Interpretability and Complexity Reduction in Iot Network Anomaly Detection Via XAI

Alfredo Nascita, Raffaele Carillo, Federica Giampetraglia, Antonio Iacono, Valerio Persico, Antonio Pescapè · 2024

Due to their versatility and effectiveness, Deep Learning (DL) approaches are increasingly used in designing Network Intrusion Detection Systems (NIDSs). Specifically, Anomaly Detection (AD) approaches such as AutoEncoders proved suitable when malicious traffic for training is not available. However, understanding how and why DL models provide a certain decision is often challenging, since they are often considered black boxes. In this paper, we develop a methodology based on SHAP—a well-known eXplainable Artificial Intelligence (XAI) technique—to elucidate the contribution of traffic features to the decisions of anomaly detectors. The interpretability gained through our methodology facilitates a deeper understanding of the characteristics of network traffic that drive the detection process. We evaluate our methodology on two recent IoT datasets including attack traffic (Kitsune and IoT-23). Leveraging the interpretability results, our investigation yields substantial enhancements in model complexity (up to −98%) without compromising its detection capabilities. The experimental results underscore the potential of XAI in refining and advancing the landscape of NIDSs.

Read the paper · More papers on PaperTik