arXiv:2602.19087cs.CRcs.AI2026-02中稿 · publication in ICT…被引 1

融合可解释AI与数据采样,提升网络安全威胁检测的透明度与效率。

Detecting Cybersecurity Threats by Integrating Explainable AI with SHAP Interpretability and Strategic Data Sampling

  • 采用策略性采样保留类别分布,提升模型训练效率。
  • 自动防数据泄露,确保实验结果可靠。
  • 结合SHAP分析提供可操作的解释,适合安全分析师使用。

网络安全运营中对透明可信机器学习的迫切需求推动了本研究提出的集成可解释AI(XAI)框架。该方法解决三大核心挑战:通过策略性采样处理大规模数据集,在保持类别分布的同时实现高效模型开发;通过自动化数据泄露预防机制,系统识别并移除污染特征,保障实验严谨性;通过集成XAI实现模型无关的可解释性,采用SHAP分析为各类算法提供可操作的解释。在CIC-IDS2017数据集上的应用表明,该框架在维持检测效能的同时降低计算开销,并为安全分析师提供有意义的解释。研究证明,可解释性、计算效率与实验完整性可同时实现,为安全运营中心部署可信AI系统提供了坚实基础。

原文摘要 · Abstract (English)

The critical need for transparent and trustworthy machine learning in cybersecurity operations drives the development of this integrated Explainable AI (XAI) framework. Our methodology addresses three fundamental challenges in deploying AI for threat detection: handling massive datasets through Strategic Sampling Methodology that preserves class distributions while enabling efficient model development; ensuring experimental rigor via Automated Data Leakage Prevention that systematically identifies and removes contaminated features; and providing operational transparency through Integrated XAI Implementation using SHAP analysis for model-agnostic interpretability across algorithms. Applied to the CIC-IDS2017 dataset, our approach maintains detection efficacy while reducing computational overhead and delivering actionable explanations for security analysts. The framework demonstrates that explainability, computational efficiency, and experimental integrity can be simultaneously achieved, providing a robust foundation for deploying trustworthy AI systems in security operations centers where decision transparency is paramount.

可解释AI网络安全数据采样SHAP

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。