xAAD in Practice: Explainable Anomaly Detection in Cybersecurity

Damir Kopljar, Vjekoslav Drvar, Jurica Babić, Vedran Podobnik · 2025

In this paper, we demonstrate the practical deployment of the Explainable Active Anomaly Discovery framework (xAAD) in a live cybersecurity setting, highlighting how its explainability and active feedback capabilities directly reduce false positives, streamline threat triage, and enhance the overall trust and efficiency of security operations centers (SOCs). By evaluating xAAD on the RoEduNetSIMARGL2021 dataset, we illustrate its immediate operational benefits and provide guidance for its integration into existing cybersecurity workflows. Our findings indicate that xAAD's explanations are both sparse-focusing on a minimal set of influential features-and robust to data perturbations, offering stability across dynamic network conditions. These qualities aid security analysts in making faster, more informed decisions, ultimately reducing investigation overhead. By bridging technical anomaly detection outputs with the operational needs of security operations centers, xAAD represents a valuable step toward practical, explainable anomaly detection solutions in high-stakes cybersecurity environments.

Read the paper · More papers on PaperTik