Using Kernel SHAP XAI Method to optimize the Network Anomaly Detection Model

07/31/2023
by   Khushnaseeb Roshan, et al.
0

Anomaly detection and its explanation is important in many research areas such as intrusion detection, fraud detection, unknown attack detection in network traffic and logs. It is challenging to identify the cause or explanation of why one instance is an anomaly? and the other is not due to its unbounded and lack of supervisory nature. The answer to this question is possible with the emerging technique of explainable artificial intelligence (XAI). XAI provides tools and techniques to interpret and explain the output and working of complex models such as Deep Learning (DL). This paper aims to detect and explain network anomalies with XAI, kernelSHAP method. The same approach is used to improve the network anomaly detection model in terms of accuracy, recall, precision and f score. The experiment is conduced with the latest CICIDS2017 dataset. Two models are created (Model_1 and OPT_Model) and compared. The overall accuracy and F score of OPT_Model (when trained in unsupervised way) are 0.90 and 0.76, respectively.

READ FULL TEXT

page 2

page 3

research
10/13/2022

A Survey on Explainable Anomaly Detection

In the past two decades, most research on anomaly detection has focused ...
research
02/14/2022

AnoMili: Spoofing Prevention and Explainable Anomaly Detection for the 1553 Military Avionic Bus

MIL-STD-1553, a standard that defines a communication bus for interconne...
research
09/09/2022

Explanation Method for Anomaly Detection on Mixed Numerical and Categorical Spaces

Most proposals in the anomaly detection field focus exclusively on the d...
research
04/09/2020

Bayesian classification, anomaly detection, and survival analysis using network inputs with application to the microbiome

While the study of a single network is well-established, technological a...
research
08/03/2021

HTTP2vec: Embedding of HTTP Requests for Detection of Anomalous Traffic

Hypertext transfer protocol (HTTP) is one of the most widely used protoc...
research
06/18/2020

The Clever Hans Effect in Anomaly Detection

The 'Clever Hans' effect occurs when the learned model produces correct ...

Please sign up or login with your details

Forgot password? Click here to reset