Explainable Artificial Intelligence Enabled Intrusion Detection in the Internet of Things
摘要
The Internet of Things (IoT) has seamlessly integrated into our daily lives. However, due to the heterogeneous nature of IoT networks, they are particularly exposed to cyber threats. To address this vulnerability, Artificial Intelligence (AI)-based Intrusion Detection Systems (IDS) have emerged as effective tools for countering IoT cyberattacks. Nevertheless, to maximize their utility, gaining a deeper comprehension of their architecture and capacity to explain predictions is essential, which is crucial for validating and analyzing potential cyber threats. Although eXplainable Artificial Intelligence (XAI) has garnered significant interest, its application in IoT cybersecurity still requires thorough investigation to measure its effectiveness in unveiling attacks. This paper introduces a novel framework for explainable intrusion detection in IoT. We have developed several IDS using varying AI techniques, e.g., Random Forest and Multilayer Perceptron, to detect cyberattacks and explain the model decisions leveraging SHapley Additive exPlanations (SHAP). We also examine the explanation results by building new detection models using a subset of features suggested by the explanation results. We validated our framework using a newly released dataset, i.e., CICIoT2023, which includes extensive cyberattack samples collected in real IoT operations. The evaluation results demonstrate that the proposed framework can assist decision-makers in comprehending complicated attack behaviors.