From Attacks to Insights: XAI and Defense in Network Security
Bharathi Ganesh Kumar, E. Shanthini · 2024
Network intrusion poses significant threats to cyber security, as malicious attacks can disrupt systems and compromise sensitive information. Real-world scenarios include unauthorized access to corporate networks, data breaches exposing sensitive customer information, and Distributed Denial of Service (DDoS) attacks that can impair critical infrastructure. This paper addresses these challenges using the UNSW-NB15 dataset, a comprehensive collection of real-world network traffic data. This dataset was chosen for its diversity in capturing contemporary cyber threats, making it ideal for evaluating model performance in detecting intrusions. While numerous classification models exist for this task, the Multi-Layer Perceptron (MLP) classifier is selected due to its ability to capture complex patterns and provide higher accuracy in non-linear datasets. To enhance the interpretability of the model, Explainable AI (XAI) techniques are employed, including SHAP, LIME, and permutation feature importance, which offer insights into model decisions by explaining feature contributions. However, adversarial machine learning introduces an additional layer of threat by exploiting model vulnerabilities. This paper focuses on the Zeroth Order Optimization (ZOO) attack, a black-box method that only requires access to the model's predictions, without needing knowledge of the architecture or gradients, to demonstrate how adversarial examples can drastically reduce model accuracy and compromise network security. Upon generating adversarial examples, a significant drop in accuracy is observed, identifying the features most susceptible to manipulation. Then XAI methods are applied again to analyze the features that contribute most to the misclassification, allowing us to understand the underlying vulnerabilities. Based on these insights, adversarial training is implemented as a defense mechanism, successfully restoring model accuracy and strengthening resilience against attacks. The results underline the importance of combining XAI with robust defenses to build secure, interpretable machine learning models for intrusion detection.