Hybrid Explainable Intrusion Detection System: Global vs. Local Approach

被引:0
|
作者
Tanuwidjaja, Harry Chandra [1 ]
Takahashi, Takeshi [1 ]
Lin, Tsung-Nan [2 ]
Lee, Boyi [3 ]
Ban, Tao [1 ]
机构
[1] Natl Inst Informat & Commun Technol, Tokyo, Japan
[2] Natl Taiwan Univ, Taipei, Taiwan
[3] Natl Appl Res Labs, Taipei, Taiwan
来源
PROCEEDINGS OF THE 2023 WORKSHOP ON RECENT ADVANCES IN RESILIENT AND TRUSTWORTHY ML SYSTEMS IN AUTONOMOUS NETWORKS, ARTMAN 2023 | 2023年
关键词
IDS; explanation; XAI; X-IDS; local interpretable model-agnostic explanations; Shapley additive explanation;
D O I
10.1145/3605772.3624004
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Intrusion Detection Systems (IDSs) play a major role in detecting suspicious activities and alerting users of potential malicious adversaries. Security operators investigate these alerts and attempt to mitigate the risks and damage. Many IDS-related studies have focused on improving detection accuracy and reducing false positives; however, the operators need to understand the rationale behind IDS engines issuing an alert. In contrast to conventional rule-based engines, machine-learning-based engines use a detection mechanism that is like a black box, i.e., it is not designed to indicate a rationale. In this paper, we introduce an explainable IDS (X-IDS) that copes with the well-used XAI techniques to ensure that the system can explain the decisions. To this end, we used local interpretable model-agnostic explanations and Shapley additive explanations, and we evaluated their differing characteristics. We proposed our explanation framework that consists of the variable importance plot, individual value plot, and partial dependence plot. Furthermore, we conclude by discussing future issues regarding better explainable IDS.
引用
收藏
页码:37 / 42
页数:6
相关论文
共 50 条
  • [1] A Hybrid Approach for Intrusion Detection System
    Hariyale, Neelam
    Rathore, Manjari Singh
    Prasad, Ritu
    Saurabh, Praneet
    SOFT COMPUTING FOR PROBLEM SOLVING, SOCPROS 2018, VOL 1, 2020, 1048 : 391 - 403
  • [2] Explainable Artificial Intelligence for Intrusion Detection System
    Patil, Shruti
    Varadarajan, Vijayakumar
    Mazhar, Siddiqui Mohd
    Sahibzada, Abdulwodood
    Ahmed, Nihal
    Sinha, Onkar
    Kumar, Satish
    Shaw, Kailash
    Kotecha, Ketan
    ELECTRONICS, 2022, 11 (19)
  • [3] EI-XIDS: An explainable intrusion detection system based on integration framework
    Xu Yang
    Li Chen
    Zhang Kun
    Xia Haojun
    Tu Bibo
    PROCEEDINGS OF THE 2024 27 TH INTERNATIONAL CONFERENCE ON COMPUTER SUPPORTED COOPERATIVE WORK IN DESIGN, CSCWD 2024, 2024, : 2680 - 2685
  • [4] XAI for intrusion detection system: comparing explanations based on global and local scope
    Swetha Hariharan
    R. R. Rejimol Robinson
    Rendhir R. Prasad
    Ciza Thomas
    N. Balakrishnan
    Journal of Computer Virology and Hacking Techniques, 2023, 19 : 217 - 239
  • [5] A Hybrid Approach to Mitigate False Positive Alarms in Intrusion Detection System
    Sachin
    Krishna, C. Rama
    INTERNATIONAL CONFERENCE ON COMPUTER NETWORKS AND COMMUNICATION TECHNOLOGIES (ICCNCT 2018), 2019, 15 : 837 - 848
  • [6] XAI for intrusion detection system: comparing explanations based on global and local scope
    Hariharan, Swetha
    Robinson, R. R. Rejimol
    Prasad, Rendhir R.
    Thomas, Ciza
    Balakrishnan, N.
    JOURNAL OF COMPUTER VIROLOGY AND HACKING TECHNIQUES, 2023, 19 (02) : 217 - 239
  • [7] Explainable AI-based innovative hybrid ensemble model for intrusion detection
    Ahmed, Usman
    Zheng, Jiangbin
    Almogren, Ahmad
    Khan, Sheharyar
    Sadiq, Muhammad Tariq
    Altameem, Ayman
    Rehman, Ateeq Ur
    JOURNAL OF CLOUD COMPUTING-ADVANCES SYSTEMS AND APPLICATIONS, 2024, 13 (01):
  • [8] Hybrid Triodetection Approach: A Framework for Intrusion Detection
    Sree, M. Mahithaa
    Saranya, M.
    Shyry, S. Prayla
    INTERNATIONAL CONFERENCE ON INTELLIGENT DATA COMMUNICATION TECHNOLOGIES AND INTERNET OF THINGS, ICICI 2018, 2019, 26 : 1032 - 1038
  • [9] Hybrid architecture for distributed intrusion detection system
    Khonde S.R.
    Venugopal U.
    Ingenierie des Systemes d'Information, 2019, 24 (01): : 19 - 28
  • [10] Explainable AI supported hybrid deep learnig method for layer 2 intrusion detection
    Kilincer, Ilhan Firat
    EGYPTIAN INFORMATICS JOURNAL, 2025, 30