eXplainable Artificial Intelligence for Transparent Optimization of Deep Learning-Based Intrusion Detection Systems.

Saved in:
Bibliographic Details
Title: eXplainable Artificial Intelligence for Transparent Optimization of Deep Learning-Based Intrusion Detection Systems.
Authors: Komarchesqui, Mateus1 (AUTHOR) mateus.komarchesqui@uel.br, Silva Ruffo, Vitor Gabriel da2 (AUTHOR) vitor.ruffo19cc@uel.br, Carvalho, Luiz Fernando3 (AUTHOR) luizfcarvalho@utfpr.edu.br, Proença Jr., Mario Lemes1 (AUTHOR) proenca@uel.br
Source: Journal of Network & Systems Management. Jul2026, Vol. 34 Issue 3, p1-37. 37p.
Abstract: The expansion of network boundaries and the rise of hybrid work environments have significantly widened the modern attack surface. Traditional rule-based monitoring struggles to scale, leading to the adoption of automated Artificial Intelligence for IT Operations powered by Deep Learning. However, while these models handle higher data volumes, their black-box nature lacks accountability, which prevents network managers from confidently triaging alarms without risking legitimate traffic disruption. While eXplainable AI techniques like SHapley Additive exPlanations are increasingly employed for regulatory compliance, research often fails to go beyond explicability and to leverage XAI insights to mitigate bias or enhance performance. This paper proposes a transparent conceptual model for the cyclical explanation and optimization of black-box Intrusion Detection Systems, along with a novel, unsupervised, cluster-based undersampling strategy. By leveraging SHAP to create an explainable pipeline and final product, we optimized an existing GAN-based IDS across two benchmark datasets. For the CIC-DDoS2019 dataset, we achieved a 4.7% increase in the Matthews Correlation Coefficient and a 26% reduction in missed attacks. On the CSE-CIC-IDS2018 dataset, the system showed a 21.3% improvement in MCC, reducing missed attacks by 92.32% and false alarms by 3.82%. [ABSTRACT FROM AUTHOR]
Copyright of Journal of Network & Systems Management is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Engineering Source
FullText Text:
  Availability: 0
Header DbId: egs
DbLabel: Engineering Source
An: 193695367
AccessLevel: 6
PubType: Academic Journal
PubTypeId: academicJournal
PreciseRelevancyScore: 0
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: eXplainable Artificial Intelligence for Transparent Optimization of Deep Learning-Based Intrusion Detection Systems.
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Komarchesqui%2C+Mateus%22">Komarchesqui, Mateus</searchLink><relatesTo>1</relatesTo> (AUTHOR)<i> mateus.komarchesqui@uel.br</i><br /><searchLink fieldCode="AR" term="%22Silva+Ruffo%2C+Vitor+Gabriel+da%22">Silva Ruffo, Vitor Gabriel da</searchLink><relatesTo>2</relatesTo> (AUTHOR)<i> vitor.ruffo19cc@uel.br</i><br /><searchLink fieldCode="AR" term="%22Carvalho%2C+Luiz+Fernando%22">Carvalho, Luiz Fernando</searchLink><relatesTo>3</relatesTo> (AUTHOR)<i> luizfcarvalho@utfpr.edu.br</i><br /><searchLink fieldCode="AR" term="%22Proença+Jr%2E%2C+Mario+Lemes%22">Proença Jr., Mario Lemes</searchLink><relatesTo>1</relatesTo> (AUTHOR)<i> proenca@uel.br</i>
– Name: TitleSource
  Label: Source
  Group: Src
  Data: <searchLink fieldCode="JN" term="%22Journal+of+Network+%26+Systems+Management%22">Journal of Network & Systems Management</searchLink>. Jul2026, Vol. 34 Issue 3, p1-37. 37p.
– Name: Abstract
  Label: Abstract
  Group: Ab
  Data: The expansion of network boundaries and the rise of hybrid work environments have significantly widened the modern attack surface. Traditional rule-based monitoring struggles to scale, leading to the adoption of automated Artificial Intelligence for IT Operations powered by Deep Learning. However, while these models handle higher data volumes, their black-box nature lacks accountability, which prevents network managers from confidently triaging alarms without risking legitimate traffic disruption. While eXplainable AI techniques like SHapley Additive exPlanations are increasingly employed for regulatory compliance, research often fails to go beyond explicability and to leverage XAI insights to mitigate bias or enhance performance. This paper proposes a transparent conceptual model for the cyclical explanation and optimization of black-box Intrusion Detection Systems, along with a novel, unsupervised, cluster-based undersampling strategy. By leveraging SHAP to create an explainable pipeline and final product, we optimized an existing GAN-based IDS across two benchmark datasets. For the CIC-DDoS2019 dataset, we achieved a 4.7% increase in the Matthews Correlation Coefficient and a 26% reduction in missed attacks. On the CSE-CIC-IDS2018 dataset, the system showed a 21.3% improvement in MCC, reducing missed attacks by 92.32% and false alarms by 3.82%. [ABSTRACT FROM AUTHOR]
– Name: AbstractSuppliedCopyright
  Label:
  Group: Ab
  Data: <i>Copyright of Journal of Network & Systems Management is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.)
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=193695367
RecordInfo BibRecord:
  BibEntity:
    Identifiers:
      – Type: doi
        Value: 10.1007/s10922-026-10084-z
    Languages:
      – Code: eng
        Text: English
    PhysicalDescription:
      Pagination:
        PageCount: 37
        StartPage: 1
    Titles:
      – TitleFull: eXplainable Artificial Intelligence for Transparent Optimization of Deep Learning-Based Intrusion Detection Systems.
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Komarchesqui, Mateus
      – PersonEntity:
          Name:
            NameFull: Silva Ruffo, Vitor Gabriel da
      – PersonEntity:
          Name:
            NameFull: Carvalho, Luiz Fernando
      – PersonEntity:
          Name:
            NameFull: Proença Jr., Mario Lemes
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 01
              M: 07
              Text: Jul2026
              Type: published
              Y: 2026
          Identifiers:
            – Type: issn-print
              Value: 10647570
          Numbering:
            – Type: volume
              Value: 34
            – Type: issue
              Value: 3
          Titles:
            – TitleFull: Journal of Network & Systems Management
              Type: main
ResultId 1