Multi-Granular Discretization for Interpretable Generalization in Precise Cyberattack Identification

📅 2025-07-16
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
Existing interpretable intrusion detection systems (IDS) commonly rely on post-hoc approximators coupled with black-box classifiers, resulting in non-auditable rules, incomplete feature representation, and potential misinterpretation. To address this, we propose an end-to-end interpretable IDS framework: first, a multi-granularity Gaussian discretization method models continuous features in a human-readable, semantically meaningful manner; second, leveraging Interpretable Generalization, the framework directly learns auditable logical rules that distinguish benign from malicious traffic without approximation. The method achieves high accuracy and full transparency—even under extremely low training sample regimes—eliminating reliance on post-hoc surrogate models. Evaluated across nine distinct splits of the UKM-IDS20 dataset, it attains an average precision gain of ≥4 percentage points over state-of-the-art interpretable baselines, while maintaining near-perfect recall (≈1.0). These results demonstrate superior few-shot generalization capability and cross-dataset robustness.

Technology Category

Machine Learning: Transparent, Interpretable, Explainable MLKnowledge Representation and Reasoning: Diagnosis and Abductive ReasoningData Mining & Knowledge Management: Anomaly/Outlier Detection

Application Category

Semantics and Knowledge: Data modeling to support human-machine intelligence, including LLMs agents, intelligent system behavior, explanations, and user-friendly interactionsUser Modeling, Personalization and Recommendation: Explainable and interpretable methods for personalizationWeb Mining and Content Analysis: Robustness and generalizability of Web mining methods
📝 Abstract
Explainable intrusion detection systems (IDS) are now recognized as essential for mission-critical networks, yet most "XAI" pipelines still bolt an approximate explainer onto an opaque classifier, leaving analysts with partial and sometimes misleading insights. The Interpretable Generalization (IG) mechanism, published in IEEE Transactions on Information Forensics and Security, eliminates that bottleneck by learning coherent patterns - feature combinations unique to benign or malicious traffic - and turning them into fully auditable rules. IG already delivers outstanding precision, recall, and AUC on NSL-KDD, UNSW-NB15, and UKM-IDS20, even when trained on only 10% of the data. To raise precision further without sacrificing transparency, we introduce Multi-Granular Discretization (IG-MD), which represents every continuous feature at several Gaussian-based resolutions. On UKM-IDS20, IG-MD lifts precision by greater than or equal to 4 percentage points across all nine train-test splits while preserving recall approximately equal to 1.0, demonstrating that a single interpretation-ready model can scale across domains without bespoke tuning.
Problem

Research questions and friction points this paper is trying to address.

Enhances precision in cyberattack identification without losing interpretability
Improves explainable intrusion detection systems with coherent pattern learning
Introduces multi-granular discretization for better feature resolution in IDS
Innovation

Methods, ideas, or system contributions that make the work stand out.

Multi-Granular Discretization for feature resolution
Interpretable Generalization for auditable rule creation
Gaussian-based resolutions for continuous features
W
Wen-Cheng Chung
Bachelor Program of Artificial Intelligence, National Yunlin University of Science and Technology
S
Shu-Ting Huang
Bachelor Program of Big Data Applications in Business, National Pingtung University
Hao-Ting Pai
Hao-Ting Pai
National Pingtung University
AI's BiasDisparityand InterpretabilityMisdiagnosisCybersecurity