Explainable Anomaly-Based Intrusion Detection for Specialized IoT Environments Enabled by Rule Extraction From Autoencoder
Mingrui Fan, Jinxin Zuo, Jiangwen Zhu, Yueming Lu · IEEE Internet of Things Journal · 2025
Due to the difficulty in predefining novel attack patterns and the scarcity of sufficient malicious training samples in specialized Internet of Things (IoT) scenarios, the focus of IoT intrusion detection researchers has shifted toward anomaly-based techniques like Autoencoder. These techniques detect attacks based on the degree of deviation and rely minimally on malicious samples. However, current machine learning (ML) and deep learning (DL) implementations lack explainability. Although some methods provide post-hoc interpretations, they are limited and partial, failing to reflect the entire decision-making process. To address this challenge, we investigate an explainable anomaly-based intrusion detection system (IDS) that translates the inference process of the Autoencoder into the high-fidelity allow-list rule library, thereby balancing the detection capability and interpretability. First, we assume that benign traffic follows a complex global distribution composed of several irrelevant local distributions. The clustering algorithm is performed in an extended feature space consisting of reconstruction loss and embeddings to decompose local distributions. Then, we deploy an approach based on Gradient Ascent to explore the boundary rules of each local distribution. The allow-list rule library that reflects Autoencoder’s inference process can be constructed by merging these boundary rules. Comprehensive evaluation experiments demonstrate that the extracted allow-list rule library accurately reproduces Autoencoder’s inference process and effectively detects IoT intrusions.