Analysis of Network Intrusion Detection via Explainable Artificial Intelligence: Applications with SHAP and LIME
İlhan Uysal, Utku Köse · 2024
The rise of complex cyber threats in recent years has prompted the creation of Network Intrusion Detection Systems (NIDS). Nevertheless, the traditional NIDS has issues in capturing sophisticated attacks because cyber-attacks are so dynamic. In this study, it is investigated the utility of using Explainable Artificial Intelligence (XAI) methods in the context of Machine Learning models for improved transparency and effectiveness in NIDS. The performance was benchmarked for models like XGBoost, Random Forest, Support Vector Machine using SHapley Additive exPlanations (SHAP) and Local Interpretable Model-agnostic Explanations (LIME). The CICIDS2017 dataset, which includes various types of attacks such as DoS/DDoS, Port Scanning, and Brute Force, was balanced and subjected to comprehensive preprocessing and feature engineering steps. Results confirm that with 100% across the board accuracy, precision, recall and F1 scores for all classes stacking model shows superior performance. XAI methods provide crucial insights into the model’s decision-making process, highlighting features such as Destination Port and Packet Length as key factors. This transparency is critical for cyber security professionals to understand better about threats and how to deal with them. The results demonstrate the feasibility of NIDS achieving both high accuracy and explainability, imparting more trustworthy networking information systems.