Human-Centered Explainable AI for Security Enhancement: A Deep Intrusion Detection Framework

The increasing complexity and frequency of cyberthreats demand intrusion detection systems (IDS) that are not only accurate but also interpretable. This paper presented a novel IDS framework that integrated Explainable Artificial Intelligence (XAI) to enhance transparency in deep learning models. The framework was evaluated experimentally using benchmark dataset NSL-KDD demonstrating superior performance compared to traditional IDS and black-box deep learning (DL) models. The proposed approach combined Convolutional Neural Network (CNNs) and Long Short-Term Memory (LSTM) network for capturing temporal dependencies in traffic sequences. Our DL results showed that both CNN and LSTM reached 0.99 for accuracy whereas LSTM outperformed CNN at macro average precision, recall and F-1 score. For weighted average precision, recall and F-1 score, both model scored almost similar. To ensure interpretability, XAI model SHapley Additive exPlanations (SHAP) was incorporated, enabling security analysts to understand and validate model decisions. Some notable influential features were srv_serror_rate, dst_host_srv_serror_rate, and serror_rate for both models as pointed out by SHAP. We also conducted a trust-focused expert survey based on IPIP6 and Big Five personality traits via an interactive user interface (UI) to evaluate the system's reliability and usability. This work highlighted the potential of combining performance and transparency in cybersecurity solutions and recommends future enhancements through adaptive learning for real-time threat detection.

Paper

Similar papers

© 2026 NYSGPT2525 LLC