arXiv:2608.13575cs.HCcs.AI2026-08中稿 · publication

通过可视化全局激活图,帮助专家发现网络流量分类中的隐藏模式。

Interactive Analysis of Global Explanations using Aggregated Class Activation Maps for Network Data

  • 基于多样本聚合激活图生成全局解释,揭示同一类别内的差异模式。
  • 支持专家交互式探索,识别误导性特征并提炼新规则。
  • 适合网络安全与机器学习交叉领域的研究人员和工程师使用。

近年来,深度学习在计算机网络流量分类等应用中表现出色。然而,单一预测类别内常存在差异模式,这给模型解释带来挑战,亟需工具来检测和分析这些模式。同时,提取类别描述规则对网络流量分析和入侵检测至关重要,尤其在下一代防火墙中。本文提出一种视觉交互系统,用于解释网络流量的类别预测。通过多个样本的全局解释,可帮助理解模型决策。可视化全局解释使专家能识别不同模式,获得更全面的特征概览。我们构建了原型系统,支持专家交互式探索与优化全局解释,发现并细化特定应用的新模式。这些解释有助于识别误导性特征,并制定新的网络管理规则。该方法还为机器学习专家提供新洞察,如类别分离或合并的可能性,以及提升深度学习模型准确性与可靠性。系统经机器学习与网络分析专家评估验证。

原文摘要 · Abstract (English)

Recent machine learning (ML) advances have demonstrated that deep learning (DL) achieves impressive results in different application domains, including the classification of computer network traffic to corresponding applications. However, the data frequently contains diverging patterns within a single predicted class. This presents a significant challenge to the ability to provide a clear and comprehensive explanation and emphasizes the necessity for tools capable of detecting and analyzing these patterns. Furthermore, the capacity to extract descriptive rules for classes is a crucial requirement in network traffic analysis and intrusion detection, particularly when leveraging advanced tools like next-generation firewalls. We provide a visual-interactive system that explains predictions of classes for network traffic. Global explanations derived from multiple samples of a given class contribute to understanding model predictions. Visualization of global explanations enables recognition of different patterns that offer experts a more comprehensive overview of its characteristics. We introduce a prototype that facilitates visual exploration and refinement of global explanations, enabling network experts to detect and refine new patterns for specific applications. These explanations support the identification of misleading features and the formulation of new rules for the management of networks. Our approach also aims at enabling ML experts to acquire new insights, including the possibility of separating or merging classes and the development of more accurate and reliable DL models. Our proposed prototype was evaluated by experts in machine learning and network analysis.

网络分析模型解释可视化

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。