arXiv:2507.17161cs.LGcs.AI2025-07被引 1

用扩散模型生成可操作的网络入侵解释,让防御更高效。

Tabular Diffusion based Actionable Counterfactual Explanations for Network Intrusion Detection

  • 基于扩散模型生成最小且多样化的反事实解释
  • 生成时间更短,3个数据集上表现优于现有方法
  • 可提炼为全局防御规则,适合安全团队部署

现代网络入侵检测系统(NIDS)广泛采用复杂深度学习模型,但其“黑箱”特性阻碍了对检测决策的理解与信任,也延迟了应对措施。本文提出一种基于扩散模型的反事实解释框架,可生成可转化为实际防御策略的解释。在3个主流网络入侵数据集上评估表明,该方法比现有算法生成更少、更多样、更快速的解释。进一步将解释归纳为全局规则,可有效过滤攻击流量,提升检测与防御效率。这是首个在入侵检测场景下对反事实解释方法的综合对比研究。

原文摘要 · Abstract (English)

Modern network intrusion detection systems (NIDS) frequently utilize the predictive power of complex deep learning models. However, the "black-box" nature of such deep learning methods adds a layer of opaqueness that hinders the proper understanding of detection decisions, trust in the decisions and prevent timely countermeasures against such attacks. Explainable AI (XAI) methods provide a solution to this problem by providing insights into the causes of the predictions. The majority of the existing XAI methods provide explanations which are not convenient to convert into actionable countermeasures. In this work, we propose a novel diffusion-based counterfactual explanation framework that can provide actionable explanations for network intrusion attacks. We evaluated our proposed algorithm against several other publicly available counterfactual explanation algorithms on 3 modern network intrusion datasets. To the best of our knowledge, this work also presents the first comparative analysis of existing counterfactual explanation algorithms within the context of network intrusion detection systems. Our proposed method provide minimal, diverse counterfactual explanations out of the tested counterfactual explanation algorithms in a more efficient manner by reducing the time to generate explanations. We also demonstrate how counterfactual explanations can provide actionable explanations by summarizing them to create a set of global rules. These rules are actionable not only at instance level but also at the global level for intrusion attacks. These global counterfactual rules show the ability to effectively filter out incoming attack queries which is crucial for efficient intrusion detection and defense mechanisms.

反事实解释网络入侵扩散模型可操作性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。