arrow
返回

An Explainable Machine Learning Framework for Intrusion Detection Systems

delete2020-01-01
delete165
delete
OA
AI
M
Maonan Wang
K
Kangfeng Zheng *
杨
杨焱青 (Yanqing Yang)
王秀娟 封面图
王秀娟 (Xiujuan Wang)
DOI:10.1109/ACCESS.2020.2988359delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
In recent years, machine learning-based intrusion detection systems (IDSs) have proven to be effective; especially, deep neural networks improve the detection rates of intrusion detection models. However, as models become more and more complex, people can hardly get the explanations behind their decisions. At the same time, most of the works about model interpretation focuses on other fields like computer vision, natural language processing, and biology. This leads to the fact that in practical use, cybersecurity experts can hardly optimize their decisions according to the judgments of the model. To solve these issues, a framework is proposed in this paper to give an explanation for IDSs. This framework uses SHapley Additive exPlanations (SHAP), and combines local and global explanations to improve the interpretation of IDSs. The local explanations give the reasons why the model makes certain decisions on the specific input. The global explanations give the important features extracted from IDSs, present the relationships between the feature values and different types of attacks. At the same time, the interpretations between two different classifiers, one-vs-all classifier and multiclass classifier, are compared. NSL-KDD dataset is used to test the feasibility of the framework. The framework proposed in this paper leads to improve the transparency of any IDS, and helps the cybersecurity staff have a better understanding of IDSs & x2019; judgments. Furthermore, the different interpretations between different kinds of classifiers can also help security experts better design the structures of the IDSs. More importantly, this work is unique in the intrusion detection field, presenting the first use of the SHAP method to give explanations for IDSs.
Keyword:
Intrusion detection
Computational modeling
Predictive models
Machine learning
Biological system modeling
Feature extraction
Intrusion detection system
Shapley value
SHapley Additive exPlanations
model interpretation
machine learning
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

IEEE Access 封面图
IEEE Access
IF:
3.6
论文数:
9.8W
被引数:
29.4W

机构

B
beijing university of posts & telecommunications
学者数:
1.4W
论文数: 1.2W
被引数: 9
B
Beijing University of Technology
学者数:
2.8W
论文数: 2.1W
被引数: 2.7W
引用论文

引用论文

Explainable machine-learning predictions for the prevention of hypoxaemia during surgery
err2018-10-10
err1.1K
errOAAI
errLundberg, Scott M.; Nair, Bala; Vavilala, Monica S.; Horibe, Mayumi; Eisses, Michael J.; Adams, Trevor; Liston, David E.; Low, Daniel King-Wai; Newman, Shu-Fang; Kim, Jerry; Lee, Su-In
err分享
err收藏
err分享
err收藏
Uncoupled 6-core Fibers with a Standard 125-m Cladding, ITU-T G.652 Optical Properties, and Low XT
err2023-01-01
err0
PREAI
errKazunori Mukasa; Takeshi Takagi; Takaaki Shishikura; Katsuhisa Maruyma; Hajime Oshio; Aditi Mehta; Karsten Rottwitt; Toshio Morioka
err分享
err收藏
Deep Learning Approach for Intelligent Intrusion Detection System面向智能入侵检测系统的深度学习方法
err2019-01-01
err868
errOAAI
errVinayakumar, R.; Alazab, Mamoun; Soman, K. P.; Poornachandran, Prabaharan; Al-Nemrat, Ameer; Venkatraman, Sitalakshmi
err分享
err收藏
err分享
err收藏
err分享
err收藏
学者 查看更多内容