XAI for intrusion detection system: comparing explanations based on global and local scope

被引:24
|
作者
Hariharan, Swetha [1 ]
Robinson, R. R. Rejimol [2 ]
Prasad, Rendhir R. [3 ]
Thomas, Ciza [4 ]
Balakrishnan, N. [1 ]
机构
[1] Indian Inst Sci, Supercomp Educ & Res Ctr, Bangalore, Karnataka, India
[2] SCT Coll Engn, Thiruvananthapuram, Kerala, India
[3] Govt Engn Coll, Barton Hill, Thiruvananthapuram, Kerala, India
[4] Govt Kerala, Directorate Tech Educ, Thiruvananthapuram, Kerala, India
关键词
Intrusion detection system; RF; XGBoost; LightGBM; XAI; SHAP; LIME; Permutation importance; Contextual importance and utility;
D O I
10.1007/s11416-022-00441-2
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Intrusion Detection System is a device or software in the field of cybersecurity that has become an essential tool in computer networks to provide a secured network environment. Machine Learning based IDS offers a self-learning solution and provides better performance when compared to traditional IDS. As the predictive performance of IDS is based on conflicting criteria, the underlying algorithms are becoming more complex and hence, less transparent. Explainable Artificial Intelligence is a set of frameworks that help to develop interpretable and inclusive machine learning models. In this paper, we use Permutation Importance, SHapley Additive exPlanation, Local Interpretable Model-Agnostic Explanation algorithms, Contextual Importance and Utility algorithms, covering both global and local scope of explanation to IDSs on Random Forest, eXtreme Gradient Boosting and Light Gradient Boosting machine learning models along with a comparison of explanations in terms of accuracy, consistency and stability. This comparison can help cyber security personnel to have a better understanding of the predictions of cyber-attacks in the network traffic. A case study focusing on DoS attack variants shows some useful insights on the impact of features in prediction performance.
引用
收藏
页码:217 / 239
页数:23
相关论文
共 50 条
  • [1] XAI for intrusion detection system: comparing explanations based on global and local scope
    Swetha Hariharan
    R. R. Rejimol Robinson
    Rendhir R. Prasad
    Ciza Thomas
    N. Balakrishnan
    Journal of Computer Virology and Hacking Techniques, 2023, 19 : 217 - 239
  • [2] An Intrusion Detection System over the IoT Data Streams Using eXplainable Artificial Intelligence (XAI)
    Alabbadi, Adel
    Bajaber, Fuad
    SENSORS, 2025, 25 (03)
  • [3] Hybrid Explainable Intrusion Detection System: Global vs. Local Approach
    Tanuwidjaja, Harry Chandra
    Takahashi, Takeshi
    Lin, Tsung-Nan
    Lee, Boyi
    Ban, Tao
    PROCEEDINGS OF THE 2023 WORKSHOP ON RECENT ADVANCES IN RESILIENT AND TRUSTWORTHY ML SYSTEMS IN AUTONOMOUS NETWORKS, ARTMAN 2023, 2023, : 37 - 42
  • [4] Experimental Analysis of Trustworthy In-Vehicle Intrusion Detection System Using eXplainable Artificial Intelligence (XAI)
    Lundberg, Hampus
    Mowla, Nishat, I
    Abedin, Sarder Fakhrul
    Thar, Kyi
    Mahmood, Aamir
    Gidlund, Mikael
    Raza, Shahid
    IEEE ACCESS, 2022, 10 : 102831 - 102841
  • [5] Assessing degree of intrusion scope (DIS): a statistical strategy for anomaly based intrusion detection
    V. Jyothsna
    V. V. Rama Prasad
    CSI Transactions on ICT, 2018, 6 (2) : 99 - 127
  • [6] Intrusion Detection System Based on Classification
    Gong Shang-fu
    Zhao Chun-lan
    2012 IEEE INTERNATIONAL CONFERENCE ON INTELLIGENT CONTROL, AUTOMATIC DETECTION AND HIGH-END EQUIPMENT (ICADE), 2012, : 78 - 83
  • [7] An Intrusion Detection System Based on Hadoop
    Shi, Zhiguo
    An, Jianwei
    IEEE 12TH INT CONF UBIQUITOUS INTELLIGENCE & COMP/IEEE 12TH INT CONF ADV & TRUSTED COMP/IEEE 15TH INT CONF SCALABLE COMP & COMMUN/IEEE INT CONF CLOUD & BIG DATA COMP/IEEE INT CONF INTERNET PEOPLE AND ASSOCIATED SYMPOSIA/WORKSHOPS, 2015, : 826 - 830
  • [8] Review on Intrusion Detection System Based on The Goal of The Detection System
    Khaleel, Mohammad Khamees
    Ismail, Mohd Arfian
    Yunan, Umar
    Kasim, Shahreen
    INTERNATIONAL JOURNAL OF INTEGRATED ENGINEERING, 2018, 10 (06): : 197 - 202
  • [9] A Constraint-based Intrusion Detection System
    Hasan, Md Siam
    Dean, Thomas
    Imam, Fahim T.
    Garcia, Francisco
    Leblanc, Sylvain P.
    Zulkernine, Mohammad
    PROCEEDINGS OF THE FIFTH EUROPEAN CONFERENCE ON THE ENGINEERING OF COMPUTER-BASED SYSTEMS (ECBS 2017), 2017,
  • [10] Fuzzy based intrusion detection system in MANET
    Edwin Singh C.
    Celestin Vigila S.M.
    Measurement: Sensors, 2023, 26