eXplainable Artificial Intelligence for Transparent Optimization of Deep Learning-Based Intrusion Detection Systems.
Saved in:
| Title: | eXplainable Artificial Intelligence for Transparent Optimization of Deep Learning-Based Intrusion Detection Systems. |
|---|---|
| Authors: | Komarchesqui, Mateus1 (AUTHOR) mateus.komarchesqui@uel.br, Silva Ruffo, Vitor Gabriel da2 (AUTHOR) vitor.ruffo19cc@uel.br, Carvalho, Luiz Fernando3 (AUTHOR) luizfcarvalho@utfpr.edu.br, Proença Jr., Mario Lemes1 (AUTHOR) proenca@uel.br |
| Source: | Journal of Network & Systems Management. Jul2026, Vol. 34 Issue 3, p1-37. 37p. |
| Abstract: | The expansion of network boundaries and the rise of hybrid work environments have significantly widened the modern attack surface. Traditional rule-based monitoring struggles to scale, leading to the adoption of automated Artificial Intelligence for IT Operations powered by Deep Learning. However, while these models handle higher data volumes, their black-box nature lacks accountability, which prevents network managers from confidently triaging alarms without risking legitimate traffic disruption. While eXplainable AI techniques like SHapley Additive exPlanations are increasingly employed for regulatory compliance, research often fails to go beyond explicability and to leverage XAI insights to mitigate bias or enhance performance. This paper proposes a transparent conceptual model for the cyclical explanation and optimization of black-box Intrusion Detection Systems, along with a novel, unsupervised, cluster-based undersampling strategy. By leveraging SHAP to create an explainable pipeline and final product, we optimized an existing GAN-based IDS across two benchmark datasets. For the CIC-DDoS2019 dataset, we achieved a 4.7% increase in the Matthews Correlation Coefficient and a 26% reduction in missed attacks. On the CSE-CIC-IDS2018 dataset, the system showed a 21.3% improvement in MCC, reducing missed attacks by 92.32% and false alarms by 3.82%. [ABSTRACT FROM AUTHOR] |
| Copyright of Journal of Network & Systems Management is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.) | |
| Database: | Engineering Source |
| FullText | Text: Availability: 0 |
|---|---|
| Header | DbId: egs DbLabel: Engineering Source An: 193695367 AccessLevel: 6 PubType: Academic Journal PubTypeId: academicJournal PreciseRelevancyScore: 0 |
| IllustrationInfo | |
| Items | – Name: Title Label: Title Group: Ti Data: eXplainable Artificial Intelligence for Transparent Optimization of Deep Learning-Based Intrusion Detection Systems. – Name: Author Label: Authors Group: Au Data: <searchLink fieldCode="AR" term="%22Komarchesqui%2C+Mateus%22">Komarchesqui, Mateus</searchLink><relatesTo>1</relatesTo> (AUTHOR)<i> mateus.komarchesqui@uel.br</i><br /><searchLink fieldCode="AR" term="%22Silva+Ruffo%2C+Vitor+Gabriel+da%22">Silva Ruffo, Vitor Gabriel da</searchLink><relatesTo>2</relatesTo> (AUTHOR)<i> vitor.ruffo19cc@uel.br</i><br /><searchLink fieldCode="AR" term="%22Carvalho%2C+Luiz+Fernando%22">Carvalho, Luiz Fernando</searchLink><relatesTo>3</relatesTo> (AUTHOR)<i> luizfcarvalho@utfpr.edu.br</i><br /><searchLink fieldCode="AR" term="%22Proença+Jr%2E%2C+Mario+Lemes%22">Proença Jr., Mario Lemes</searchLink><relatesTo>1</relatesTo> (AUTHOR)<i> proenca@uel.br</i> – Name: TitleSource Label: Source Group: Src Data: <searchLink fieldCode="JN" term="%22Journal+of+Network+%26+Systems+Management%22">Journal of Network & Systems Management</searchLink>. Jul2026, Vol. 34 Issue 3, p1-37. 37p. – Name: Abstract Label: Abstract Group: Ab Data: The expansion of network boundaries and the rise of hybrid work environments have significantly widened the modern attack surface. Traditional rule-based monitoring struggles to scale, leading to the adoption of automated Artificial Intelligence for IT Operations powered by Deep Learning. However, while these models handle higher data volumes, their black-box nature lacks accountability, which prevents network managers from confidently triaging alarms without risking legitimate traffic disruption. While eXplainable AI techniques like SHapley Additive exPlanations are increasingly employed for regulatory compliance, research often fails to go beyond explicability and to leverage XAI insights to mitigate bias or enhance performance. This paper proposes a transparent conceptual model for the cyclical explanation and optimization of black-box Intrusion Detection Systems, along with a novel, unsupervised, cluster-based undersampling strategy. By leveraging SHAP to create an explainable pipeline and final product, we optimized an existing GAN-based IDS across two benchmark datasets. For the CIC-DDoS2019 dataset, we achieved a 4.7% increase in the Matthews Correlation Coefficient and a 26% reduction in missed attacks. On the CSE-CIC-IDS2018 dataset, the system showed a 21.3% improvement in MCC, reducing missed attacks by 92.32% and false alarms by 3.82%. [ABSTRACT FROM AUTHOR] – Name: AbstractSuppliedCopyright Label: Group: Ab Data: <i>Copyright of Journal of Network & Systems Management is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.) |
| PLink | https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=193695367 |
| RecordInfo | BibRecord: BibEntity: Identifiers: – Type: doi Value: 10.1007/s10922-026-10084-z Languages: – Code: eng Text: English PhysicalDescription: Pagination: PageCount: 37 StartPage: 1 Titles: – TitleFull: eXplainable Artificial Intelligence for Transparent Optimization of Deep Learning-Based Intrusion Detection Systems. Type: main BibRelationships: HasContributorRelationships: – PersonEntity: Name: NameFull: Komarchesqui, Mateus – PersonEntity: Name: NameFull: Silva Ruffo, Vitor Gabriel da – PersonEntity: Name: NameFull: Carvalho, Luiz Fernando – PersonEntity: Name: NameFull: Proença Jr., Mario Lemes IsPartOfRelationships: – BibEntity: Dates: – D: 01 M: 07 Text: Jul2026 Type: published Y: 2026 Identifiers: – Type: issn-print Value: 10647570 Numbering: – Type: volume Value: 34 – Type: issue Value: 3 Titles: – TitleFull: Journal of Network & Systems Management Type: main |
| ResultId | 1 |