The Dynamic Explainable Framework (DEF), which couples a machine-learning detection backbone with inference-time SHAP and LIME explanations and an explanation-aware alert prioritization layer, is proposed and designed and profiled for real-time operation on benchmark traffic traces.
Abstract
Security Operation Center (SOC) analysts face 50–100 security alerts per hour, leading to cognitive fatigue and delayed incident response. Existing intrusion detection systems (IDS) suffer from high false-positive rates and opaque black-box architectures that erode analyst trust and slow triage decisions. This paper proposes the
Dynamic Explainable Framework
(DEF), which couples a machine-learning detection backbone with inference-time SHAP and LIME explanations and an explanation-aware alert prioritization layer. DEF is evaluated on two benchmarks under an identical protocol: a stratified 60,900-flow subset of CICIoT2023 (eight classes) and a deduplicated 60,889-flow subset of UNSW-NB15 (ten classes). The XGBoost detection backbone attains
94.05 ± 0.08%
accuracy with
88.49 ± 0.13%
macro F1 at a
1.29%
false-positive rate on CICIoT2023, and
88.26 ± 0.07%
accuracy with
68.22 ± 0.22%
macro F1 at a
1.25%
false-positive rate on UNSW-NB15; false-positive rate and AUC-ROC therefore transfer essentially unchanged across domains (0.99 and 0.98). Measured against the alerts the detector actually generates (true plus false positives, 2,849 on CICIoT2023 and 2,912 on UNSW-NB15) rather than against all inspected flows, the prioritization layer removes roughly half of the residual false positives at the operating point (91 of 184 on CICIoT2023) while raising macro precision by 2.8 points, at a bounded cost in recall. The residual recall cost concentrates on stealthy, low-signature attack classes, and a per-class threshold analysis bounds the safe operating range. SHAP explanations are generated at
1.6 ms
per alert (fidelity
$$\rho = 0.79$$
against permutation importance) and LIME at
144.4 ms
(top-10 feature stability 0.62), with a combined detection-plus-attribution latency of
3.17 ms
per alert and a sustained throughput of
315 alerts per second
on commodity CPU hardware. Transformer-based temporal and graph-based topology-context modules were additionally implemented and evaluated; their fusion does not surpass the tabular backbone on either benchmark, a negative result that we report and analyze. Comparing the two datasets isolates its cause: roughly
half
(51%) of the fusion’s shortfall on CICIoT2023 is attributable to that benchmark’s omission of per-flow host and timestamp identifiers, which forces proxy sequence and graph construction. The framework is designed and profiled for real-time operation on benchmark traffic traces; validation in a live SOC deployment remains future work.
The method, ECCOLA, is presented, which aims at making the high-level AI ethics principles more practical, making it possible for developers to more easily implement them in practice.
Ville Vakkuri, Kai-Kristian Kemell, P. Abrahamsson· EUROMICRO Conference on Soft...· 64 citations· ⚡6
The goal is to not only refine the accuracy of the LLM-based tool but also to underscore its potential in streamlining the software development lifecycle through proactive code improvement and education.
Z. Rasheed, Malik Abdul Sami, Muhammad Waseem et al.· arXiv.org· 62 citations· ⚡3
The use of large language models to automatically improve the user story quality in Austrian Post Group IT agile teams is explored, with a reference model for an Autonomous LLM-based Agent System developed and implemented at the company.
Zheying Zhang, M. Rayhan, Tomas Herda et al.· International Conference on...· 48 citations· ⚡4
This paper introduces a novel multi-AI-agent system designed to fully automate SLRs, and demonstrates how it substantially reduces the time and effort traditionally required for SLRs while maintaining comprehensiveness and precision.
Abdul Malik Sami, Z. Rasheed, Kai-Kristian Kemell et al.· arXiv.org· 44 citations· ⚡2
The proposed LLM-based multi-agent system automates qualitative data analysis process, creating opportunities for researchers and practitioners, and future improvements focus on enhancing multilingual performance and integrating continuous expert feedback.
Z. Rasheed, Muhammad Waseem, Aakash Ahmad et al.· arXiv.org· 41 citations
Exploring how generative AI could make machine vision more accessible to businesses. The post GenEye in a Box: Making Machine Vision Something You Can Just Ask For appeared first on GPT-Lab.
MIT News · Artificial Intelligence· news.mit.eduOct 8, 2026
Training AI agents with reinforcement learning can be challenging because their tools, context, and decision-making are managed by complex frameworks. Agent Lightning connects existing agents to RL training, making it easier to improve them without rebuilding them. The post Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses appeared first on Microsoft Research.
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.