对比三种白盒可解释AI方法在网络安全检测中的表现
A Comparative Analysis of DNN-based White-Box Explainable AI Methods in Network Security
- 采用LRP、IG、DeepLift等白盒解释技术评估神经网络模型
- 白盒方法在鲁棒性和完整性上表现更优,适合安全分析场景
- 开源代码供研究者复用,支持端到端评估框架
针对网络入侵检测系统(NIDS)中日益复杂的黑箱人工智能模型,本文评估了三种白盒可解释AI方法(LRP、IG、DeepLift)在三大主流数据集(NSL-KDD、CICIDS-2017、RoEduNet-SIMARGL2021)上的表现。通过端到端框架,从全局与局部层面分析六项指标:描述准确性、稀疏性、稳定性、鲁棒性、效率与完整性。结果表明,白盒方法在鲁棒性与完整性方面显著优于黑盒方法,对安全分析师更具实用价值。研究提供的源代码已开源,便于社区改进与复用。
原文摘要 · Abstract (English)
New research focuses on creating artificial intelligence (AI) solutions for network intrusion detection systems (NIDS), drawing its inspiration from the ever-growing number of intrusions on networked systems, increasing its complexity and intelligibility. Hence, the use of explainable AI (XAI) techniques in real-world intrusion detection systems comes from the requirement to comprehend and elucidate black-box AI models to security analysts. In an effort to meet such requirements, this paper focuses on applying and evaluating White-Box XAI techniques (particularly LRP, IG, and DeepLift) for NIDS via an end-to-end framework for neural network models, using three widely used network intrusion datasets (NSL-KDD, CICIDS-2017, and RoEduNet-SIMARGL2021), assessing its global and local scopes, and examining six distinct assessment measures (descriptive accuracy, sparsity, stability, robustness, efficiency, and completeness). We also compare the performance of white-box XAI methods with black-box XAI methods. The results show that using White-box XAI techniques scores high in robustness and completeness, which are crucial metrics for IDS. Moreover, the source codes for the programs developed for our XAI evaluation framework are available to be improved and used by the research community.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。