Enhancing Explainability and Trustworthiness of Intrusion Detection Systems Using Competitive Learning
Jesse Ables, Thomas Kirby, William S. Anderson, Sudip Mittal, Shahram Rahimi, Ioana Banicescu, Maria A. Seale, Thomas Arnold, Joseph E. Jabour · 2024
Current AI-based Intrusion Detection Systems (IDS) primarily rely on untrustworthy black box methods. Traditionally, many of these black box IDS are built using Error Based Learning (EBL) algorithms such as neural networks. EBL algorithms can offer high accuracy but at the cost of explainability. White box algorithms, on the other hand, are far more explainable and trustworthy than black box EBL techniques. Our proposed solution is a white box Competitive Learning (CL) based explainable Intrusion Detection System (X-IDS), offering innate explainability. This architecture is built using DARPA’s guidelines for explainable systems. We analyze the statistical and visual explanations generated by the CL models and demonstrate a method for understanding the explanations. Using these explanations, users could potentially make changes to the architecture to improve security. Lastly, a performance analysis using traditional accuracy metrics is performed using the NSL-KDD and CIC-IDS-2017 datasets. While achieving slightly lower accuracies (1%-3% less than EBL models) on NSL- KDD and CIC-IDS-2017 datasets, CL models provide enhanced explainability and trustworthiness.