用可解释AI选出关键网络入侵特征,提升检测效果与安全性
XAI-based Feature Selection for Improved Network Intrusion Detection Systems
- 结合XAI方法识别重要网络特征,改进入侵检测
- 新方法使多种主流模型检测性能显著提升
- 为安全分析师提供决策依据,适合网络安全研究者
可解释性与AI模型评估是现代网络入侵检测系统(IDS)安全的关键环节,但目前仍不足。特征选择在此过程中至关重要,能识别出最关键的特征,从而提升攻击检测能力并增强对攻击行为的描述。本文提出基于可解释AI(XAI)的新特征选择方法,结合不同AI模型生成的关键属性,设计了五种新型特征筛选策略。通过与多种前沿特征选择方法对比,验证了所提方法在多数情况下能显著提升模型性能。本研究不仅提供了新颖的特征选择技术,还为多个基于XAI的策略奠定了基础,帮助安全分析人员更好地理解人工智能在入侵检测中的决策逻辑。此外,论文公开了源代码,支持社区在此框架上构建更优模型。
原文摘要 · Abstract (English)
Explainability and evaluation of AI models are crucial parts of the security of modern intrusion detection systems (IDS) in the network security field, yet they are lacking. Accordingly, feature selection is essential for such parts in IDS because it identifies the most paramount features, enhancing attack detection and its description. In this work, we tackle the feature selection problem for IDS by suggesting new ways of applying eXplainable AI (XAI) methods for this problem. We identify the crucial attributes originated by distinct AI methods in tandem with the novel five attribute selection methods. We then compare many state-of-the-art feature selection strategies with our XAI-based feature selection methods, showing that most AI models perform better when using the XAI-based approach proposed in this work. By providing novel feature selection techniques and establishing the foundation for several XAI-based strategies, this research aids security analysts in the AI decision-making reasoning of IDS by providing them with a better grasp of critical intrusion traits. Furthermore, we make the source codes available so that the community may develop additional models on top of our foundational XAI-based feature selection framework.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。