MARATTO

review · Frontiers in Artificial Intelligence

A systematic review on the integration of explainable artificial intelligence in intrusion detection systems to enhancing transparency and interpretability in cybersecurity

202540 citationsOpen accessSol Plaatje University

In plain language

Intrusion detection systems protect networks against sophisticated cyber threats by identifying breaches in real time. Many systems employ complex machine learning models that deliver high accuracy but function as opaque black boxes, preventing security analysts from understanding why specific alerts or decisions are made. Integrating explainable artificial intelligence addresses this challenge by improving transparency, interpretability, and trust in automated security systems. An analysis of current literature shows that rule-based and tree-based approaches are frequently favoured because they are readily interpretable, though balancing interpretability against detection accuracy remains difficult. Significant challenges also persist around scalability, real-time explanation generation, and the absence of standardised evaluation metrics. To overcome these limitations, future advancements require hybrid models, specialised metrics, and ethical frameworks designed specifically to support transparent and secure network defence operations.

Key takeaways

  • Explainable artificial intelligence enhances trust and transparency in intrusion detection systems by clarifying automated decision-making processes.
  • Rule-based and tree-based explainability models are commonly preferred for interpretability, though trade-offs with detection accuracy persist.
  • Critical gaps remain in scalability and standardisation, highlighting the need for hybrid models capable of delivering real-time explanations.
  • Future progress depends on tailored explainability techniques, standardised evaluation metrics, and ethical frameworks prioritising security.

Why it matters

Cybersecurity tools increasingly rely on complex artificial intelligence to stop attacks, but opaque automated decisions can leave analysts unable to verify or act on critical alerts. Providing clear, interpretable explanations helps human defenders trust automated alerts, diagnose errors, and respond effectively to emerging threats, ensuring that advanced protection does not come at the cost of operational visibility and human oversight.

Commercialisation angle

The work relates to enterprise cybersecurity operations and security operations centres, where analysts must interpret automated intrusion alerts in real time. Because the findings stem from a systematic review highlighting major unresolved gaps in scalability, real-time deployment, and standardised metrics, practical adoption remains at an early to intermediate stage. Hybrid models and robust real-time explanation frameworks must be developed and validated before widespread deployment in commercial intrusion detection platforms can occur.

AI-generated from the published abstract. Always read the original work before citing.

Abstract

The rise of sophisticated cyber threats has spurred advancements in Intrusion Detection Systems (IDS), which are crucial for identifying and mitigating security breaches in real-time. Traditional IDS often rely on complex machine learning algorithms that lack transparency despite their high accuracy, creating a "black box" effect that can hinder the analysts' understanding of their decision-making processes. Explainable Artificial Intelligence (XAI) offers a promising solution by providing interpretability and transparency, enabling security professionals to understand better, trust, and optimize IDS models. This paper presents a systematic review of the integration of XAI in IDS, focusing on enhancing transparency and interpretability in cybersecurity. Through a comprehensive analysis of recent studies, this review identifies commonly used XAI techniques, evaluates their effectiveness within IDS frameworks, and examines their benefits and limitations. Findings indicate that rule-based and tree-based XAI models are preferred for their interpretability, though trade-offs with detection accuracy remain challenging. Furthermore, the review highlights critical gaps in standardization and scalability, emphasizing the need for hybrid models and real-time explainability. The paper concludes with recommendations for future research directions, suggesting improvements in XAI techniques tailored for IDS, standardized evaluation metrics, and ethical frameworks prioritizing security and transparency. This review aims to inform researchers and practitioners about current trends and future opportunities in leveraging XAI to enhance IDS effectiveness, fostering a more transparent and resilient cybersecurity landscape.

Research topics

  • Explainable Artificial Intelligence (XAI)
  • Adversarial Robustness in Machine Learning
  • Anomaly Detection Techniques and Applications

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.3389/frai.2025.1526221

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.