信息网络安全 ›› 2026, Vol. 26 ›› Issue (6): 854-869.doi: 10.3969/j.issn.1671-1122.2026.06.002
收稿日期:2025-12-31
出版日期:2026-06-10
发布日期:2026-07-27
通讯作者:
杨望
E-mail:wang.yang@seu.edu.cn
作者简介:杨望(1979—),男,安徽,讲师,博士,主要研究方向为网络空间安全|郑伟特(1999—),男,浙江,硕士研究生,主要研究方向为网络安全日志分析
基金资助:Received:2025-12-31
Online:2026-06-10
Published:2026-07-27
Contact:
YANG Wang
E-mail:wang.yang@seu.edu.cn
摘要:
针对深度学习入侵检测系统存在决策过程不透明、面对变种攻击泛化能力弱等问题,文章提出一种解释驱动的入侵检测方法(EGA-ID)。该方法打破传统集成学习仅依赖准确率筛选基学习器的局限,引入解释一致性作为衡量模型互补性的关键维度。通过构建统一的解释向量空间,量化异构模型决策逻辑的差异,筛选出决策视角多元且互补的模型子集。同时,结合基于快速梯度符号法的对抗增强训练与包含普拉特概率校准及元学习器的多层融合决策机制,构建稳健且透明的端到端检测架构。在NSL-KDD与UNSW-NB15双基准数据集上的实验结果表明,EGA-ID在F1值与检测精度上均优于深度学习基准及传统集成模型,并在保持高精确率的同时,显著提升对稀疏及变种攻击样本的召回率。此外,该方法实现较高的解释忠实度与稳定性,证实高质量的可解释性能够提升模型性能,在所评测的场景下实现高性能与可解释性的良好平衡。
中图分类号:
杨望, 郑伟特. 基于可解释人工智能的入侵检测方法研究[J]. 信息网络安全, 2026, 26(6): 854-869.
YANG Wang, ZHENG Weite. A Study on Intrusion Detection Methods Based on Explainable Artificial Intelligence[J]. Netinfo Security, 2026, 26(6): 854-869.
表1
不同模型在NSL-KDD与UNSW-NB15数据集上的性能对比
| 数据集 | 模型名称 | Accuracy | Precision | Recall | F1-Score |
|---|---|---|---|---|---|
| NSL-KDD | CNN | 94.85% | 95.12% | 94.60% | 94.86% |
| LSTM | 94.20% | 94.45% | 93.90% | 94.17% | |
| Random Forest | 98.72% | 98.85% | 98.50% | 98.67% | |
| XGBoost | 99.15% | 99.20% | 99.08% | 99.14% | |
| DT-EnSVM | 99.36% | 99.70% | 99.07% | 99.38% | |
| HAE-HRL | 95.72% | 96.03% | 95.45% | 95.74% | |
| EGA-ID | 99.72% | 99.65% | 99.79% | 99.72% | |
| UNSW-NB15 | CNN | 91.55% | 92.10% | 91.05% | 91.57% |
| LSTM | 90.85% | 91.30% | 90.45% | 90.87% | |
| Random Forest | 94.15% | 94.80% | 93.55% | 94.17% | |
| XGBoost | 95.35% | 96.10% | 94.75% | 95.42% | |
| DT-EnSVM | 96.12% | 97.50% | 95.93% | 96.70% | |
| HAE-HRL | 94.93% | 94.85% | 94.91% | 94.89% | |
| EGA-ID | 96.82% | 97.35% | 97.18% | 97.26% |
表2
EGA-ID关键模块在不同数据集上的消融实验结果
| 数据集 | 编号 | Accuracy | Precision | Recall | F1-Score | Fidelity_Drop | Stability |
|---|---|---|---|---|---|---|---|
| NSL-KDD | A0 | 99.72% | 99.65% | 99.79% | 99.72% | 0.6935 | 0.0425 |
| A1 | 99.50% | 99.68% | 99.32% | 99.50% | 0.6422 | 0.1355 | |
| A2 | 99.15% | 99.02% | 99.28% | 99.15% | 0.5104 | 0.0510 | |
| UNSW-NB15 | A0 | 96.82% | 97.35% | 97.18% | 97.26% | 0.6743 | 0.1358 |
| A1 | 95.73% | 96.58% | 95.41% | 95.99% | 0.6125 | 0.2874 | |
| A2 | 95.18% | 95.93% | 94.87% | 95.40% | 0.5017 | 0.1642 |
| [1] | ROESCH M. Snort: Lightweight Intrusion Detection for Networks[EB/OL]. (1999-11-09)[2025-12-20]. https://dl.acm.org/doi/10.5555/1039834.1039864. |
| [2] | PATCHA A, PARK J M. An Overview of Anomaly Detection Techniques: Existing Solutions and Latest Technological Trends[J]. Computer Networks, 2007, 51(12): 3448-3470. |
