用优化决策树实现高精度可解释的物联网异常检测,适合边缘设备部署。
An Optimized Decision Tree-Based Framework for Explainable IoT Anomaly Detection
- 基于优化决策树结合SHAP与灵敏度分析,实现局部与全局特征解释。
- 测试准确率达99.91%,F1-score为99.51%,跨验证平均准确率98.93%。
- 计算开销小,适合资源受限的物联网设备实时检测。
随着物联网(IoT)设备数量激增,网络攻击面显著扩大,亟需在资源受限环境下具备清晰解释能力的强入侵检测系统(IDS)。然而,现有物联网IDS常在检测质量、模型可解释性与计算效率间权衡,难以部署于边缘设备。本文提出一种基于优化决策树的可解释人工智能(XAI)框架,融合局部解释方法SHAP与全局敏感性分析Morris,量化特征重要性。实验显示,该系统在测试集上达到99.91%准确率、99.51% F1-score和0.9960 Cohen Kappa值,交叉验证平均准确率为98.93%,表现稳定。相较于集成模型,推理速度更快,计算开销更低。特征分析表明SrcMac为最关键预测因子。相比以往方法,本方案克服了无法部署于边缘设备的缺陷,支持实时处理,满足AI透明性要求,并对各类攻击均保持高检测率。高精度、强解释性与低计算成本的结合,使其在真实资源受限的物联网安全场景中具有实用价值。
原文摘要 · Abstract (English)
The increase in the number of Internet of Things (IoT) devices has tremendously increased the attack surface of cyber threats thus making a strong intrusion detection system (IDS) with a clear explanation of the process essential towards resource-constrained environments. Nevertheless, current IoT IDS systems are usually traded off with detection quality, model elucidability, and computational effectiveness, thus the deployment on IoT devices. The present paper counteracts these difficulties by suggesting an explainable AI (XAI) framework based on an optimized Decision Tree classifier with both local and global importance methods: SHAP values that estimate feature attribution using local explanations, and Morris sensitivity analysis that identifies the feature importance in a global view. The proposed system attains the state of art on the test performance with 99.91% accuracy, F1-score of 99.51% and Cohen Kappa of 0.9960 and high stability is confirmed by a cross validation mean accuracy of 98.93%. Efficiency is also enhanced in terms of computations to provide faster inferences compared to those that are generalized in ensemble models. SrcMac has shown as the most significant predictor in feature analyses according to SHAP and Morris methods. Compared to the previous work, our solution eliminates its major drawback lack because it allows us to apply it to edge devices and, therefore, achieve real-time processing, adhere to the new regulation of transparency in AI, and achieve high detection rates on attacks of dissimilar classes. This combination performance of high accuracy, explainability, and low computation make the framework useful and reliable as a resource-constrained IoT security problem in real environments.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。