PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
May 13, 2026Journal of Network and Systems Management2 citationsOpen Access

eXplainable Artificial Intelligence for Transparent Optimization of Deep Learning-Based Intrusion Detection Systems

MKMateus KomarchesquiVRVitor Gabriel da Silva RuffoLCLuiz Fernando Carvalho

Key Points

  • This research aims to create a transparent model for optimizing black-box intrusion detection systems using explainable AI techniques.
  • Proposed a cyclical explanation and optimization model for intrusion detection systems.
  • Developed a novel unsupervised, cluster-based undersampling strategy.
  • Utilized SHAP to establish an explainable pipeline and tested on benchmark datasets.
  • Achieved a 4.7% increase in Matthews Correlation Coefficient on the CIC-DDoS2019 dataset, with a 26% reduction in missed attacks.
  • On the CSE-CIC-IDS2018 dataset, demonstrated a 21.3% improvement in MCC, reducing missed attacks by 92.32% and false alarms by 3.82%.

Abstract

Abstract The expansion of network boundaries and the rise of hybrid work environments have significantly widened the modern attack surface. Traditional rule-based monitoring struggles to scale, leading to the adoption of automated Artificial Intelligence for IT Operations powered by Deep Learning. However, while these models handle higher data volumes, their black-box nature lacks accountability, which prevents network managers from confidently triaging alarms without risking legitimate traffic disruption. While eXplainable AI techniques like SHapley Additive exPlanations are increasingly employed for regulatory compliance, research often fails to go beyond explicability and to leverage XAI insights to mitigate bias or enhance performance. This paper proposes a transparent conceptual model for the cyclical explanation and optimization of black-box Intrusion Detection Systems, along with a novel, unsupervised, cluster-based undersampling strategy. By leveraging SHAP to create an explainable pipeline and final product, we optimized an existing GAN-based IDS across two benchmark datasets. For the CIC-DDoS2019 dataset, we achieved a 4.7% increase in the Matthews Correlation Coefficient and a 26% reduction in missed attacks. On the CSE-CIC-IDS2018 dataset, the system showed a 21.3% improvement in MCC, reducing missed attacks by 92.32% and false alarms by 3.82%.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Komarchesqui et al. (2026) studied this question.

synapsesocial.com/papers/6a04158679e20c90b4445520https://doi.org/10.1007/s10922-026-10084-z
Ask AI
Helpful
Bookmark
Share
View Full Paper