Transparent Threat Detection Using SHAP and LIME to build an Explainable Intrusion Detection System

Vinayak Naik, Dharaneesh Kuruba, R Gowtham, V Monish, Deepthi Vs · Journal of Emerging Technologies and Innovative Research · 2025

The increasing rate of cyber threats requires the high level of accuracy in Intrusion Detection Systems (IDS). Nevertheless, the contemporary ML-driven IDS can be considered rather opaque black boxes that can be highly accurate but lose interpretability and credibility. This is a highly important impediment to quick decision-making in Security Operations Centres (SOCs), which is caused by the related fatigue in alerts. The present project reviews most recent works on Explainable Intrusion Detection Systems (XAI-IDS) that combine LIME (Local Interpretable Model-agnostic Explanations) and SHAP (SHapley Additive exPlanations). The purpose of this is to build a high performance IDS framework relying on such models as XGBoost based on benchmark IDS datasets (e.g., CIC-IDS2017, UNSWNB15). We have shown that XAI can contribute substantially to the levels of analyst trust and that approaches based on XGBoost and SHAP give the best trade-offs between interpretability and accuracy. The proposed methodology is devoted to the effective XAI integration that will produce human-readable explanations of the predictions used in the IDS and will be checked with the help of the visualization and performance metrics to assure actionable results that will be offered to SOC analysts.

Read the paper · More papers on PaperTik