eXplainable Artificial Intelligence for Transparent Optimization of Deep Learning-Based Intrusion Detection Systems.

Saved in:
Bibliographic Details
Title: eXplainable Artificial Intelligence for Transparent Optimization of Deep Learning-Based Intrusion Detection Systems.
Authors: Komarchesqui, Mateus1 (AUTHOR) mateus.komarchesqui@uel.br, Silva Ruffo, Vitor Gabriel da2 (AUTHOR) vitor.ruffo19cc@uel.br, Carvalho, Luiz Fernando3 (AUTHOR) luizfcarvalho@utfpr.edu.br, Proença Jr., Mario Lemes1 (AUTHOR) proenca@uel.br
Source: Journal of Network & Systems Management. Jul2026, Vol. 34 Issue 3, p1-37. 37p.
Abstract: The expansion of network boundaries and the rise of hybrid work environments have significantly widened the modern attack surface. Traditional rule-based monitoring struggles to scale, leading to the adoption of automated Artificial Intelligence for IT Operations powered by Deep Learning. However, while these models handle higher data volumes, their black-box nature lacks accountability, which prevents network managers from confidently triaging alarms without risking legitimate traffic disruption. While eXplainable AI techniques like SHapley Additive exPlanations are increasingly employed for regulatory compliance, research often fails to go beyond explicability and to leverage XAI insights to mitigate bias or enhance performance. This paper proposes a transparent conceptual model for the cyclical explanation and optimization of black-box Intrusion Detection Systems, along with a novel, unsupervised, cluster-based undersampling strategy. By leveraging SHAP to create an explainable pipeline and final product, we optimized an existing GAN-based IDS across two benchmark datasets. For the CIC-DDoS2019 dataset, we achieved a 4.7% increase in the Matthews Correlation Coefficient and a 26% reduction in missed attacks. On the CSE-CIC-IDS2018 dataset, the system showed a 21.3% improvement in MCC, reducing missed attacks by 92.32% and false alarms by 3.82%. [ABSTRACT FROM AUTHOR]
Copyright of Journal of Network & Systems Management is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Engineering Source
Description
Abstract:The expansion of network boundaries and the rise of hybrid work environments have significantly widened the modern attack surface. Traditional rule-based monitoring struggles to scale, leading to the adoption of automated Artificial Intelligence for IT Operations powered by Deep Learning. However, while these models handle higher data volumes, their black-box nature lacks accountability, which prevents network managers from confidently triaging alarms without risking legitimate traffic disruption. While eXplainable AI techniques like SHapley Additive exPlanations are increasingly employed for regulatory compliance, research often fails to go beyond explicability and to leverage XAI insights to mitigate bias or enhance performance. This paper proposes a transparent conceptual model for the cyclical explanation and optimization of black-box Intrusion Detection Systems, along with a novel, unsupervised, cluster-based undersampling strategy. By leveraging SHAP to create an explainable pipeline and final product, we optimized an existing GAN-based IDS across two benchmark datasets. For the CIC-DDoS2019 dataset, we achieved a 4.7% increase in the Matthews Correlation Coefficient and a 26% reduction in missed attacks. On the CSE-CIC-IDS2018 dataset, the system showed a 21.3% improvement in MCC, reducing missed attacks by 92.32% and false alarms by 3.82%. [ABSTRACT FROM AUTHOR]
ISSN:10647570
DOI:10.1007/s10922-026-10084-z