Explainable Machine Learning for Intrusion Detection

被引:0
|
作者
Bellegdi, Sameh [1 ]
Selamat, Ali [1 ,2 ,3 ,4 ]
Olatunji, Sunday O. [5 ]
Fujita, Hamido [1 ]
Krejcar, Ondfrej [4 ]
机构
[1] Univ Teknol Malaysia UTM, Malaysia Japan Int Inst Technol, Kuala Lumpur 54100, Malaysia
[2] Univ Teknol Malaysia, Univ Teknol Malaysia UTM, Fac Comp, Johor Baharu 81310, Johor, Malaysia
[3] Univ Teknol Malaysia, Media & Games Ctr Excellence MagicX, Johor Baharu 81310, Johor, Malaysia
[4] Univ Hradec Kralove, Rokitanskeho 62, Hradec Kralove 50003, Czech Republic
[5] Imam Abdulrahman Bin Faisal Univ, Dammam 31441, Saudi Arabia
关键词
intrusion detection; IDS; machine learning; explainable machine learning; XAI; SHAP; LIME;
D O I
10.1007/978-981-97-4677-4_11
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Intrusion detection systems (IDS) are essential tools to maintain robust cybersecurity. Machine learning (ML)-based IDS provides promising results. However, such IDS are recognized as black-box and lack trust and transparency. There is a limited number of explainable IDS (X-IDS). Moreover, several X-IDS used outdated datasets. Some papers used deep neural network which is computationally expensive. This paper proposes lightweight tree-based X-IDS using a recent IDS dataset. We explore the effectiveness of explainable artificial intelligence (XAI) techniques in increasing ML-based IDS transparency. Four ML algorithms are employed; viz. LightGBM, random forests, AdaBoost, and XGBoost; to classify a given network flow as benign or malicious. Network flows extracted from the CSE-CIC-IDS2018 dataset are used to evaluate the IDS models. The best F1-score results of 0.979 and 0.978 are achieved with LightGBM and XGBoost, respectively. We use SHapley Additive exPlanations (SHAP) and Local Model-Agnostic Explanations (LIME) techniques to provide global and local explanations for predictions made by the LightGBM. The obtained explanations in the form of graphs provide measurable insights for cybersecurity experts regarding the most important features that impact the detection of intrusions.
引用
收藏
页码:122 / 134
页数:13
相关论文
共 50 条
  • [31] Intrusion Detection Using Machine Learning and Deep Learning Techniques
    Calisir, Sinan
    Atay, Remzi
    Pehlivanoglu, Meltem Kurt
    Duru, Nevcihan
    2019 4TH INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND ENGINEERING (UBMK), 2019, : 656 - 660
  • [32] Adversarial Robust and Explainable Network Intrusion Detection Systems Based on Deep Learning
    Sauka, Kudzai
    Shin, Gun-Yoo
    Kim, Dong-Wook
    Han, Myung-Mook
    APPLIED SCIENCES-BASEL, 2022, 12 (13):
  • [33] DeepIIoT: An Explainable Deep Learning Based Intrusion Detection System for Industrial IOT
    Alani, Mohammed M.
    Damiani, Ernesto
    Ghosh, Uttam
    2022 IEEE 42ND INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS WORKSHOPS (ICDCSW), 2022, : 169 - 174
  • [34] An explainable deep learning-enabled intrusion detection framework in IoT networks
    Keshk, Marwa
    Koroniotis, Nickolaos
    Pham, Nam
    Moustafa, Nour
    Turnbull, Benjamin
    Zomaya, Albert Y.
    INFORMATION SCIENCES, 2023, 639
  • [35] Enhanced and Explainable Deep Learning-Based Intrusion Detection in IoT Networks
    Gyawali, Sohan
    Sartipi, Kamran
    Van Ravesteyn, Benjamin
    Huang, Jiaqi
    Jiang, Yili
    MILCOM 2023 - 2023 IEEE MILITARY COMMUNICATIONS CONFERENCE, 2023,
  • [36] An Explainable Ensemble Deep Learning Approach for Intrusion Detection in Industrial Internet of Things
    Shtayat, Mousa'B Mohammad
    Hasan, Mohammad Kamrul
    Sulaiman, Rossilawati
    Islam, Shayla
    Khan, Atta Ur Rehman
    IEEE ACCESS, 2023, 11 : 115047 - 115061
  • [37] IoBT Intrusion Detection System using Machine Learning
    Alkanjr, Basmh
    Alshammari, Thamer
    2023 IEEE 13TH ANNUAL COMPUTING AND COMMUNICATION WORKSHOP AND CONFERENCE, CCWC, 2023, : 886 - 892
  • [38] Intrusion Detection Study and Enhancement Using Machine Learning
    Mliki, Hela
    Kaceam, Abir Hadj
    Chaari, Lamia
    RISKS AND SECURITY OF INTERNET AND SYSTEMS (CRISIS 2019), 2020, 12026 : 263 - 278
  • [39] On the Evaluation of Sequential Machine Learning for Network Intrusion Detection
    Corsini, Andrea
    Yang, Shanchieh Jay
    Apruzzese, Giovanni
    ARES 2021: 16TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, 2021,
  • [40] Malicious URL and Intrusion Detection using Machine Learning
    Hamza, Amr
    Hammam, Farah
    Abouzeid, Medhat
    Ahmed, Mohammad Arsalan
    Dhou, Salam
    Aloul, Fadi
    38TH INTERNATIONAL CONFERENCE ON INFORMATION NETWORKING, ICOIN 2024, 2024, : 795 - 800