Netinfo Security ›› 2026, Vol. 26 ›› Issue (6): 854-869.doi: 10.3969/j.issn.1671-1122.2026.06.002

Previous Articles     Next Articles

A Study on Intrusion Detection Methods Based on Explainable Artificial Intelligence

YANG Wang(), ZHENG Weite   

  1. School of Cyber Science and Engineering, Southeast University, Nanjing 211189, China
  • Received:2025-12-31 Online:2026-06-10 Published:2026-07-27
  • Contact: YANG Wang E-mail:wang.yang@seu.edu.cn

Abstract:

To address the issues of opaque decision-making processes and poor generalization ability against variant attacks in deep learning-based intrusion detection systems, this paper proposed an explainability-guided intrusion detection method (EGA-ID). This method breaked the limitation of traditional ensemble learning, which selected base learners solely based on accuracy, and introduced explanation consistency as a key dimension to measure model complementarity. By constructing a unified explanatory vector space, the differences in decision-making logics of heterogeneous models were quantified, thereby selecting a subset of models with diverse and complementary decision-making perspectives. Meanwhile, combined with FGSM-based adversarial augmentation training and a multi-layer fusion decision mechanism comprising Platt Scaling probability calibration and a meta-learner, a robust and transparent end-to-end detection architecture was established. Experimental results on both NSL-KDD and UNSW-NB15 datasets demonstrate that EGA-ID outperforms deep learning baselines and traditional ensemble models in F1-score and detection accuracy. Furthermore, it significantly improves the recall rate for sparse and variant attack samples while maintaining high precision. In addition, the method achieves extremely high explanation fidelity and stability, verifying that high-quality explainability can feedback and enhance model performance, thus achieving a favorable balance between high performance and explainability in the evaluated scenarios.

Key words: intrusion detection, explainable AI, ensemble learning, explanation consistency, adversarial training

CLC Number: