arXiv:2602.13271cs.AIcs.HC2026-02

用可解释AI提升网络安全检测,让模型决策透明可信。

Human-Centered Explainable AI for Security Enhancement: A Deep Intrusion Detection Framework

  • 融合CNN与LSTM捕捉流量时序特征,提升检测精度。
  • 模型准确率达0.99,LSTM在精确率、召回率上更优。
  • 引入SHAP解释机制,帮助安全人员理解关键风险特征。

随着网络威胁日益复杂频繁,入侵检测系统(IDS)不仅需要高准确性,还需具备可解释性。本文提出一种集成可解释人工智能(XAI)的新型深度学习框架,通过结合卷积神经网络(CNN)和长短期记忆网络(LSTM)捕获流量序列的时序依赖关系,在基准数据集NSL-KDD上验证了其优越性能。实验结果显示,CNN与LSTM的准确率均达0.99,其中LSTM在宏平均精确率、召回率及F-1分数上表现更佳,加权平均指标则相近。为保障可解释性,引入SHAP方法,揭示了srv_serror_rate、dst_host_srv_serror_rate和serror_rate等关键特征对决策的影响。通过基于IPIP6与大五人格特质的专家信任调查,评估系统可靠性与可用性。研究证明了性能与透明性结合在网络安全中的潜力,并建议未来通过自适应学习实现实时威胁检测。

原文摘要 · Abstract (English)

The increasing complexity and frequency of cyber-threats demand intrusion detection systems (IDS) that are not only accurate but also interpretable. This paper presented a novel IDS framework that integrated Explainable Artificial Intelligence (XAI) to enhance transparency in deep learning models. The framework was evaluated experimentally using the benchmark dataset NSL-KDD, demonstrating superior performance compared to traditional IDS and black-box deep learning models. The proposed approach combined Convolutional Neural Network (CNN) and Long Short-Term Memory (LSTM) networks for capturing temporal dependencies in traffic sequences. Our deep learning results showed that both CNN and LSTM reached 0.99 for accuracy, whereas LSTM outperformed CNN at macro average precision, recall, and F-1 score. For weighted average precision, recall, and F-1 score, both models scored almost similarly. To ensure interpretability, the XAI model SHapley Additive exPlanations (SHAP) was incorporated, enabling security analysts to understand and validate model decisions. Some notable influential features were srv_serror_rate, dst_host_srv_serror_rate, and serror_rate for both models, as pointed out by SHAP. We also conducted a trust-focused expert survey based on IPIP6 and Big Five personality traits via an interactive UI to evaluate the system's reliability and usability. This work highlighted the potential of combining performance and transparency in cybersecurity solutions and recommends future enhancements through adaptive learning for real-time threat detection.

入侵检测可解释AI深度学习网络安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。