Explainable Artificial Intelligence For Real-Time Cyber Attack Detection And Risk Assessment

Uncategorized

Authors: Priya Mahesh Borkar, S.Divya

Abstract: Security operations centers rely on machine learning in increasing amounts when conducting network intrusion detection, but the inability to comprehend, trust, and act on alerts caused by black-box models is a significant issue under time pressure. Explainable AI (XAI) solutions such as SHAP and LIME provide solutions to the transparency problem, yet the explanation latency that they introduce makes them unsuitable for real-time triage of security alerts. This paper introduces an integrated XAI framework that consists of a Random Forest-XGBoost soft voting model along with a latency-aware dual mode explanation engine that uses the optimal LIME path for real-time query explanation and the approximated KernelSHAP path for forensic query explanation. A feature weighted risk scoring component transforms explanation attribution scores into a risk score bound in real time. Using the UNSW-NB15 dataset, we show that the framework provides state-of-the-art detection performance comparable to black box baselines with explanation latency well within real-time bounds and high attribution stability for forensic purposes.

× How can I help you?