用可解释的高斯过程模型提升网络安全在线学习的可信度。
Inherently Interpretable and Uncertainty-Aware Models for Online Learning in Cyber-Security Problems
- 采用加性高斯过程,天然具备可解释性和不确定性感知能力。
- 在保持高可解释性的同时,显著提升了模型在安全场景下的可扩展性。
- 适合需要信任决策的网络安全分析人员使用。
本文针对高风险行业(尤其是网络安全)中在线学习对可解释性与不确定性感知的需求,提出一种新型在线监督学习框架。该框架利用加性高斯过程(AGPs)模型固有的可解释性与不确定性量化能力,兼顾预测性能与透明度,同时解决AGPs模型可扩展性差的核心问题。该方法有助于安全分析师更可靠地验证威胁检测、排查误报并做出可信决策。研究为可解释人工智能领域提供了一类适用于高风险决策任务的模型,具有实际应用价值。代码已开源。
原文摘要 · Abstract (English)
In this paper, we address the critical need for interpretable and uncertainty-aware machine learning models in the context of online learning for high-risk industries, particularly cyber-security. While deep learning and other complex models have demonstrated impressive predictive capabilities, their opacity and lack of uncertainty quantification present significant questions about their trustworthiness. We propose a novel pipeline for online supervised learning problems in cyber-security, that harnesses the inherent interpretability and uncertainty awareness of Additive Gaussian Processes (AGPs) models. Our approach aims to balance predictive performance with transparency while improving the scalability of AGPs, which represents their main drawback, potentially enabling security analysts to better validate threat detection, troubleshoot and reduce false positives, and generally make trustworthy, informed decisions. This work contributes to the growing field of interpretable AI by proposing a class of models that can be significantly beneficial for high-stake decision problems such as the ones typical of the cyber-security domain. The source code is available.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。