arXiv:2509.20391cs.CRcs.LG2025-09被引 9

用集成学习+可解释AI,实现无人机网络多类攻击的高精度检测。

A Comparative Analysis of Ensemble-Based Machine Learning Approaches with Explainable AI for Multi-Class Intrusion Detection in Drone Networks

  • 对比五种集成模型,随机森林在九类攻击上表现最佳。
  • 最高达0.9998的宏平均F1分数,AUC接近1.0。
  • 结合SHAP/LIME分析特征重要性,提升决策可信度。

无人机在民用、商业和国防领域的广泛应用带来显著网络安全挑战,尤其是针对通信协议的网络入侵风险上升。由于无人机流量动态性强且存在欺骗、注入、重放、中间人(MITM)等多种复杂攻击向量,入侵检测与分类极具挑战。本文提出一个面向无人机网络的鲁棒且可解释的入侵检测框架,聚焦多类别分类与模型可解释性。比较了随机森林、极端梯度提升(Extra Trees)、AdaBoost、CatBoost和XGBoost五种集成学习模型,在包含正常流量及九类入侵的标注数据集上进行训练与评估。通过缺失值填补、归一化和类别编码等预处理后,采用宏平均F1分数、ROC AUC、马修斯相关系数和对数损失等指标全面评估性能。结果表明,随机森林表现最优,宏平均F1得分为0.9998,ROC AUC为1.0000。通过弗里德曼检验、威尔科克森符号秩检验(带霍姆校正)及自助置信区间验证结果的统计显著性。进一步融合可解释AI方法SHAP与LIME,实现全局与局部特征重要性分析,增强模型透明度与决策可信度。该方法不仅达到近乎完美的准确率,更具备可解释性,适用于实时且高安全要求的无人机运行场景。

原文摘要 · Abstract (English)

The growing integration of drones into civilian, commercial, and defense sectors introduces significant cybersecurity concerns, particularly with the increased risk of network-based intrusions targeting drone communication protocols. Detecting and classifying these intrusions is inherently challenging due to the dynamic nature of drone traffic and the presence of multiple sophisticated attack vectors such as spoofing, injection, replay, and man-in-the-middle (MITM) attacks. This research aims to develop a robust and interpretable intrusion detection framework tailored for drone networks, with a focus on handling multi-class classification and model explainability. We present a comparative analysis of ensemble-based machine learning models, namely Random Forest, Extra Trees, AdaBoost, CatBoost, and XGBoost, trained on a labeled dataset comprising benign traffic and nine distinct intrusion types. Comprehensive data preprocessing was performed, including missing value imputation, scaling, and categorical encoding, followed by model training and extensive evaluation using metrics such as macro F1-score, ROC AUC, Matthews Correlation Coefficient, and Log Loss. Random Forest achieved the highest performance with a macro F1-score of 0.9998 and ROC AUC of 1.0000. To validate the superiority of the models, statistical tests, including Friedmans test, the Wilcoxon signed-rank test with Holm correction, and bootstrapped confidence intervals, were applied. Furthermore, explainable AI methods, SHAP and LIME, were integrated to interpret both global and local feature importance, enhancing model transparency and decision trustworthiness. The proposed approach not only delivers near-perfect accuracy but also ensures interpretability, making it highly suitable for real-time and safety-critical drone operations.

入侵检测集成学习可解释AI无人机安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。