammed [1 ]
机构
[1] Univ Jeddah, Coll Business, MIS Dept, Jeddah, Saudi Arabia
[2] Univ Tunis, ISG Tunis, LARODEC Lab, Tunis, Tunisia
关键词
Intrusion detection; Deep learning; Interpretable machine learning; Explainable machine learning; LSTM-based algorithms; Ensemble learning; NEURAL-NETWORK;
D O I
10.7717/peerj-cs.2289
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Given the exponential growth of available data in large networks, the need for an accurate and explainable intrusion detection system has become of high necessity to effectively discover attacks in such networks. To deal with this challenge, we propose a two-phase Explainable Ensemble deep learning-based method (EED) for intrusion detection. In the first phase, a new ensemble intrusion detection model using three one-dimensional long short-term memory networks (LSTM) is designed for an accurate attack identification. The outputs of three classifiers are aggregated using a meta-learner algorithm resulting in refined and improved results. In the second phase, interpretability and explainability of EED outputs are enhanced by leveraging the capabilities of SHape Additive exPplanations (SHAP). Factors contributing to the identification and classification of attacks are highlighted which allows security experts to understand and interpret the attack behavior and then implement effective response strategies to improve the network security. Experiments conducted on real datasets have shown the effectiveness of EED compared to conventional intrusion detection methods in terms of both accuracy and explainability. The EED method exhibits high accuracy in accurately identifying and classifying attacks while providing transparency and interpretability.
引用
收藏
页数:32
相关论文
共 43 条
  • [1] A novel SVM-kNN-PSO ensemble method for intrusion detection system
    Aburomman, Abdulla Amin
    Reaz, Mamun Bin Ibne
    [J]. APPLIED SOFT COMPUTING, 2016, 38 : 360 - 372
  • [2] Network intrusion detection system: A systematic study of machine learning and deep learning approaches
    Ahmad, Zeeshan
    Shahid Khan, Adnan
    Wai Shiang, Cheah
    Abdullah, Johari
    Ahmad, Farhan
    [J]. TRANSACTIONS ON EMERGING TELECOMMUNICATIONS TECHNOLOGIES, 2021, 32 (01)
  • [3] Designing accurate lightweight intrusion detection systems for IoT networks using fine-tuned linear SVM and feature selectors
    Azimjonov, Jahongir
    Kim, Taehong
    [J]. COMPUTERS & SECURITY, 2024, 137
  • [4] Baldi P, 2013, Advances in neural information processing systems
  • [5] Robust Network Intrusion Detection Through Explainable Artificial Intelligence (XAI)
    Barnard, Pieter
    Marchetti, Nicola
    Dasilva, Luiz A.
    [J]. IEEE Networking Letters, 2022, 4 (03): : 167 - 171
  • [6] An Explanation of the LSTM Model Used for DDoS Attacks Classification
    Bashaiwth, Abdulmuneem
    Binsalleeh, Hamad
    AsSadhan, Basil
    [J]. APPLIED SCIENCES-BASEL, 2023, 13 (15):
  • [7] Bjorck J, 2018, ADV NEUR IN, V31
  • [8] Network Intrusion Detection Model Based on CNN and GRU
    Cao, Bo
    Li, Chenghai
    Song, Yafei
    Qin, Yueyi
    Chen, Chen
    [J]. APPLIED SCIENCES-BASEL, 2022, 12 (09):
  • [9] Debicha I., 2021, arXiv
  • [10] Dhanabal L., 2015, Int. J. Adv. Res. Comput. Commun. Eng, V4, P446, DOI DOI 10.17148/IJARCCE.2015.4696