对比统计与逻辑方法在5G入侵检测中特征归因的效果
Feature Attribution in 5G Intrusion Detection: A Statistical vs. Logic-Based Comparison
- 用SHAP(统计)和VoTE-XAI(逻辑)对比特征归因方法
- 逻辑方法更简洁稳定,且未遗漏统计方法的高重要特征
- 逻辑方法效率更高,适合高维5G实时监控场景
随着5G网络在关键应用中的普及,安全系统需从简单检测恶意行为转向提供可信赖的处置判断。理解机器学习模型的安全告警原因对实现可操作的响应至关重要。解释性人工智能(XAI)通过特征归因揭示输入对输出的影响,提升可信度。本文对比了统计型(如SHAP)与逻辑型(如VoTE-XAI)特征归因方法在三个5G相关数据集(5G-NIDD、MSA、PFCP)上的表现,覆盖多种攻击场景。评估指标包括:稀疏性(解释简洁度)、稳定性(同类型攻击间一致性)和效率(生成速度)。结果显示,逻辑方法在稀疏性和稳定性上持续优于统计方法;两者所选特征存在显著差异,但SHAP的前几名特征均被VoTE-XAI包含。此外,逻辑方法在478维特征环境下仍具备实时处理能力。
原文摘要 · Abstract (English)
With the rise of fifth-generation (5G) networks in critical applications, it is urgent to move from detection of malicious activity to systems capable of providing a reliable verdict suitable for mitigation. In this regard, understanding and interpreting machine learning (ML) models' security alerts is crucial for enabling actionable incident response orchestration. Explainable Artificial Intelligence (XAI) techniques are expected to enhance trust by providing insights into why alerts are raised. Under the umbrella of XAI, interpretability of outcomes is crucially dependent on understanding the influence of specific inputs, referred to as feature attribution. {A dominant approach to feature attribution statistically associates feature sets that can be correlated to a given alert. This paper investigates its merits against the backdrop of criticism from recent literature, in comparison with feature attribution based on logic. We extensively study two methods, SHAP and VoTE-XAI, as representatives of each feature attribution approach by analyzing their interpretations of alerts generated by an XGBoost model across three 5G-relevant datasets (5G-NIDD, MSA, and PFCP) covering multiple attack scenarios. We identify three metrics for assessing explanations: sparsity, how concise they are; stability, how consistent they are across samples from the same attack type; and efficiency, how fast an explanation is generated. Our results reveal that logic-based attributions are consistently more sparse and stable across alerts. More importantly, we found a significant divergence between features selected by SHAP and VoTE-XAI. However, none of the top-ranked features selected by SHAP were missed by VoTE-XAI. Finally, we analyze the efficiency of both methods, discussing their suitability for real-time security monitoring even in high-dimensional 5G environments (478 features).
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。