用可解释方法分析物联网攻击行为,提升安全系统可信度。
Explainable Threat Attribution for IoT Networks Using Conditional SHAP and Flow Behavior Modelling
- 结合梯度提升与SHAP分析攻击特征驱动因素
- 在CICIoT2023数据集上区分8类攻击行为模式
- 适合关注可解释AI与物联网安全的开发者
随着物联网在关键基础设施、智能环境和消费设备中的持续扩展,其网络安全变得愈发重要。传统入侵检测模型常将物联网威胁视为二分类问题或依赖黑箱模型,限制了可信度。本文基于CICIoT2023数据集,研究物联网环境中多类别威胁归因,将30余种攻击变体归纳为8个语义明确的类别。采用梯度提升模型与SHAP(SHapley Additive exPlanations)相结合,实现全局及类别特异性解释,深入揭示各类攻击分类的关键特征。结果表明,模型通过流量时序、包大小一致性、TCP标志动态及统计方差等行为特征,有效区分不同攻击。进一步分析展示了每类攻击的特征归因与决策路径,验证了这些模式的有效性。研究为构建更精准、可解释的入侵检测系统提供了支持,弥合高性能机器学习与物联网安全中对信任与问责的需求之间的差距。
原文摘要 · Abstract (English)
As the Internet of Things (IoT) continues to expand across critical infrastructure, smart environments, and consumer devices, securing them against cyber threats has become increasingly vital. Traditional intrusion detection models often treat IoT threats as binary classification problems or rely on opaque models, thereby limiting trust. This work studies multiclass threat attribution in IoT environments using the CICIoT2023 dataset, grouping over 30 attack variants into 8 semantically meaningful classes. We utilize a combination of a gradient boosting model and SHAP (SHapley Additive exPlanations) to deliver both global and class-specific explanations, enabling detailed insight into the features driving each attack classification. The results show that the model distinguishes distinct behavioral signatures of the attacks using flow timing, packet size uniformity, TCP flag dynamics, and statistical variance. Additional analysis that exposes both feature attribution and the decision trajectory per class further validates these observed patterns. Our findings contribute to the development of more accurate and explainable intrusion detection systems, bridging the gap between high-performance machine learning and the need for trust and accountability in AI-driven cybersecurity for IoT environments.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。