| [3] | BUCZAK A L, GUVEN E. A Survey of Data Mining and Machine Learning Methods for Cyber Security Intrusion Detection[J]. IEEE Communications Surveys & Tutorials, 2016, 18(2): 1153-1176. |
| [4] | LOTFOLLAHI M, JAFARI S M, SHIRALI H Z R, et al. Deep Packet: A Novel Approach for Encrypted Traffic Classification Using Deep Learning[J]. Soft Computing, 2020, 24(3): 1999-2012. |
| [5] | MOHALE V Z, OBAGBUWA I C. A Systematic Review on the Integration of Explainable Artificial Intelligence in Intrusion Detection Systems to Enhancing Transparency and Interpretability in Cybersecurity[EB/OL]. (2025-01-28)[2025-12-20]. https://doi.org/10.3389/frai.2025.1526221. |
| [6] | MALLAMPATI S B, SEETHA H. Enhancing Intrusion Detection with Explainable AI: A Transparent Approach to Network Security[J]. Cybernetics and Information Technologies, 2024, 24(1): 98-117. |
| [7] | IKRAM I, HUMA Z. An Explainable AI Approach to Intrusion Detection Using Interpretable Machine Learning Models[EB/OL]. (2024-05-31)[2025-12-20]. https://evjai.com/index.php/evjai/article/view/20. |
| [8] | SARHAN M. L-XAIDS: A LIME-Based Explainable AI Framework for Intrusion Detection Systems[EB/OL]. (2025-09-03)[2025-12-20]. https://link.springer.com/article/10.1007/s10586-025-05326-9. |
| [9] | GRABOWSKI A, XU Shengjie. Advancing Cybersecurity Practice: Explainable Machine Learning for Network Intrusion Detection[EB/OL]. (2025-12-15)[2025-12-20]. https://digitalcommons.kennesaw.edu/jcerp/vol2025/iss1/25/. |
| [10] | COREA P M, LIU Yongxin, WANG Jian, et al. Explainable AI for Comparative Analysis of Intrusion Detection Models[C]// IEEE. 2024 IEEE International Mediterranean Conference on Communications and Networking (MeditCom). New York: IEEE, 2024: 585-590. |
| [11] | ALMOLHIS N A. Intrusion Detection Using Hybrid Random Forest and Attention Models and Explainable AI Visualization[J]. Journal of Internet Services and Information Security, 2025, 15(1): 371-384. |
| [12] | MARICAR A, ANOOP A, SAMUEL B E, et al. An Improved Explainable Artificial Intelligence for Intrusion Detection System[EB/OL]. [2025-12-20]. https://ijisae.org/index.php/IJISAE/article/view/4642. |
| [13] | AHMED U, ZHENG Jiangbin, ALMOGREN A, et al. Explainable AI-Based Innovative Hybrid Ensemble Model for Intrusion Detection[EB/OL]. (2024-10-21)[2025-12-20]. https://link.springer.com/article/10.1186/s13677-024-00712-x. |
| [14] | NUGRAHA B, JNANASHREE A V, BAUSCHERT T. A Versatile XAI-Based Framework for Efficient and Explainable Intrusion Detection Systems[J]. Annals of Telecommunications, 2025, 80(11/12): 1095-1120. |
| [15] | ARRECHE O, GUNTUR T, ABDALLAH M. XAI-Based Feature Selection for Improved Network Intrusion Detection Systems[EB/OL]. (2024-10-14)[2025-12-20]. https://arxiv.org/abs/2410.10050. |
