Explainable Machine Learning for Intrusion Detection

被引:0
|
作者
Bellegdi, Sameh [1 ]
Selamat, Ali [1 ,2 ,3 ,4 ]
Olatunji, Sunday O. [5 ]
Fujita, Hamido [1 ]
Krejcar, Ondfrej [4 ]
机构
[1] Univ Teknol Malaysia UTM, Malaysia Japan Int Inst Technol, Kuala Lumpur 54100, Malaysia
[2] Univ Teknol Malaysia, Univ Teknol Malaysia UTM, Fac Comp, Johor Baharu 81310, Johor, Malaysia
[3] Univ Teknol Malaysia, Media & Games Ctr Excellence MagicX, Johor Baharu 81310, Johor, Malaysia
[4] Univ Hradec Kralove, Rokitanskeho 62, Hradec Kralove 50003, Czech Republic
[5] Imam Abdulrahman Bin Faisal Univ, Dammam 31441, Saudi Arabia
来源
ADVANCES AND TRENDS IN ARTIFICIAL INTELLIGENCE: THEORY AND APPLICATIONS, IEA-AIE 2024 | 2024年 / 14748卷
关键词
intrusion detection; IDS; machine learning; explainable machine learning; XAI; SHAP; LIME;
D O I
10.1007/978-981-97-4677-4_11
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Intrusion detection systems (IDS) are essential tools to maintain robust cybersecurity. Machine learning (ML)-based IDS provides promising results. However, such IDS are recognized as black-box and lack trust and transparency. There is a limited number of explainable IDS (X-IDS). Moreover, several X-IDS used outdated datasets. Some papers used deep neural network which is computationally expensive. This paper proposes lightweight tree-based X-IDS using a recent IDS dataset. We explore the effectiveness of explainable artificial intelligence (XAI) techniques in increasing ML-based IDS transparency. Four ML algorithms are employed; viz. LightGBM, random forests, AdaBoost, and XGBoost; to classify a given network flow as benign or malicious. Network flows extracted from the CSE-CIC-IDS2018 dataset are used to evaluate the IDS models. The best F1-score results of 0.979 and 0.978 are achieved with LightGBM and XGBoost, respectively. We use SHapley Additive exPlanations (SHAP) and Local Model-Agnostic Explanations (LIME) techniques to provide global and local explanations for predictions made by the LightGBM. The obtained explanations in the form of graphs provide measurable insights for cybersecurity experts regarding the most important features that impact the detection of intrusions.
引用
收藏
页码:122 / 134
页数:13
相关论文
共 50 条
  • [41] Enhancing Network Security: Leveraging Machine Learning for Intrusion Detection
    Rao, M. Veera V. Rama
    Rapaka, Anuj
    Prasad, M.
    Rao, P. B. V. Raja
    Satyanarayanamurty, P.
    Pokkuluri, Kiran Sree
    JOURNAL OF ELECTRICAL SYSTEMS, 2024, 20 (02) : 1555 - 1562
  • [42] Role of Machine Learning in Intrusion Detection System: A Systematic Review
    Alhasani, Areej
    Al Omrani, Faten
    Alzahrani, Taghreed
    alFahhad, Rehab
    Alotaibi, Mohamed
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2022, 22 (03): : 155 - 162
  • [43] An intrusion detection system based on hybrid machine learning classifier
    Reji, M.
    Joseph, Christeena
    Nancy, P.
    Mary, A. Lourdes
    JOURNAL OF INTELLIGENT & FUZZY SYSTEMS, 2023, 44 (03) : 4245 - 4255
  • [44] TinyIDS - An IoT Intrusion Detection System by Tiny Machine Learning
    Fusco, Pietro
    Rimoli, Gennaro Pio
    Ficco, Massimo
    COMPUTATIONAL SCIENCE AND ITS APPLICATIONS-ICCSA 2024 WORKSHOPS, PT II, 2024, 14816 : 71 - 82
  • [45] Intrusion detection based on Machine Learning techniques in computer networks
    Dina, Ayesha S.
    Manivannan, D.
    INTERNET OF THINGS, 2021, 16
  • [46] Performance Evaluation of Supervised Machine Learning Algorithms for Intrusion Detection
    Belavagi, Manjula C.
    Muniyal, Balachandra
    TWELFTH INTERNATIONAL CONFERENCE ON COMMUNICATION NETWORKS, ICCN 2016 / TWELFTH INTERNATIONAL CONFERENCE ON DATA MINING AND WAREHOUSING, ICDMW 2016 / TWELFTH INTERNATIONAL CONFERENCE ON IMAGE AND SIGNAL PROCESSING, ICISP 2016, 2016, 89 : 117 - 123
  • [47] Analysis on intrusion detection system using machine learning techniques
    Seraphim B.I.
    Poovammal E.
    Lecture Notes on Data Engineering and Communications Technologies, 2021, 66 : 423 - 441
  • [48] Machine Learning With Variational AutoEncoder for Imbalanced Datasets in Intrusion Detection
    Lin, Ying-Dar
    Liu, Zi-Qiang
    Hwang, Ren-Hung
    Van-Linh Nguyen
    Lin, Po-Ching
    Lai, Yuan-Cheng
    IEEE ACCESS, 2022, 10 : 15247 - 15260
  • [49] Improved Preprocessing for Machine Learning Intrusion Detection in IEEE 802.11
    Skrak, Peter
    Lehoczky, Peter
    Bencel, Rastislav
    Galinski, Marek
    Kotuliak, Ivan
    PROCEEDINGS OF THE 2022 14TH IFIP WIRELESS AND MOBILE NETWORKING CONFERENCE (WMNC 2022), 2022, : 118 - 122
  • [50] Improving the performance of the intrusion detection systems by the machine learning explainability
    Quang-Vinh Dang
    INTERNATIONAL JOURNAL OF WEB INFORMATION SYSTEMS, 2021, 17 (05) : 537 - 555