Explainable AI for Anomaly Detection in Cybersecurity: Enhancing Security Analyst Decision-Making

Rekha Sivakolundhu · Journal of Artificial Intelligence Machine Learning and Data Science · 2022

Anomaly detection plays a crucial role in identifying potential cybersecurity threats.While machine learning models have demonstrated impressive detection capabilities, their "black-box" nature often hinders security analysts' understanding and decision-making.This research addresses the challenge of explainable anomaly detection in cybersecurity by developing and evaluating machine learning models that provide transparent and actionable explanations for their predictions.We investigate various explanation techniques, such as feature importance, counterfactual explanations, and rule-based explanations, to determine their effectiveness in assisting security analysts in understanding and responding to anomalies.Through comprehensive experiments and user studies with security analysts, we assess the impact of explainable AI on threat investigation and incident response processes.Our findings highlight the potential of explainable anomaly detection to improve both the efficiency and accuracy of security operations, ultimately enhancing cybersecurity resilience.This research contributes to the growing field of explainable AI in cybersecurity and offers practical solutions to bridge the gap between machine learning models and human decision-makers.

Read the paper · More papers on PaperTik