Your browser doesn't support javascript.
loading
Enhancing intrusion detection performance using explainable ensemble deep learning.
Ben Ncir, Chiheb Eddine; Ben HajKacem, Mohamed Aymen; Alattas, Mohammed.
Affiliation
  • Ben Ncir CE; MIS Department, College of Business, University of Jeddah, Jeddah, Jeddah, Saudi Arabia.
  • Ben HajKacem MA; LARODEC Lab, ISG Tunis, University of Tunis, Le Bardo, Tunis, Tunisia.
  • Alattas M; MIS Department, College of Business, University of Jeddah, Jeddah, Jeddah, Saudi Arabia.
PeerJ Comput Sci ; 10: e2289, 2024.
Article in En | MEDLINE | ID: mdl-39314740
ABSTRACT
Given the exponential growth of available data in large networks, the need for an accurate and explainable intrusion detection system has become of high necessity to effectively discover attacks in such networks. To deal with this challenge, we propose a two-phase Explainable Ensemble deep learning-based method (EED) for intrusion detection. In the first phase, a new ensemble intrusion detection model using three one-dimensional long short-term memory networks (LSTM) is designed for an accurate attack identification. The outputs of three classifiers are aggregated using a meta-learner algorithm resulting in refined and improved results. In the second phase, interpretability and explainability of EED outputs are enhanced by leveraging the capabilities of SHape Additive exPplanations (SHAP). Factors contributing to the identification and classification of attacks are highlighted which allows security experts to understand and interpret the attack behavior and then implement effective response strategies to improve the network security. Experiments conducted on real datasets have shown the effectiveness of EED compared to conventional intrusion detection methods in terms of both accuracy and explainability. The EED method exhibits high accuracy in accurately identifying and classifying attacks while providing transparency and interpretability.
Key words

Full text: 1 Collection: 01-internacional Database: MEDLINE Language: En Journal: PeerJ Comput Sci Year: 2024 Document type: Article Affiliation country: Saudi Arabia Country of publication: United States

Full text: 1 Collection: 01-internacional Database: MEDLINE Language: En Journal: PeerJ Comput Sci Year: 2024 Document type: Article Affiliation country: Saudi Arabia Country of publication: United States