Beyond the Black Box: XAI Strategies for Safeguarding Critical Infrastructure
摘要
Machine learning (ML) has become proficient in performing analysis and prediction of emerging threats more effectively and efficiently. It has been extensively used in protecting the critical computing infrastructure. However, the opaqueness with ML-based intrusion detection systems (IDSes) for protecting the data and applications of computing infrastructure raises a strong concern about the trustworthiness of such tools. In the realm of raising security incidents, transparency is crucial to trusting and confidently using ML models to develop robust security tools. Yet, the inherent opacity of black-box ML models and the increasing complexity of cumulative models pose potential security risks. In response, Explainable Artificial Intelligence (XAI) emerges as a crucial approach, focusing on the interpretability of AI systems that can clarify their decisions or predictions for users. XAI aims to enhance transparency, trustworthiness, and accountability, especially in high-stakes applications such as cybersecurity. This chapter offers a comprehensive understanding of the fundamental concepts of XAI and its applications for protecting critical computing infrastructure against emerging attacks. A comprehensive analysis of the taxonomy of ML models, XAI techniques, and libraries is provided to explain the importance of XAI in security. The future directions on XAI have also been discussed. A case study on the use of XAI is provided for protecting the data and applications from network malware attacks using open-source libraries and tools.