Skip to content
#explainable ai Open access

A dynamic explainable AI framework for real-time intrusion detection and automated alert prioritization in security operation centers

Sep 2026 · Scientific Reports · 0 citations
Network Security and Intrusion Detection

TL;DR

The Dynamic Explainable Framework (DEF), which couples a machine-learning detection backbone with inference-time SHAP and LIME explanations and an explanation-aware alert prioritization layer, is proposed and designed and profiled for real-time operation on benchmark traffic traces.

Abstract

Security Operation Center (SOC) analysts face 50–100 security alerts per hour, leading to cognitive fatigue and delayed incident response. Existing intrusion detection systems (IDS) suffer from high false-positive rates and opaque black-box architectures that erode analyst trust and slow triage decisions. This paper proposes the Dynamic Explainable Framework (DEF), which couples a machine-learning detection backbone with inference-time SHAP and LIME explanations and an explanation-aware alert prioritization layer. DEF is evaluated on two benchmarks under an identical protocol: a stratified 60,900-flow subset of CICIoT2023 (eight classes) and a deduplicated 60,889-flow subset of UNSW-NB15 (ten classes). The XGBoost detection backbone attains 94.05 ± 0.08% accuracy with 88.49 ± 0.13% macro F1 at a 1.29% false-positive rate on CICIoT2023, and 88.26 ± 0.07% accuracy with 68.22 ± 0.22% macro F1 at a 1.25% false-positive rate on UNSW-NB15; false-positive rate and AUC-ROC therefore transfer essentially unchanged across domains (0.99 and 0.98). Measured against the alerts the detector actually generates (true plus false positives, 2,849 on CICIoT2023 and 2,912 on UNSW-NB15) rather than against all inspected flows, the prioritization layer removes roughly half of the residual false positives at the operating point (91 of 184 on CICIoT2023) while raising macro precision by 2.8 points, at a bounded cost in recall. The residual recall cost concentrates on stealthy, low-signature attack classes, and a per-class threshold analysis bounds the safe operating range. SHAP explanations are generated at 1.6 ms per alert (fidelity $$\rho = 0.79$$ against permutation importance) and LIME at 144.4 ms (top-10 feature stability 0.62), with a combined detection-plus-attribution latency of 3.17 ms per alert and a sustained throughput of 315 alerts per second on commodity CPU hardware. Transformer-based temporal and graph-based topology-context modules were additionally implemented and evaluated; their fusion does not surpass the tabular backbone on either benchmark, a negative result that we report and analyze. Comparing the two datasets isolates its cause: roughly half (51%) of the fusion’s shortfall on CICIoT2023 is attributable to that benchmark’s omission of per-flow host and timestamp identifiers, which forces proxy sequence and graph construction. The framework is designed and profiled for real-time operation on benchmark traffic traces; validation in a live SOC deployment remains future work.

Read PDF

Similar papers

#artificial intelligence Conference Open access Apr 2020

ECCOLA - a Method for Implementing Ethically Aligned AI Systems

The method, ECCOLA, is presented, which aims at making the high-level AI ethics principles more practical, making it possible for developers to more easily implement them in practice.

Ville Vakkuri, Kai-Kristian Kemell, P. Abrahamsson · 64 citations · ⚡6
#computer vision Review Apr 2024

AI-powered Code Review with LLMs: Early Results

The goal is to not only refine the accuracy of the LLM-based tool but also to underscore its potential in streamlining the software development lifecycle through proactive code improvement and education.

Z. Rasheed, Malik Abdul Sami, Muhammad Waseem et al. · 62 citations · ⚡3
#computer vision Open access Mar 2024

LLM-based agents for automating the enhancement of user story quality: An early report

The use of large language models to automatically improve the user story quality in Austrian Post Group IT agile teams is explored, with a reference model for an Autonomous LLM-based Agent System developed and implemented at the company.

Zheying Zhang, M. Rayhan, Tomas Herda et al. · 48 citations · ⚡4
#computer vision Review Mar 2024

System for systematic literature review using multiple AI agents: Concept and an empirical evaluation

This paper introduces a novel multi-AI-agent system designed to fully automate SLRs, and demonstrates how it substantially reduces the time and effort traditionally required for SLRs while maintaining comprehensiveness and precision.

Abdul Malik Sami, Z. Rasheed, Kai-Kristian Kemell et al. · 44 citations · ⚡2
#computer vision Feb 2024

Can Large Language Models Serve as Data Analysts? A Multi-Agent Assisted Approach for Qualitative Data Analysis

The proposed LLM-based multi-agent system automates qualitative data analysis process, creating opportunities for researchers and practitioners, and future improvements focus on enhancing multilingual performance and integrating continuous expert feedback.

Z. Rasheed, Muhammad Waseem, Aakash Ahmad et al. · 41 citations
#artificial intelligence Conference Open access Jun 2018

The Key Concepts of Ethics of Artificial Intelligence

It is suggested that the focus on finding keywords is the first step in guiding and providing direction for future research in the AI ethics field.

Ville Vakkuri, P. Abrahamsson · 39 citations · ⚡2

Related blog posts

Microsoft Research Blog Oct 7, 2026

Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses

Training AI agents with reinforcement learning can be challenging because their tools, context, and decision-making are managed by complex frameworks. Agent Lightning connects existing agents to RL training, making it easier to improve them without rebuilding them. The post Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses appeared first on Microsoft Research.

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.