Toward Transparent Intrusion Detection Systems: An Explainable Ai Approach For Network Security
DOI:
https://doi.org/10.70715/jitcai.2026.v3.i4.079Keywords:
Intrusion Detection Systems,, Explainable Artificial Intelligence, Network Security, Logistic Regression, Model Interpretability, Machine Learning SecurityAbstract
The growth in use of machine-learning based intrusion detection systems (IDS), however, also raises critical issues of transparency, trust, and accountability due to the fact that most of the top performing models are "black box" models. Lack of ability to provide explanation of detection decisions severely limits the operability of IDSs in critical security areas and reduces the confidence analysts have in their decision making processes. Therefore, the objective of this research was to determine if excellent intrusion detection performance could be obtained without loss of interpretability. For that purpose, this paper proposes an inherent explanatory IDS framework. The method used logistic regression as a classification model and evaluated its performance on the entire UNSW-NB15 dataset using flow-based statistics as input to logistic regression. This paper treated the proposed IDS as a two-class problem identifying both normal and attack flows and evaluated it using a variety of comprehensive performance metrics such as accuracy, precision, recall, F1 score, confusion matrices, and Receiver Operating Characteristic Area Under Curve (ROC-AUC). The experimental results demonstrated that the explanatory model had an average accuracy of 87.5%, an AUC value of .9697, and therefore good discriminant ability. Further, the experiments provided evidence that the model's good performance did not depend significantly on the balance between classes, but instead had high precision for attacks and performed consistently over several views.
Downloads
References
[1] Ahmad, Z., Shahid Khan, A., Shiang, C. W., Abdullah, J., & Ahmad, F. (2021). Network intrusion detection system: A systematic study of machine learning and deep learning approaches. Transactions on Emerging Telecommunications Technologies, 32(1), e4150. https://doi.org/10.1002/ett.4150 DOI: https://doi.org/10.1002/ett.4150
[2] Aljawarneh, S., Aldwairi, M., & Yassein, M. B. (2020). Anomaly-based intrusion detection system through feature selection analysis and building hybrid efficient model. Journal of Computational Science, 45, 101221. https://doi.org/10.1016/j.jocs.2020.101221 DOI: https://doi.org/10.1016/j.jocs.2020.101221
[3] Alshamrani, A., Myneni, S., Chowdhary, A., & Huang, D. (2021). A survey on advanced persistent threats: Techniques, solutions, challenges, and research opportunities. IEEE Communications Surveys & Tutorials, 23(2), 804–840. https://doi.org/10.1109/COMST.2020.3043028
[4] Axelsson, S. (2000). Intrusion detection systems: A survey and taxonomy. Proceedings of the IEEE Computer Security Foundations Workshop. https://doi.org/10.1109/CSFW.2000.856938 DOI: https://doi.org/10.1109/CSFW.2000.856938
[5] Buczak, A. L., & Guven, E. (2020). A survey of data mining and machine learning methods for cyber security intrusion detection. IEEE Communications Surveys & Tutorials, 22(2), 1153–1176. https://doi.org/10.1109/COMST.2019.2966627 DOI: https://doi.org/10.1109/COMST.2015.2494502
[6] Das, A., & Rad, P. (2022). Opportunities and challenges in explainable artificial intelligence (XAI): A survey. IEEE Access, 10, 75456–75469. https://doi.org/10.1109/ACCESS.2022.3183110 DOI: https://doi.org/10.1109/ACCESS.2022.3204171
[7] Doshi-Velez, F., & Kim, B. (2017). Towards a rigorous science of interpretable machine learning. arXiv preprint arXiv:1702.08608. https://doi.org/10.48550/arXiv.1702.08608
[8] Ferrag, M. A., Maglaras, L., Moschoyiannis, S., & Janicke, H. (2020). Deep learning for cyber security intrusion detection: Approaches, datasets, and comparative study. Journal of Information Security and Applications, 50, 102419. https://doi.org/10.1016/j.jisa.2019.102419 DOI: https://doi.org/10.1016/j.jisa.2019.102419
[9] Guidotti, R., Monreale, A., Ruggieri, S., Turini, F., Giannotti, F., & Pedreschi, D. (2020). A survey of methods for explaining black box models. ACM Computing Surveys, 51(5), 1–42. https://doi.org/10.1145/3236009 DOI: https://doi.org/10.1145/3236009
[10] Hindy, H., Brosset, D., Bayne, E., Seeam, A., Tachtatzis, C., Atkinson, R., & Bellekens, X. (2020). A taxonomy of network threats and the effect of current datasets on intrusion detection systems. IEEE Access, 8, 104650–104675. https://doi.org/10.1109/ACCESS.2020.2999161 DOI: https://doi.org/10.1109/ACCESS.2020.3000179
