用可解释性分析无人机入侵检测,揭示攻击伪装背后的真相。
XAI and Statistical Analysis for Reliable Intrusion Detection in the UAVIDS-2025 Dataset: From Tree to Hybrid and Tabular DNN Ensembles

- 结合树模型与深度网络,构建混合集成模型提升检测性能
- 通过SHAP和统计检验发现虫洞、黑洞攻击的误判根源
- 适合关注安全可解释性与对抗攻击分析的研究者
近年来,机制可解释性作为可解释人工智能(XAI)的重要分支,被用于解析无人机入侵检测系统(UAVIDS)中复杂机器学习模型的决策过程。本文采用最佳数据预处理方法,评估多种树集成、深度神经网络、混合堆叠模型及最新集成神经网络,在UAVIDS-2025数据集上进行分层10折交叉验证。最优模型XGBoost进一步结合SHAP值分析全局与局部特征重要性,识别各攻击如何模仿正常流量,并定位误分类区域。随后通过核密度估计(KDE)曲线与小提琴图对比,利用Westfall-Young置换检验、带宽优化与Jensen-Shannon散度进行多重比较,揭示了虫洞与黑洞攻击在密度支持交叠问题上的真实误判成因。研究提供了可靠、可解释的无人机入侵检测模型,并揭示了攻击隐藏本质的统计规律。
原文摘要 · Abstract (English)
During thDuring the last few years, the term Mechanistic Interpretability, a specific area, under the umbrella of explainable artificial intelligence (XAI), has been introduced, to explain the decisions made by complex machine learning (ML) models in critical systems like UAV intrusion detection systems (UAVIDS). In this paper, we apply best-practices for data pre-processing and examine a wide range of tree-ensembles, deep neural networks, hybrid stacking models and the latest ensemble neural networks to detect intrusions in UAV, with stratified 10-fold cross validation. With our top-performing model, XGBoost, we proceed to Shapley Additive explanations (SHAP), to analyze the global and local feature importances and understand which features, each attack targets, to mimic normal traffic and where the misclassifications occur. Furthermore a distribution analysis follows, by visually comparing violin plots and the curves of kernel density estimations. With the Westfall-Young permutation test for multiple comparisons, the Bandwidth optimization of the KDEs and the selection of Jensen-Shannon Distance for the test, we discover the true causes of false predictions, observed in Wormhole and Blackhole attacks in UAVIDS-2025. The findings provide robust, reliable and explainable models for UAV intrusion detection, along with statistical insights, which capture and clarify the masked nature of the attacks, regarding the challenge of Density Support Intersection, between these attacks, in this dataset.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。