AI-Powered Explainable Intrusion Detection System with Cross-Domain Adaptability
DOI:
https://doi.org/10.22178/acta.27.3.4Keywords:
Intrusion Detection System, Explainable Artificial Intelligence, Machine Learning, Deep Learning, SHAP, Adversarial Defence, Cross-Domain Adaptability, Mitigation, FilterAbstract
As the Internet of Things (IoT), cloud computing, and distributed network systems continue to grow rapidly, ensuring cybersecurity has become a critical global concern. The rise in the number of smart devices interconnected has expanded the potential attack surface for cyber threats, thus necessitating real-time threat detection and prevention. Traditional Intrusion Detection Systems (IDS) primarily rely on static, signature-based, or rule-based detection methods, which are adequate for identifying known threats but inadequate for recognizing new, altered, or zero-day attacks. Furthermore, these systems often operate as black boxes, lacking transparency and explanation for their actions, which undermines their reliability in real-world security scenarios. This study presents an AI-driven Explainable Intrusion Detection System (IDS) that integrates the strengths of Machine Learning (ML) and Deep Learning (DL) models to both detect and clarify. The framework utilizes hybrid algorithms, including XG-Boost, Random Forest, and Convolutional Neural Networks (CNN), to attain high accuracy in detection. To enhance interpretability, the system integrates SHAP (Shapley Additive explanations), an Explainable AI (XAI) method that illustrates and quantifies how specific network features impact the model’s prediction results. Additionally, the model features an Adversarial Defense mechanism to bolster its resistance against evasion and poisoning attacks, assuring dependability even when confronted with manipulated or adversarial input data. A significant innovation presented in this work is the Mitigation Module, which expands the IDS beyond merely detecting threats. The system automatically provides suggestions for appropriate defensive measures as an attack is detected. For example, it may suggest rate limiting and firewall adjustments in the case of Distributed Denial of Service (DDoS) attacks, account lockout and password throttling for brute-force intrusions, and input sanitization or prepared statements for injection-based threats. This transforms the IDS from a detection system into an intelligent and proactive security assistant capable of real-time response.
The system has been evaluated and confirmed using various benchmark datasets, such as CICIDS 2017, TON_IoT, IoT-23, NSL-KDD, and UNSW-NB15, representing a diverse array of attack types, networking conditions, and traffic behaviours. The proposed Intrusion Detection System (IDS) consistently achieves high accuracy, exceeding 97% across all datasets, while also showing improved interpretability, resilience, and adaptability to different domains. By incorporating AI-based modelling, explainability, adversarial defences, and automated mitigation strategies, the system provides a thorough, transparent, and adaptable solution for contemporary cybersecurity issues. The results underscore the potential of this framework to lay the groundwork for future self-learning and explainable IDS solutions in both industrial and research contexts.



