Contact us
![]() |
customer@davidpublishing.com |
![]() |
3275638434 |
![]() |
![]() |
| Paper Publishing WeChat |
Useful Links
This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License
Article
Opening the Black Box: Explainable AI in Network Intrusion Detection
Author(s)
Sraboni Ghosh Joya, Nila Sultana
Full-Text PDF
XML 78 Views
DOI:10.17265/2328-2185/2026.03.004
Affiliation(s)
City University, Dhaka, Bangladesh
ABSTRACT
Intrusion Detection Systems
(IDSs) are very useful for stopping and finding bad things that happen on
networks. Machine learning (ML) and deep learning (DL) methods are useful for
increasing detection rates, but they often work like a “black box”, which makes
them hard to trust, understand, and follow. This study presents an Explainable Artificial Intelligence (XAI) pipeline
for Network Intrusion
Detection Systems (NIDSs),
incorporating traditional
models such as Logistic Regression (LR) and Random Forest (RF) alongside neural
models like Multilayer Perceptron (MLP). We employ post hoc explanation
methodologies, such as SHAPs (Shapley Additive Explanations), to augment the
transparency of these
models. We demonstrate that our model explanations yield insights into decision-making
and feature significance when utilizing synthetic data. We examine the
advantages and disadvantages of detection
performance and model interpretability. The MLP model works pretty well,
with an F1 score of about 0.86, and the explanations show how important features
affect the model. This work helps put explainable NIDS into practice
by pointing out possible problems
and future paths.
KEYWORDS
Network Intrusion Detection, Explainable Artificial Intelligence, SHAP, Random Forest, Multilayer Perceptron, model interpretability
Cite this paper
References




