A Shapley-based Lightweight Global Explainer for Network Intrusion Detection System

Hangsheng Zhang, Yu Chen, Weiyu Liu, Shangyuan Zhuang, Jiyan Sun, Yinlong Liu, Liru Geng · 2022

As deep learning models usually suffer from the black-box problem, even well-performing network intrusion detection systems (NIDSs) are not trusted by safety-critical practitioners. Thus explaining the decision-making mechanism of NIDSs model is urgently needed. Shapley-based explanation methods are promising due to their theoretical guarantees and the ability to capture the interactions between features. However, they require exponential computation and are time-consuming, especially for global explanation. This makes them insufficient for the need of NIDSs to quickly understand global threats and respond rapidly to malicious behavior. According to our in-depth analysis of NIDSs' data and mechanism of Shapley-based global explanation, we identified two culprits that lead to computationally complex and time-consuming. They are significant data redundancy and global queries in two steps during explanation, respectively. To address the above problems, we develop SLGE as a novel Shapley-based lightweight global explainer. As an innovative first step, SLGE introduces a multi-objective data reduction method based on our proposed metrics for assessing data quality. Then the high-quality sub-dataset obtained by data reduction is used to optimize the two steps that require global queries during global explaining. Our experimental results demonstrate that SLGE can accelerate global explanation for deep learning-based NIDS by up to 10 times and for random forest-based NIDS by up to 3 times while ensuring high-quality (75% fidelity) explanations.

Read the paper · More papers on PaperTik