An Explainable Intrusion Detection System

Yun Wang, Pan Wang, Zixuan Wang, Mengting Cao · 2021

Malicious traffic detection has become a challenge in modern communications. As the research of intrusion detection systems becomes more and more in-depth, from machine learning to deep learning, the accuracy of intrusion detection continues to improve, the complexity of the model is getting higher and higher, and the interpretability of the model is lower. The model is like a black box, it is difficult for people to know the reason behind the decision. In fact, the interpretability of the model has made some achievements in the fields of biology, computer vision, and natural language processing. Therefore, in this article, for an intrusion detection system based on deep neural networks, we propose an interpretable artificial intelligence framework to enhance the transparency of machine learning decision-making, that is, which important features the model uses to determine attack or non attack. We use the SHAP method to explain, and combine local and global explanations to realize IDS interpretation in all directions. The partial explanation gives us the reason why the model makes a decision on a particular instance, which gives us a certain reference value. The global interpretation gives the important characteristics of the model as a whole, which helps to improve the transparency of IDS. We use the CICIDS2017 dataset to verify the feasibility of the intrusion detection system's two-classification experiment. Interpretability work can help network security personnel better understand the decision-making of intrusion detection system.

Read the paper · More papers on PaperTik