Detecting Poisoning Attacks in Collaborative IDSs of Vehicular Networks Using XAI and Shapley Value
Ahmed Saleh Bataineh, Mohammad Zulkernine, Adel Hammad Abusitta, Talal Halabi · ACM Journal on Autonomous Transportation Systems · 2024
Machine learning-based Intrusion Detection Systems (IDSs) for vehicle networks can collaborate to enhance their performance by sharing crucial decisions when individual datasets lack diversity, which hinders effective model training. However, such collaborative coalitions are vulnerable to poisoning attacks, where certain members tamper with training data, leading to wrong predictions by the IDSs. The current solutions to this problem have the following issues: (1) They require accessing the training dataset of IDSs, which raises critical privacy concerns; (2) their heavy reliance on voting mechanisms may exclude clients and fail to detect malicious coalition members when attackers form the majority coalition; and (3) the verification process can potentially expose sensitive information, posing privacy risks. To address these issues and improve the resilience of collaborative IDSs against poisoning attacks, we propose a novel approach that combines XAI (Explainable AI) technology with Shapley value from cooperative game theory. XAI justifies IDS decisions, while the Shapley value identifies poisoning attacks in training datasets by capturing contradictions between explanations and decisions. We tested our implementation using a publicly available dataset and various machine learning models (e.g., RFC, SVM, and LSTM). Our results prove highly promising in detecting poisoning attacks and overcoming the flaws in existing solutions.