Return
Machine Learning and Explainable Artificial Intelligence for Network Intrusion Detection
DOI:10.4018/IJISP.402900.png)
Abstract
En 中文
The growing sophistication of cyber threats demands adaptive security mechanisms beyond traditional Intrusion Detection Systems (IDS). This paper explores integrating Machine Learning (NIDS). Using the CICIDS2017 dataset, the authors evaluate ML models including Convolutional Neural Networks (CNN), Random Forest, and XGBoost, balancing detection performance with interpretability. Results show XGBoost achieves the highest accuracy with minimal misclassifications, underscoring its robustness for intrusion detection. To address the black-box challenge of deep learning, SHapley Additive exPlanations (SHAP) is applied to interpret predictions. Key features such as Destination Port, Flow Duration, and Packet Length emerged as critical, improving trust, reducing false positives, and aiding investigation. The authors highlight the necessity of coupling high-performing ML with XAI frameworks for transparency. Finally, challenges in scalability, robustness, and dataset generalizability are discussed.
Keywords:
Cybersecurity
SHAPAnalysis
Machine Learning
Network Traffic
Anomaly Detection
Artificial Intelligence
Explainable Artificial Intelligence
and Intrusion Detection
AI Summary
Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.
Journal
I
IF:
0.9
Papers:
6
Citations:
185

