An Explainable Deep Neural Network Framework for IoT Intrusion Detection: Enhancing Transparency, Interpretability, and Trustworthiness | IJCSE Volume 10 β Issue 5 | IJCSE-V10I5P27
Table of Contents
ToggleInternational Journal of Computer Science Engineering Techniques
ISSN: 2455-135X
Volume 10, Issue 5
|
Published:
Author
RAMPY
Abstract
The rapid expansion of Internet of Things (IoT) deployments has increased the number and heterogeneity of connected devices, creating a broad and dynamic attack surface. Machine-learning (ML)-based intrusion detection systems can learn complex network-traffic patterns and identify malicious behavior, yet many high-performing models provide limited insight into the reasons behind individual predictions. This paper proposes an explainable machine-learning framework for IoT intrusion detection that integrates data preprocessing, feature engineering, supervised classification, and post-hoc Explainable Artificial Intelligence (XAI). SHAP is used for global and local feature attribution, while LIME is used to generate locally interpretable explanations for selected alerts. The proposed evaluation considers binary and multi-class intrusion detection and measures accuracy, precision, recall, F1-score, false-positive rate, ROC-AUC, inference time, model size, and explanation stability. CICIoT2023 is selected as the principal benchmark because it contains traffic from an IoT topology of 105 devices and 33 attacks grouped into seven categories. The framework is designed to move beyond detection accuracy by examining whether an IDS can provide understandable and consistent evidence for its predictions. Numerical performance values are intentionally not fabricated in this manuscript; the experimental protocol and results templates are provided so that measured results can be inserted after implementation. The resulting methodology can support research into transparent and practically useful IoT security analytics.
Keywords
Internet of Things (IoT), Intrusion Detection Systems (IDS), Machine Learning, Deep Neural Networks, Explainable Artificial Intelligence (XAI), SHAP, LIME, CICIoT2023, Cybersecurity, Model Interpretability, Transparency, Trustworthy AI.Conclusion
This paper proposed a comprehensive explainable machine-learning framework for IoT intrusion detection. The framework integrates preprocessing, leakage-aware feature selection, multiple ML classifiers, SHAP and LIME explanations, class-sensitive evaluation, and deployment-oriented measurements. CICIoT2023 provides a suitable benchmark because it was generated from a topology of 105 IoT devices and includes 33 attack scenarios across seven categories. [1]
The proposed methodology deliberately separates measured evidence from conceptual design. No experimental performance values are claimed until the models are executed on the selected dataset. This is important for a publishable research paper because accuracy, F1-score, confusion matrices, ROC curves, and explanation rankings should be reproducible from the reported experimental setup.
The central research contribution is therefore a methodology for combining detection with explanation. By evaluating both predictive behavior and explanation stability, the framework can provide a stronger basis for studying transparent and trustworthy IoT security analytics.
References
[1] E. C. P. Neto, S. Dadkhah, R. Ferreira, A. Zohourian, R. Lu, and A. A. Ghorbani, βCICIoT2023: A Real-Time Dataset and Benchmark for Large-Scale Attacks in IoT Environment,β Sensors, vol. 23, no. 13, Art. no. 5941, 2023.
[2] S. M. Lundberg and S.-I. Lee, βA Unified Approach to Interpreting Model Predictions,β in Advances in Neural Information Processing Systems 30 (NeurIPS), pp. 4765β4774, 2017.
[3] M. T. Ribeiro, S. Singh, and C. Guestrin, βWhy Should I Trust You? Explaining the Predictions of Any Classifier,β in Proc. 22nd ACM SIGKDD Int. Conf. Knowledge Discovery and Data Mining, pp. 1135β1144, 2016.
[4] T. Chen and C. Guestrin, βXGBoost: A Scalable Tree Boosting System,β in Proc. 22nd ACM SIGKDD Int. Conf. Knowledge Discovery and Data Mining, pp. 785β794, 2016.
[5] L. Breiman, βRandom Forests,β Machine Learning, vol. 45, no. 1, pp. 5β32, 2001.
