用XGBoost与SHAP构建可解释的入侵检测系统,提升关键基础设施网络安全治理可信度。
Explainable AI-Driven Cyber Risk Analytics and Model Reliability Assessment for Intelligent Governance of U.S. Critical Infrastructure: An XGBoost and SHAP-Based Intrusion Detection Framework
- 基于XGBoost与SHAP构建可解释的入侵检测模型
- 在CICIDS2017数据集上达到98.7%准确率和0.96 F1分数
- 适合关注网络安全可信决策的政府与企业安全团队
美国关键基础设施领域日益普及智能数字技术,使系统面临高级网络威胁和运营漏洞。人工智能驱动的治理与自动化决策系统已成为能源、医疗、交通、金融及通信等领域的核心,以提升效率与战略管理能力。当前分布式拒绝服务攻击(DDoS)、僵尸网络、勒索软件及高级持续性威胁(APT)等新型攻击对基础设施韧性、网络安全可靠性与治理可信度构成重大挑战。传统安全机制在动态网络环境中难以适应变化需求。本研究基于CICIDS2017数据集,开发一套具备韧性的网络风险分析与模型可靠性评估框架,用于支持美国关键基础设施的智能治理与决策支持。采用XGBoost、随机森林与决策树等分类器进行网络恶意行为检测与风险等级判定,并引入可解释人工智能(XAI)技术增强安全决策的透明性与可信度。通过准确率、精确率、召回率、F1分数、ROC-AUC及误报率等指标评估模型性能,验证其可靠性和鲁棒性。
原文摘要 · Abstract (English)
The increasing penetrations of the critical infrastructure sector in the United States with intelligent digital technologies have greatly increased exposure to advanced cyber adversaries and operational vulnerabilities. AI-powered governance and automated decision-making systems are becoming a key part of the operation of critical infrastructure systems, including energy, healthcare, transportation, financial services, and communication infrastructure, in order to improve efficiency and strategic management. The growing cyber threat environment, such as Distributed Denial of Service (DDos) attacks, botnets, ransomware, and Advanced Persistent Threats (APTs) pose significant challenges to infrastructure resilience, cyber security reliability, and governance trustworthiness. In a changing attack landscape and dynamic network environment, traditional cybersecurity mechanisms can often fall short of meeting the evolving needs and protecting critical systems. This study will develop a resilient cyber risk analytics and model reliability assessment framework to support intelligent governance and decision support for cyber risk exposure in the U.S. critical infrastructure environment. This study is based on the CICIDS2017 dataset for the development and testing of intrusion detection system models and cyber risk prediction models based on machine learning. Various classifiers like XGBoost, Random Forest, and Decision Tree are used to detect malicious activities on the network and determine the level of cyber risk. Furthermore, the Explainable Artificial Intelligence (XAI) techniques are integrated to enhance transparency, interpretability, and trust in cybersecurity decision-making processes. The proposed framework presents the reliability and resilience of the model by having various performance measures such as accuracy, precision, recall, F1 score, ROC-AUC, and false positive rate.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。