Explainable AI-based innovative hybrid ensemble model for intrusion detection

被引:1
作者
Ahmed, Usman [1 ]
Zheng, Jiangbin [1 ]
Almogren, Ahmad [2 ]
Khan, Sheharyar [1 ]
Sadiq, Muhammad Tariq [3 ,4 ]
Altameem, Ayman [5 ]
Rehman, Ateeq Ur [6 ]
机构
[1] Northwestern Polytech Univ, Sch Software, Xian 710072, Peoples R China
[2] King Saud Univ, Coll Comp & Informat Sci, Dept Comp Sci, Riyadh 11633, Saudi Arabia
[3] Univ Essex, Sch Comp Sci & Elect Engn, Colchester Campus, Colchester, England
[4] Appl Sci Private Univ, Appl Sci Res Ctr, Amman, Jordan
[5] King Saud Univ, Coll Appl Studies & Community Serv, Dept Nat & Engn Sci, Riyadh 11543, Saudi Arabia
[6] Gachon Univ, Sch Comp, Seongnam Si 13120, South Korea
来源
JOURNAL OF CLOUD COMPUTING-ADVANCES SYSTEMS AND APPLICATIONS | 2024年 / 13卷 / 01期
关键词
Stacking ensemble; Bayesian model averaging; Conditional ensemble method; Machine learning; Explainable AI; Network security; Intrusion detection; DETECTION SYSTEMS; ARCHITECTURE; IDS;
D O I
10.1186/s13677-024-00712-x
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cybersecurity threats have become more worldly, demanding advanced detection mechanisms with the exponential growth in digital data and network services. Intrusion Detection Systems (IDSs) are crucial in identifying illegitimate access or anomalous behaviour within computer network systems, consequently opposing sensitive information. Traditional IDS approaches often struggle with high false positive rates and the ability to adapt embryonic attack patterns. This work asserts a novel Hybrid Adaptive Ensemble for Intrusion Detection (HAEnID), an innovative and powerful method to enhance intrusion detection, different from the conventional techniques. HAEnID is composed of a string of multi-layered ensemble, which consists of a Stacking Ensemble (SEM), a Bayesian Model Averaging (BMA), and a Conditional Ensemble method (CEM). HAEnID combines the best of these three ensemble techniques for ultimate success in detection with a considerable cut in false alarms. A key feature of HAEnID is an adaptive mechanism that allows ensemble components to change over time as network traffic patterns vary and new threats appear. This way, HAEnID would provide adequate protection as attack vectors change. Furthermore, the model would become more interpretable and explainable using Shapley Additive Explanations (SHAP) and Local Interpretable Model-agnostic Explanations (LIME). The proposed Ensemble model for intrusion detection on CIC-IDS 2017 achieves excellent accuracy (97-98%), demonstrating effectiveness and consistency across various configurations. Feature selection further enhances performance, with BMA-M (20) reaching 98.79% accuracy. These results highlight the potential of the ensemble model for accurate and reliable intrusion detection and, hence, is a state-of-the-art choice for accuracy and explainability.
引用
收藏
页数:34
相关论文
共 70 条
  • [1] A New Ensemble-Based Intrusion Detection System for Internet of Things
    Abbas, Adeel
    Khan, Muazzam A.
    Latif, Shahid
    Ajaz, Maria
    Shah, Awais Aziz
    Ahmad, Jawad
    [J]. ARABIAN JOURNAL FOR SCIENCE AND ENGINEERING, 2022, 47 (02) : 1805 - 1819
  • [2] Abbasi Fereshteh, 2021, 2021 5th International Conference on Internet of Things and Applications (IoT), DOI 10.1109/IoT52625.2021.9469605
  • [3] Classification model for accuracy and intrusion detection using machine learning approach
    Agarwal, Arushi
    Sharma, Purushottam
    Alshehri, Mohammed
    Mohamed, Ahmed A.
    Alfarraj, Osama
    [J]. PEERJ COMPUTER SCIENCE, 2021,
  • [4] Network intrusion detection system: A systematic study of machine learning and deep learning approaches
    Ahmad, Zeeshan
    Shahid Khan, Adnan
    Wai Shiang, Cheah
    Abdullah, Johari
    Ahmad, Farhan
    [J]. TRANSACTIONS ON EMERGING TELECOMMUNICATIONS TECHNOLOGIES, 2021, 32 (01)
  • [5] Al Obaidli A, 2023, 2023 1 INT C ADV INN, P1
  • [6] Ensemble-Learning Framework for Intrusion Detection to Enhance Internet of Things' Devices Security
    Alotaibi, Yazeed
    Ilyas, Mohammad
    [J]. SENSORS, 2023, 23 (12)
  • [7] Alshaher H., 2021, THESIS N CAROLINA AG
  • [8] Explaining anomalies detected by autoencoders using Shapley Additive Explanations
    Antwarg, Liat
    Miller, Ronnie Mindlin
    Shapira, Bracha
    Rokach, Lior
    [J]. EXPERT SYSTEMS WITH APPLICATIONS, 2021, 186
  • [9] An intrusion detection framework for energy constrained IoT devices
    Arshad, Junaid
    Azad, Muhammad Ajmal
    Abdeltaif, Muhammad Mahmoud
    Salah, Khaled
    [J]. MECHANICAL SYSTEMS AND SIGNAL PROCESSING, 2020, 136 (136)
  • [10] A Flexible SDN-Based Architecture for Identifying and Mitigating Low-Rate DDoS Attacks Using Machine Learning
    Arturo Perez-Diaz, Jesus
    Amezcua Valdovinos, Ismael
    Choo, Kim-Kwang Raymond
    Zhu, Dakai
    [J]. IEEE ACCESS, 2020, 8 (08): : 155859 - 155872