XAI for intrusion detection system: comparing explanations based on global and local scope

被引:24
作者
Hariharan, Swetha [1 ]
Robinson, R. R. Rejimol [2 ]
Prasad, Rendhir R. [3 ]
Thomas, Ciza [4 ]
Balakrishnan, N. [1 ]
机构
[1] Indian Inst Sci, Supercomp Educ & Res Ctr, Bangalore, Karnataka, India
[2] SCT Coll Engn, Thiruvananthapuram, Kerala, India
[3] Govt Engn Coll, Barton Hill, Thiruvananthapuram, Kerala, India
[4] Govt Kerala, Directorate Tech Educ, Thiruvananthapuram, Kerala, India
关键词
Intrusion detection system; RF; XGBoost; LightGBM; XAI; SHAP; LIME; Permutation importance; Contextual importance and utility;
D O I
10.1007/s11416-022-00441-2
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Intrusion Detection System is a device or software in the field of cybersecurity that has become an essential tool in computer networks to provide a secured network environment. Machine Learning based IDS offers a self-learning solution and provides better performance when compared to traditional IDS. As the predictive performance of IDS is based on conflicting criteria, the underlying algorithms are becoming more complex and hence, less transparent. Explainable Artificial Intelligence is a set of frameworks that help to develop interpretable and inclusive machine learning models. In this paper, we use Permutation Importance, SHapley Additive exPlanation, Local Interpretable Model-Agnostic Explanation algorithms, Contextual Importance and Utility algorithms, covering both global and local scope of explanation to IDSs on Random Forest, eXtreme Gradient Boosting and Light Gradient Boosting machine learning models along with a comparison of explanations in terms of accuracy, consistency and stability. This comparison can help cyber security personnel to have a better understanding of the predictions of cyber-attacks in the network traffic. A case study focusing on DoS attack variants shows some useful insights on the impact of features in prediction performance.
引用
收藏
页码:217 / 239
页数:23
相关论文
共 50 条
  • [31] An Intrusion Detection System Based on a Simplified Residual Network
    Xiao, Yuelei
    Xiao, Xing
    INFORMATION, 2019, 10 (11)
  • [32] Intrusion Detection System Based On The Integrity of TCP Packet
    Alhamaty, Moad
    Yazdian, Ali
    Al-qadasi, Fathi
    PROCEEDINGS OF WORLD ACADEMY OF SCIENCE, ENGINEERING AND TECHNOLOGY, VOL 11, 2006, 11 : 234 - +
  • [33] A Feature Selection Based DNN for Intrusion Detection System
    Li, Li-Hua
    Ahmad, Ramli
    Tsai, Wen-Chung
    Sharma, Alok Kumar
    PROCEEDINGS OF THE 2021 15TH INTERNATIONAL CONFERENCE ON UBIQUITOUS INFORMATION MANAGEMENT AND COMMUNICATION (IMCOM 2021), 2021,
  • [34] Ontology-based Distributed Intrusion Detection System
    Abdoli, F.
    Kahani, M.
    2009 14TH INTERNATIONAL COMPUTER CONFERENCE, 2009, : 65 - +
  • [35] A Smart Grid Intrusion Detection System Based on Optimization
    Liu, Gaoyuan
    Sun, Huayi
    Zhong, Guangyuan
    2021 3RD INTERNATIONAL CONFERENCE ON SMART POWER & INTERNET ENERGY SYSTEMS (SPIES 2021), 2021, : 284 - 290
  • [36] Anomaly-Based Network Intrusion Detection System
    Villalba, L. J. G.
    Orozco, A. L. S.
    Vidal, J. M.
    IEEE LATIN AMERICA TRANSACTIONS, 2015, 13 (03) : 850 - 855
  • [37] Network Intrusion Detection System based on Direct LDA
    Saad, Alaoui-Adib
    Khalid, Chougdali
    Mohamed, Jedra
    PROCEEDINGS OF 2015 THIRD IEEE WORLD CONFERENCE ON COMPLEX SYSTEMS (WCCS), 2015,
  • [38] Smart Fluid Agent Based Intrusion Detection System
    Saha, Ankita
    Setua, S. K.
    PROCEEDINGS OF 2015 4TH INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND NETWORK TECHNOLOGY (ICCSNT 2015), 2015, : 1070 - 1073
  • [39] An explainable intrusion detection system based on feature importance
    Liao, Peixin
    Huang, Xvxin
    Huang, Qiangbo
    Liang, Yanming
    Wang, Zhongxiao
    Zhang, Denghui
    2023 IEEE 12TH INTERNATIONAL CONFERENCE ON CLOUD NETWORKING, CLOUDNET, 2023, : 389 - 397
  • [40] Research on Vehicular External Network Intrusion Detection System Based on Ensemble Learning
    Liu, Qian
    Bao, Weijie
    Liu, Qilie
    2023 IEEE 98TH VEHICULAR TECHNOLOGY CONFERENCE, VTC2023-FALL, 2023,