Hybrid Explainable Intrusion Detection System: Global vs. Local Approach

被引:0
|
作者
Tanuwidjaja, Harry Chandra [1 ]
Takahashi, Takeshi [1 ]
Lin, Tsung-Nan [2 ]
Lee, Boyi [3 ]
Ban, Tao [1 ]
机构
[1] Natl Inst Informat & Commun Technol, Tokyo, Japan
[2] Natl Taiwan Univ, Taipei, Taiwan
[3] Natl Appl Res Labs, Taipei, Taiwan
关键词
IDS; explanation; XAI; X-IDS; local interpretable model-agnostic explanations; Shapley additive explanation;
D O I
10.1145/3605772.3624004
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Intrusion Detection Systems (IDSs) play a major role in detecting suspicious activities and alerting users of potential malicious adversaries. Security operators investigate these alerts and attempt to mitigate the risks and damage. Many IDS-related studies have focused on improving detection accuracy and reducing false positives; however, the operators need to understand the rationale behind IDS engines issuing an alert. In contrast to conventional rule-based engines, machine-learning-based engines use a detection mechanism that is like a black box, i.e., it is not designed to indicate a rationale. In this paper, we introduce an explainable IDS (X-IDS) that copes with the well-used XAI techniques to ensure that the system can explain the decisions. To this end, we used local interpretable model-agnostic explanations and Shapley additive explanations, and we evaluated their differing characteristics. We proposed our explanation framework that consists of the variable importance plot, individual value plot, and partial dependence plot. Furthermore, we conclude by discussing future issues regarding better explainable IDS.
引用
收藏
页码:37 / 42
页数:6
相关论文
共 50 条
  • [1] A Hybrid Approach for an Interpretable and Explainable Intrusion Detection System
    Dias, Tiago
    Oliveira, Nuno
    Sousa, Norberto
    Praca, Isabel
    Sousa, Orlando
    [J]. INTELLIGENT SYSTEMS DESIGN AND APPLICATIONS, ISDA 2021, 2022, 418 : 1035 - 1045
  • [2] A Hybrid Approach for Intrusion Detection System
    Hariyale, Neelam
    Rathore, Manjari Singh
    Prasad, Ritu
    Saurabh, Praneet
    [J]. SOFT COMPUTING FOR PROBLEM SOLVING, SOCPROS 2018, VOL 1, 2020, 1048 : 391 - 403
  • [3] Local vs. global approach in the analysis of sintering kinetics
    Kang, Suk-Joong L.
    [J]. SCRIPTA MATERIALIA, 2009, 60 (10) : 921 - 922
  • [4] Explainable Artificial Intelligence for Intrusion Detection System
    Patil, Shruti
    Varadarajan, Vijayakumar
    Mazhar, Siddiqui Mohd
    Sahibzada, Abdulwodood
    Ahmed, Nihal
    Sinha, Onkar
    Kumar, Satish
    Shaw, Kailash
    Kotecha, Ketan
    [J]. ELECTRONICS, 2022, 11 (19)
  • [5] An Explainable Intrusion Detection System for IoT Networks
    Fazzolari, Michela
    Ducange, Pietro
    Marcelloni, Francesco
    [J]. 2023 IEEE INTERNATIONAL CONFERENCE ON FUZZY SYSTEMS, FUZZ, 2023,
  • [6] Model redundancy vs. intrusion detection
    Li, ZW
    Das, A
    Emmanuel, S
    [J]. INFORMATION SECURITY PRACTICE AND EXPERIENCE, 2005, 3439 : 217 - 229
  • [7] HYBRID INTRUSION DETECTION APPROACH FOR WIRELESS LOCAL AREA NETWORK
    Ozkan-Okay, Merve
    Samet, Refik
    [J]. PROCEEDINGS OF THE7TH INTERNATIONAL CONFERENCE ON CONTROL AND OPTIMIZATION WITH INDUSTRIAL APPLICATIONS, VOL. 1, 2020, : 311 - 313
  • [8] A Hybrid Feature Reduced Approach for Intrusion Detection System
    Garg, Lavisha
    Akashdeep
    Aggarwal, Naveen
    [J]. COMPUTING AND NETWORK SUSTAINABILITY, 2019, 75
  • [9] A Global Hybrid Intrusion Detection System for Wireless Sensor Networks
    Maleh, Yassine
    Ezzati, Abdellah
    Qasmaoui, Youssef
    Mbida, Mohamed
    [J]. 6TH INTERNATIONAL CONFERENCE ON AMBIENT SYSTEMS, NETWORKS AND TECHNOLOGIES (ANT-2015), THE 5TH INTERNATIONAL CONFERENCE ON SUSTAINABLE ENERGY INFORMATION TECHNOLOGY (SEIT-2015), 2015, 52 : 1047 - 1052
  • [10] Local vs. global pragmatics
    Borg, Emma
    [J]. INQUIRY-AN INTERDISCIPLINARY JOURNAL OF PHILOSOPHY, 2017, 60 (05): : 509 - 516