An intrusion detection system based on multiple interpretation methods
Dongwen Chai, Xiaofen Wang, Xiaosong Zhang, Haomiao Yang, Tao Chen · 2022
In recent years, many related researches on machine learning-based IDSs have achieved remarkable results. The researchers further focused on improving the interpretability of machine learning to increase the trustworthiness of the model. However, the discrepancy between the interpretation results and the expert knowledge also arises. In this paper we propose an Intrusion Detection System that combines multiple interpretable methods to achieve the best interpretation performance in terms of stability, loyalty and complexity, which makes the interpretation results closer to expert knowledge. This is the first study to combine multiple interpretation methods in the field of intrusion detection. Experiments show that the coincidence rate of the important features corresponding to four attacks given by our method and the artificially extracted expert knowledge increases by 26% and 46% on average compared with the results in SHAP-based-IDS and UFGM-IDS, respectively. NSL-KDD dataset is used as experimental validation in our experiment.