[11] Huang, C., Xiong, N., Yang, L., & Luo, J. (2020). A lightweight intrusion detection system based on explainable machine learning. IEEE Access, 8, 192641–192654. https://doi.org/10.1109/ACCESS.2020.3032796 DOI: https://doi.org/10.1109/ACCESS.2020.2988359
[12] Kim, G., Lee, S., & Kim, S. (2021). A novel hybrid intrusion detection method integrating anomaly detection with misuse detection. Expert Systems with Applications, 168, 114360. https://doi.org/10.1016/j.eswa.2020.114360 DOI: https://doi.org/10.1016/j.eswa.2020.114360
[13] Kumar, S., & Lim, T. (2023). Explainable artificial intelligence in cybersecurity: A systematic review. Computers & Security, 124, 102975. https://doi.org/10.1016/j.cose.2022.102975 DOI: https://doi.org/10.1016/j.cose.2022.102975
[14] Liao, Q. V., Gruen, D., & Miller, S. (2021). Questioning the AI: Informing design practices for explainable AI user experiences. Proceedings of the ACM on Human-Computer Interaction, 4(CSCW3), 1–28. https://doi.org/10.1145/3434179 DOI: https://doi.org/10.1145/3313831.3376590
[15] Linardatos, P., Papastefanopoulos, V., & Kotsiantis, S. (2021). Explainable AI: A review of machine learning interpretability methods. Entropy, 23(1), 18. https://doi.org/10.3390/e23010018 DOI: https://doi.org/10.3390/e23010018
[16] Moustafa, N., & Slay, J. (2015). UNSW-NB15: A comprehensive data set for network intrusion detection systems. Proceedings of the Military Communications and Information Systems Conference (MilCIS). https://doi.org/10.1109/MilCIS.2015.7348942 DOI: https://doi.org/10.1109/MilCIS.2015.7348942
[17] Ribeiro, M. T., Singh, S., & Guestrin, C. (2016). “Why should I trust you?” Explaining the predictions of any classifier. Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, 1135–1144. https://doi.org/10.1145/2939672.2939778 DOI: https://doi.org/10.1145/2939672.2939778
[18] Ring, M., Wunderlich, S., Grüdl, D., Landes, D., & Hotho, A. (2019). A survey of network-based intrusion detection data sets. Computers & Security, 86, 147–167. https://doi.org/10.1016/j.cose.2019.06.005 DOI: https://doi.org/10.1016/j.cose.2019.06.005
[19] Ring, M., Wunderlich, S., Scheuring, D., Landes, D., & Hotho, A. (2020). Flow-based benchmark data sets for intrusion detection. European Symposium on Research in Computer Security (ESORICS). https://doi.org/10.1007/978-3-030-58951-6_16 DOI: https://doi.org/10.1007/978-3-030-58951-6_16
[20] Rudin, C. (2019). Stop explaining black box machine learning models for high stakes decisions and use interpretable models instead. Nature Machine Intelligence, 1(5), 206–215. https://doi.org/10.1038/s42256-019-0048-x DOI: https://doi.org/10.1038/s42256-019-0048-x
[21] Rudin, C., Chen, C., Chen, Z., Huang, H., Semenova, L., & Zhong, C. (2022). Interpretable machine learning: Fundamental principles and 10 grand challenges. Statistics Surveys, 16, 1–85. https://doi.org/10.1214/21-SS133 DOI: https://doi.org/10.1214/21-SS133
[22] Sarhan, M., Layeghy, S., Portmann, M., & He, S. (2019). Towards a standard feature set for network intrusion detection system datasets. Computers & Security, 82, 221–251. https://doi.org/10.1016/j.cose.2019.01.013 DOI: https://doi.org/10.1016/j.cose.2019.01.013
[23] Sarhan, M., Layeghy, S., Portmann, M., & He, S. (2021). Feature analysis for effective intrusion detection systems. Computers & Security, 110, 102433. https://doi.org/10.1016/j.cose.2021.102433 DOI: https://doi.org/10.1016/j.cose.2021.102433
[24] Sharafaldin, I., Lashkari, A. H., & Ghorbani, A. A. (2021). Toward generating a new intrusion detection dataset and intrusion traffic characterization. Proceedings of the International Conference on Information Systems Security and Privacy (ICISSP). https://doi.org/10.5220/0006639801080116 DOI: https://doi.org/10.5220/0006639801080116
[25] Sommer, R., & Paxson, V. (2010). Outside the closed world: On using machine learning for network intrusion detection. IEEE Symposium on Security and Privacy, 305–316. https://doi.org/10.1109/SP.2010.25 DOI: https://doi.org/10.1109/SP.2010.25
[26] Tang, T. A., Mhamdi, L., McLernon, D., Zaidi, S. A. R., & Ghogho, M. (2020). Deep learning approach for network intrusion detection in software defined networking. IEEE Transactions on Network and Service Management, 17(2), 1181–1195. https://doi.org/10.1109/TNSM.2020.2976659
[27] Verkerken, M., D’hooge, L., Wauters, T., Volckaert, B., & De Turck, F. (2022). Towards model-agnostic explainability in intrusion detection systems. IEEE Access, 10, 24757–24769. https://doi.org/10.1109/ACCESS.2022.3154412
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Clinton Amponsah, Bernard Kyiewu, Andrew Oppong-Asante, Maclean Nimoh Antwi (Author)

This work is licensed under a Creative Commons Attribution 4.0 International License.