| [16] | ALABBADI A, BAJABER F. An Intrusion Detection System over the IoT Data Streams Using eXplainable Artificial Intelligence (XAI)[EB/OL]. (2025-01-30)[2025-12-20]. https://www.mdpi.com/1424-8220/25/3/847. |
| [17] | OZAWA N, SUNAHARA S, HAGIHARA S. Evaluation Criteria for Explainable AI in Intrusion Detection to Ensure the Creation of High-Quality Threat Intelligence[C]// ACM. The 2025 14th International Conference on Software and Computer Applications. New York: ACM, 2025: 60-66. |
| [18] | ARRECHE O, ABDALLAH M. A Comparative Analysis of DNN-Based White-Box Explainable AI Methods in Network Security[EB/OL]. (2025-04-24)[2025-12-20]. https://link.springer.com/article/10.1186/s13635-025-00201-x. |
| [19] | AL S, SAGIROGLU S. Explainable Artificial Intelligence Models in Intrusion Detection Systems[EB/OL]. (2025-01-31)[2025-12-20]. https://doi.org/10.1016/j.engappai.2025.110145. |
| [20] | XUE Yankun, KANG Chunying, YU Hongchen. HAE-HRL: A Network Intrusion Detection System Utilizing a Novel Autoencoder and a Hybrid Enhanced LSTM-CNN-Based Residual Network[EB/OL]. (2025-01-16)[2025-12-20]. https://doi.org/10.1016/j.cose.2025.104328. |
| [21] | GU Jie, WANG Lihong, WANG Huiwen, et al. A Novel Approach to Intrusion Detection Using SVM Ensemble with Feature Augmentation[J]. Computers & Security, 2019, 86: 53-62. |
| [1] | 孙钰, 张轩瑞, 刘新宇. 高级持续性威胁检测与溯源研究进展[J]. 信息网络安全, 2026, 26(6): 833-853. |
| [2] | 张浩, 叶骏威. 基于深度主动学习的联邦半监督入侵检测系统[J]. 信息网络安全, 2026, 26(6): 944-957. |
| [3] | 陈潮, 王诺萱, 周胜利. 基于ADASYN、Lasso回归和集成学习的比特币异常交易检测方法[J]. 信息网络安全, 2026, 26(3): 452-461. |
| [4] | 王新猛, 陈俊雹, 杨一涛, 李文瑾, 顾杜娟. 贝叶斯优化的DAE-MLP恶意流量识别模型[J]. 信息网络安全, 2025, 25(9): 1465-1472. |
| [5] | 曹越, 方泊璎, 魏高达, 李金宇, 杨洋, 彭涛. 车载以太网环境下CAN总线入侵检测系统兼容性评估与优化[J]. 信息网络安全, 2025, 25(8): 1175-1195. |
| [6] | 金志刚, 李紫梦, 陈旭阳, 刘泽培. 面向数据不平衡的网络入侵检测系统研究综述[J]. 信息网络安全, 2025, 25(8): 1240-1253. |
| [7] | 孙南, 秦中元, 胡爱群, 李涛. 基于仿生免疫的可编程数据平面入侵检测方法[J]. 信息网络安全, 2025, 25(8): 1263-1275. |
| [8] | 荀毅杰, 崔嘉容, 毛伯敏, 秦俊蔓. 基于联邦学习的智能汽车CAN总线入侵检测系统[J]. 信息网络安全, 2025, 25(6): 872-888. |
| [9] | 金增旺, 江令洋, 丁俊怡, 张慧翔, 赵波, 方鹏飞. 工业控制系统安全研究综述[J]. 信息网络安全, 2025, 25(3): 341-363. |
| [10] | 刘晨飞, 万良. 基于时空图神经网络的CAN总线入侵检测方法[J]. 信息网络安全, 2025, 25(3): 478-493. |
| [11] | 刘联海, 黎汇业, 毛冬晖. 基于图像凸包特征的CBAM-CNN网络入侵检测方法[J]. 信息网络安全, 2024, 24(9): 1422-1431. |
| [12] | 赵伟, 任潇宁, 薛吟兴. 基于集成学习的成员推理攻击方法[J]. 信息网络安全, 2024, 24(8): 1252-1264. |
| [13] | 项慧, 薛鋆豪, 郝玲昕. 基于语言特征集成学习的大语言模型生成文本检测[J]. 信息网络安全, 2024, 24(7): 1098-1109. |
| [14] | 张浩, 谢大智, 胡云晟, 叶骏威. 基于半监督学习的网络异常检测研究综述[J]. 信息网络安全, 2024, 24(4): 491-508. |
| [15] | 屠晓涵, 张传浩, 刘孟然. 恶意流量检测模型设计与实现[J]. 信息网络安全, 2024, 24(4): 520-533. |
| 阅读次数 | ||||||
|
全文 |
|
|||||
|
摘要 |
|
|||||
