Interpretable Intrusion Detection through Approximation of Complex Model
Mengyu Qi, Zun Liu, Yangming Guo, Long Jiang, Yucan Zou · 2024
Intrusion detection models process attack data efficiently with high accuracy while security researchers make decisions based on their results. However, despite the excellent detection results of black-box models, researchers cannot improve their decisions based on the model's predictions. To address the above issues, this paper proposes an interpretable RFAL-stack intrusion detection model, which builds an ensemble L-stack model to accomplish intrusion detection efficiently and transparentizes the original model with random forest approximation. With the transparent random forest, the RFAL-stack can output its decision paths and quantitatively measure the actual contribution of different paths to the results. Finally, the article experimentally demonstrates that the RFAL-stack significantly reduces the decision tree size and improves the interpretability of the model with guaranteed detection performance.