🤖 AI Summary
To address the prevalent black-box nature of machine learning–based intrusion detection systems (IDS), this paper proposes an explainable AI framework integrating LIME (Local Interpretable Model-agnostic Explanations), ELI5 (Explain Like I’m 5), and decision trees—marking the first synergistic application of local instance-level explanations and global feature importance analysis in the IDS domain. Evaluated on the UNSW-NB15 dataset, the framework balances model transparency with detection performance, achieving 85% attack classification accuracy while identifying and ranking the top-10 most influential features for each attack class. The core contribution lies in a lightweight, production-ready hybrid interpretability paradigm that enhances both trustworthiness and operational utility of AI models in cybersecurity applications.
📝 Abstract
Recent developments in Artificial Intelligence (AI) and their applications in critical industries such as healthcare, fin-tech and cybersecurity have led to a surge in research in explainability in AI. Innovative research methods are being explored to extract meaningful insight from blackbox AI systems to make the decision-making technology transparent and interpretable. Explainability becomes all the more critical when AI is used in decision making in domains like fintech, healthcare and safety critical systems such as cybersecurity and autonomous vehicles. However, there is still ambiguity lingering on the reliable evaluations for the users and nature of transparency in the explanations provided for the decisions made by black-boxed AI. To solve the blackbox nature of Machine Learning based Intrusion Detection Systems, a framework is proposed in this paper to give an explanation for IDSs decision making. This framework uses Local Interpretable Model-Agnostic Explanations (LIME) coupled with Explain Like I'm five (ELI5) and Decision Tree algorithms to provide local and global explanations and improve the interpretation of IDSs. The local explanations provide the justification for the decision made on a specific input. Whereas, the global explanations provides the list of significant features and their relationship with attack traffic. In addition, this framework brings transparency in the field of ML driven IDS that might be highly significant for wide scale adoption of eXplainable AI in cyber-critical systems. Our framework is able to achieve 85 percent accuracy in classifying attack behaviour on UNSW-NB15 dataset, while at the same time displaying the feature significance ranking of the top 10 features used in the classification.