Skip to main navigation Skip to search Skip to main content

xIDS-EnsembleGuard: An Explainable Ensemble Learning-based Intrusion Detection System

  • Muhammad Adil
  • , Mian Ahmad Jan
  • , Safayat Bin Hakim
  • , Houbing Herbert Song
  • , Zhanpeng Jin
  • SUNY Buffalo
  • University of Sharjah
  • University of Maryland, Baltimore County

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

5 Scopus citations

Abstract

In this paper, we focus on addressing the challenges of detecting malicious attacks in networks by designing an advanced Explainable Intrusion Detection System (xIDS). The existing machine learning and deep learning approaches have invisible limitations, such as potential biases in predictions, a lack of interpretability, and the risk of overfitting to training data. These issues can create doubt about their usefulness, and transparency, and decrease the trust of involved stakeholders. To overcome these challenges, we propose an ensemble learning technique called the "EnsembleGuard". This approach uses the predicted outputs of multiple models, including tree-based (LightGBM, GBM, Bagging, XGBoost, CatBoost) and deep learning models such as neural network (LSTM (long short-term memory networks) and GRU (gated recurrent unit), to maintain a balance and achieve trustworthy results. Our work is unique because it combines both tree-based and deep learning models to design an interpretable and explainable meta-model through model distillation. By considering the predictions of all individual models, our neta-model effectively addresses key challenges, and ensures both explainable and reliable results. We evaluate our model using well-known datasets, including UNSW-NB15, NSL-KDD, and CIC-IDS-2017, to assess its reliability against various types of attacks. During analysis, we found that our model outperforms both tree-based models and other comparative approaches when it comes to different kinds of attack scenarios.

Original languageEnglish
Title of host publicationProceedings - 2024 IEEE 23rd International Conference on Trust, Security and Privacy in Computing and Communications, TrustCom 2024, 18th IEEE International Conference on Big Data Science and Engineering, BigDataSE 2024, 27th IEEE International Conference on Computational Science and Engineering, CSE 2024, 22nd International Conferences on Embedded and Ubiquitous Computing, EUC 2024 and 12th IEEE International Conference on Smart City and Informatization, iSCI 2024
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages93-100
Number of pages8
Edition2024
ISBN (Electronic)9798331506209, 9798331506209
DOIs
StatePublished - 2024
Event23rd IEEE International Conference on Trust, Security and Privacy in Computing and Communications, TrustCom 2024 - Sanya, China
Duration: Dec 17 2024Dec 21 2024

Conference

Conference23rd IEEE International Conference on Trust, Security and Privacy in Computing and Communications, TrustCom 2024
Country/TerritoryChina
CitySanya
Period12/17/2412/21/24

Keywords

  • Ensemble Learning
  • Intrusion Detection Systems
  • Transparency in Attacks Detection

Fingerprint

Dive into the research topics of 'xIDS-EnsembleGuard: An Explainable Ensemble Learning-based Intrusion Detection System'. Together they form a unique fingerprint.

Cite this