Skip to content
Open access

TRACE: Feature-Space Feasible Action Contracts for Explainable Intrusion Triage

Jul 2026 · Electronics · 0 citations · 38 references

Abstract

Explainable intrusion detection systems often provide feature attributions without indicating whether a security action should be released, downgraded, or deferred. This paper investigates whether action-governed explanations can provide bounded triage evidence under traffic feature feasibility constraints. We present TRACE, a framework that maps calibrated detector outputs to a finite action ladder, constructs conformal action sets, selects actions via a utility-minimax rule, and releases high-severity actions only when compact support contracts remain stable under feasible perturbations, where feasibility is a property of the processed benchmark features and not of packet-level realizability. Ablations isolate the conformal set and release gate as the primary drivers of system behavior. Across 11 gated dataset–model pairs, TRACE produces non-degenerate action sets with zero full-set collapse and defer/block rates from 0.603 to 1.000. Under held-out sample split tuning, it achieves higher average proxy utility than unconditional release and release rate-matched random release on all 11 pairs. Against the strongest simple selective gate, however, it matches on 6 of 11 pairs and trails on the remaining 5. Robustness sweeps confirm positive all-row utility on all pairs, though pass-only utility becomes fragile in ultra-low-release regimes. Unlike display-only attribution summaries, the TRACE contract records the plausible action set, feasibility checks, stability summaries, and an explicit release rationale. The results support TRACE as a bounded evidentiary framework for action-governed XAI in IDS, rather than claiming superiority over all IDS/XAI methods or general deployment readiness.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.