A Novel Explainable Method based on Grad-CAM for Network Intrusion Detection

Yunpeng Sun, Zhichao Lian, Shuangquan Zhang, Zhanfeng Wang, Tao Duan · 2024

When deep learning models are employed in Network Intrusion Detection Systems (NIDSs) to cope with a variety of rising attacks from network, the interpretability of these applications are not studied adequately, which result in the uncertainty of their classification basis and also can not give the warning for how to improve model decisions. In this paper, a new framework is designed to provide a NIDS with visual and quantitative analysis, including a modified ensemble Convolutional Neural Network (CNN) model and a novel explainable method. The ensemble model is used as a feature extractor and aims to make classification. The explainable method in combination with Gradient-weighted Class Activation Mapping (Grad-CAM) is made to calculate feature importance of network traffic from the aspect of spatial relations, and find out the key features for improving model performance. The results of the experiments on NSL-KDD and UNSW-NB15 datasets demonstrate that the new framework, which has a high accuracy comparing with the existing models, can explain the feature importance effectively, and also improve model performance.

Read the paper · More papers on PaperTik