A New Method to Detect Man-in-the-Middle Attack using Explainable Artificial Intelligence
Taha Aljadir, Iván García‐Magariño, Raquel Lacuesta, Jaime Lloret · 2025
Man in the Middle Attack (MitM) attacks are a severe threat due to their stealth, as well as their ability to impact networks. The impact of such AI-driven detection systems on cybersecurity is to enhance trust and allow for the better mitigation of threats, because explainable artificial intelligence (XAI) can assist it in making these systems transparent and trustworthy. This synergy solves both the operational requirement for clear-cut security implementations and the technical challenge of high-level threats. This work uses XAI methodologies to enhance the detection and analysis of MitM attacks in Intrusion Detection Systems (IDS). We propose an innovative approach that integrates the XGBoost classifier with SHAP (SHapley Additive exPlanations) to improve detection accuracy and deliver interpretable model outputs. Through analyzing critical network traffic characteristics, our methodology achieves a detection accuracy of 0.99998 and a recall of 0.99999. The findings illustrate the efficacy of XAI in enhancing cybersecurity protocols while highlighting the need for further exploration to augment datasets and examine other XAI techniques. This study contributes to existing literature on explainable intrusion detection by providing an in-depth analysis of feature significance and model decision processes. The XAI explanations of this approach have been positively evaluated according to feature importance analysis, explanation stability, sensitivity analysis and explanation conciseness.