通过多粒度离散化提升攻击识别的可解释性与精度
Multi-Granular Discretization for Interpretable Generalization in Precise Cyberattack Identification
- 用多粒度高斯离散化处理连续特征,增强模型对细微模式的捕捉能力
- 在UKM-IDS20上精度提升≥4个百分点,召回率保持≈1.0
- 无需调参即可跨数据集通用,适合需要透明决策的网络安全场景
可解释入侵检测系统(IDS)对关键网络至关重要,但多数‘XAI’方案仅在黑箱分类器上附加近似解释器,导致分析结果不完整甚至误导。此前提出的可解释泛化(IG)机制通过学习良性与恶意流量的独特特征组合,生成可审计规则,已在NSL-KDD、UNSW-NB15和UKM-IDS20上实现优异的精确率、召回率和AUC,即使仅用10%数据训练也表现良好。为进一步提升精度而不牺牲透明性,本文提出多粒度离散化(IG-MD),将每个连续特征以多个基于高斯分布的分辨率表示。在UKM-IDS20上,IG-MD在全部九组训练测试划分中,精度提升≥4个百分点,同时保持召回率≈1.0,证明单一可解释模型可在无需定制调优的情况下跨域扩展。
原文摘要 · Abstract (English)
Explainable intrusion detection systems (IDS) are now recognized as essential for mission-critical networks, yet most "XAI" pipelines still bolt an approximate explainer onto an opaque classifier, leaving analysts with partial and sometimes misleading insights. The Interpretable Generalization (IG) mechanism, published in IEEE Transactions on Information Forensics and Security, eliminates that bottleneck by learning coherent patterns - feature combinations unique to benign or malicious traffic - and turning them into fully auditable rules. IG already delivers outstanding precision, recall, and AUC on NSL-KDD, UNSW-NB15, and UKM-IDS20, even when trained on only 10% of the data. To raise precision further without sacrificing transparency, we introduce Multi-Granular Discretization (IG-MD), which represents every continuous feature at several Gaussian-based resolutions. On UKM-IDS20, IG-MD lifts precision by greater than or equal to 4 percentage points across all nine train-test splits while preserving recall approximately equal to 1.0, demonstrating that a single interpretation-ready model can scale across domains without bespoke tuning.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。