Jul 2026· Scriptora International Journal of Research and Innovation (SIJRI)· 0 citations· 18 references
TL;DR
The results showed that embedding explainability in an IDS enhances the human-AI partnership, allowing security analysts to confirm the results of their IDS, mitigate false-positive ambiguity, optimize incident response, and meet regulatory and ethical obligations.
Abstract
The sophistication of cyber threats is growing, and there is a growing need for timely detection and response to security threats, which is now possible with the help of artificial intelligence (AI) based Intrusion Detection System (IDS). While the accuracy of detection has increased with the implementation of more sophisticated machine learning and deep learning models, those models tend to be opaque and complicated, making it difficult for cybersecurity professionals to understand, verify and believe automated predictions. The study explores how XAI can enhance the understanding and accuracy of artificial intelligence (AI) intrusion detection systems (IDSs). The study is carried out using the qualitative method which examines the application of the existing techniques of XAI such as feature attribution, local or global explanation models, visualization techniques and rule based interpretations for explaining the techniques and gaining enhanced confidence of the analyst and informed security decisions. The secondary data used in this research was obtained from scholarly articles, cybersecurity frameworks, industry reports, and case studies to identify real-world applications, problems in implementation, as well as the current trends of the explainable AI for cyber defense. The results showed that embedding explainability in an IDS enhances the human-AI partnership, allowing security analysts to confirm the results of their IDS, mitigate false-positive ambiguity, optimize incident response, and meet regulatory and ethical obligations. Other challenges remain such as: maintaining the explainability attribute while obtaining the predictive performance, handling large traffic density, avoiding adversarial manipulation on the explanation mechanisms, and scalability. The study finds explainable AI to be an important milestone on the path towards trustworthy and responsible cybersecurity systems. By enabling organizations to make their security operations more resilient, boost the trust in automated cyber defense, and enhance transparency without compromising detection, XAI can help organizations achieve these goals. The study provides valuable insights for practitioners in the cybersecurity industry, AI developers, decision makers and organizations developing intrusion detection systems that are transparent, reliable and ethically responsible in the dynamic digital landscape.
The results show that XAI can improve the transparency, trustworthiness and effectiveness of AI-based cybersecurity systems, in addition to highlighting a range of privacy, adversarial robustness, scalability and evaluation challenges that warrant further research to ensure reliable deployment in the real world.
Raman Kumar· International Journal of Adv...· 0 citations
The growth in use of machine-learning based intrusion detection systems (IDS), however, also raises critical issues of transparency, trust, and accountability due to the fact that most of the top performing models are "black box" models. Lack of ability to provide explanation of detection decisions severely limits the operability of IDSs in critical security areas and reduces the confidence analysts have in their decision making processes. Therefore, the objective of this research was to determine if excellent intrusion detection performance could be obtained without loss of interpretability. For that purpose, this paper proposes an inherent explanatory IDS framework. The method used logistic regression as a classification model and evaluated its performance on the entire UNSW-NB15 dataset using flow-based statistics as input to logistic regression. This paper treated the proposed IDS as a two-class problem identifying both normal and attack flows and evaluated it using a variety of comprehensive performance metrics such as accuracy, precision, recall, F1 score, confusion matrices, and Receiver Operating Characteristic Area Under Curve (ROC-AUC). The experimental results demonstrated that the explanatory model had an average accuracy of 87.5%, an AUC value of .9697, and therefore good discriminant ability. Further, the experiments provided evidence that the model's good performance did not depend significantly on the balance between classes, but instead had high precision for attacks and performed consistently over several views.
Clinton Amponsah, B. Kyiewu, Andrew Oppong-Asante et al.· Journal of Information Techn...· 0 citations
A conceptual framework is proposed that combines detection, explanation, and orchestrated response in a continuous feedback loop that is suitable for zero trust and IoT-enabled critical-infrastructure environments that will allow for continuous retraining of the model.
Jayesh Dalmet· Journal of Digital Security...· 0 citations
This study presents an Explainable Artificial Intelligence (XAI)-based cyber threat detection framework that combines Long Short-Term Memory (LSTM) and Autoencoder models for accurate and transparent threat detection.
Indu Asitha, M. N.· International Journal of Com...· 0 citations
Cyberattacks are becoming more frequent and sophisticated in today’s digital world, rendering conventional security measures inadequate. In order to increase the accuracy of cyber threat detection, this study investigates the application of deeplearning methods to increase the accuracy of cyber threat detection. A cybersecurity dataset was used to test four classification models: Artificial Neural Networks (ANN), Random Forest, XGBoost, and Logistic Regression. The models were evaluated using the key 95.32. The performance of Artificial Neural Networks, Random Forest, XGBoost, and Logistic Regression was examined. These findings imply that learning-based and ensemble models are better at spotting intricate and changing attack patterns. In general, the study highlights the significance of clever, data-driven methods for creating cybersecurity defence systems that are quicker, more dependable, and more resilient.
D. Sharma, Inderdeep Kaur, Krishika Gupta et al.· International Conference on...· 0 citations
They originate from the rapid rise of cyber threats such as malware, phishing, ransomware,
denial of service, and unauthorised network intrusion, which have proven to be so difficult to
tackle that traditional security measures can hardly deal with the issue. Signature-based
intrusion detection system techniques in particular, which are commonly adopted by traditional
methods, usually lack the ability to detect novel and evolving attack vectors in addition to high
false positive rate and response time. In this regard, this paper proposes an AI threat detection
framework, employing data science methods to boost cybersecurity performances. The
researchers of this paper have tested the effectiveness of several models using a benchmark
dataset for cyber security, including CICIDS2017 or NSL-KDD and machine learning
techniques such as Random Forest, Support Vector Machine, Logistic Regression and
XGBoost for evaluating performance. Using measures of accuracy, precision, recall and F1-
score, the experiments show that the performance of ensemble learning models is higher than
shallow learning models in this research; XGBoost and Random Forest.
Praveen Kumar Reddy Gouni· International Journal of Soc...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.