inklap

Advancing Cybersecurity Practice: Explainable Machine Learning for Network Intrusion Detection

Adam Grabowski, Shengjie Xu · Journal of Cybersecurity Education, Research and Practice · 2025

This research investigates explainable artificial intelligence (XAI) integration within machine learning (ML)-based intrusion detection systems (IDS), focusing on distinguishing malicious from benign network activities. We employed Random Forest and XGBoost models evaluated on widely recognized datasets, including NSL-KDD and UNSW-NB15, using both binary and multi-class classification tasks. The objective was to enhance cybersecurity operations through improved model transparency and interpretability. By integrating SHAP (SHapley Additive exPlanations) and LIME (Local Interpretable Model-Agnostic Explanations), the study offers comprehensive global and local insights into model decision-making processes. Results demonstrate SHAP's effectiveness in providing a broad, dataset-wide understanding of feature interactions and importance, while LIME facilitates targeted analysis of specific misclassified instances, thereby identifying potential biases. This dual approach advances the state-of-the-art by enabling security analysts to effectively interpret AI-driven decisions, reduce false positives, and refine response strategies. The integration of XAI into IDS frameworks significantly im

📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً