MARATTO

article · International Journal of Information Security and Privacy

Machine Learning and Explainable Artificial Intelligence for Network Intrusion Detection

Abstract

The growing sophistication of cyber threats demands adaptive security mechanisms beyond traditional Intrusion Detection Systems (IDS). This paper explores integrating Machine Learning (ML) and Explainable Artificial Intelligence (XAI) to enhance Network Intrusion Detection Systems (NIDS). Using the CICIDS2017 dataset, the authors evaluate ML models including Convolutional Neural Networks (CNN), Random Forest, and XGBoost, balancing detection performance with interpretability. Results show XGBoost achieves the highest accuracy with minimal misclassifications, underscoring its robustness for intrusion detection. To address the black-box challenge of deep learning, SHapley Additive exPlanations (SHAP) is applied to interpret predictions. Key features such as Destination Port, Flow Duration, and Packet Length emerged as critical, improving trust, reducing false positives, and aiding investigation. The authors highlight the necessity of coupling high-performing ML with XAI frameworks for transparency. Finally, challenges in scalability, robustness, and dataset generalizability are discussed.

Research topics

  • Network Security and Intrusion Detection
  • Explainable Artificial Intelligence (XAI)
  • Adversarial Robustness in Machine Learning

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.4018/ijisp.402900

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.