[6] C. Cortes and V. Vapnik, βSupport-vector networks,β Machine Learning, vol. 20, pp. 273β297, 1995.
[7] Y. Meidan, M. Bohadana, Y. Mathov, Y. Mirsky, D. Breitenbacher, A. Shabtai, and Y. Elovici, βN-BaIoTβNetwork-Based Detection of IoT Botnet Attacks Using Deep Autoencoders,β IEEE Pervasive Computing, vol. 17, no. 3, pp. 12β22, 2018.
[8] A. Alsaedi, N. Moustafa, Z. Tari, A. Mahmood, and A. Anwar, βTON_IoT Telemetry Dataset: A New Generation Dataset of IoT and IIoT for Data-Driven Intrusion Detection Systems,β IEEE Access, vol. 8, pp. 165130β165150, 2020.
[9] N. Moustafa and J. Slay, βThe Evaluation of Network Anomaly Detection Systems: Statistical Analysis of the UNSW-NB15 Data Set and the Comparison with the KDD99 Data Set,β Information Security Journal: A Global Perspective, vol. 25, no. 1β3, pp. 18β31, 2016.
[10] N. Moustafa, E. Adi, B. Turnbull, and J. Hu, βA New Threat Intelligence Scheme for Safeguarding Industry 4.0 Systems,β IEEE Access, vol. 6, pp. 32910β32924, 2018.
[11] N. Moustafa, B. Turnbull, and K.-K. R. Choo, βAn Ensemble Intrusion Detection Technique Based on Hybrid of Feature Selection and Machine Learning Algorithms,β IEEE Access, vol. 7, pp. 111324β111337, 2019.
[12] A. Khraisat, I. Gondal, P. Vamplew, and J. Kamruzzaman, βSurvey of Intrusion Detection Systems: Techniques, Datasets and Challenges,β Cybersecurity, vol. 2, Art. no. 20, 2019.
[13] M. Ring, S. Wunderlich, D. Scheuring, D. Landes, and A. Hotho, βA Survey of Network-Based Intrusion Detection Data Sets,β Computers & Security, vol. 86, pp. 147β167, 2019.
[14] R. Sommer and V. Paxson, βOutside the Closed World: On Using Machine Learning for Network Intrusion Detection,β in Proc. IEEE Symposium on Security and Privacy, pp. 305β316, 2010.
[15] R. C. Chen, K. H. Dewi, S. W. Huang, and R. E. Caraka, βSelecting Critical Features for Data Classification Based on Machine Learning Methods,β Journal of Big Data, vol. 7, Art. no. 52, 2020.
[16] M. Du, N. Liu, and X. Hu, βTechniques for Interpretable Machine Learning,β Communications of the ACM, vol. 63, no. 1, pp. 68β77, 2019.
[17] R. Guidotti, A. Monreale, S. Ruggieri, F. Turini, F. Giannotti, and D. Pedreschi, βA Survey of Methods for Explaining Black Box Models,β ACM Computing Surveys, vol. 51, no. 5, Art. no. 93, 2018.
[18] S. M. Lundberg, G. G. Erion, H. Chen, A. DeGrave, J. M. Prutkin, B. Nair, R. Katz, J. Himmelfarb, N. Bansal, and S.-I. Lee, βFrom Local Explanations to Global Understanding with Explainable AI for Trees,β Nature Machine Intelligence, vol. 2, pp. 56β67, 2020.
[19] A. Adadi and M. Berrada, βPeeking Inside the Black-Box: A Survey on Explainable Artificial Intelligence (XAI),β IEEE Access, vol. 6, pp. 52138β52160, 2018.
[20] M. T. Ribeiro, S. Singh, and C. Guestrin, βAnchors: High-Precision Model-Agnostic Explanations,β in Proc. AAAI Conf. Artificial Intelligence, vol. 32, no. 1, 2018.
An Explainable Deep Neural Network Framework for IoT Intrusion Detection Enhancing Transparency, Interpretability, and TrustworthinessDownload
