{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,9]],"date-time":"2026-02-09T22:54:08Z","timestamp":1770677648451,"version":"3.49.0"},"publisher-location":"Cham","reference-count":34,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031440632","type":"print"},{"value":"9783031440649","type":"electronic"}],"license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023]]},"DOI":"10.1007\/978-3-031-44064-9_25","type":"book-chapter","created":{"date-parts":[[2023,10,29]],"date-time":"2023-10-29T04:19:19Z","timestamp":1698553159000},"page":"483-497","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":9,"title":["Evaluating Feature Relevance XAI in\u00a0Network Intrusion Detection"],"prefix":"10.1007","author":[{"given":"Julian","family":"Tritscher","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Maximilian","family":"Wolf","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Andreas","family":"Hotho","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Daniel","family":"Schl\u00f6r","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,10,30]]},"reference":[{"issue":"15","key":"25_CR1","doi-asserted-by":"publisher","first-page":"5690","DOI":"10.3390\/s22155690","volume":"22","author":"MM Alani","year":"2022","unstructured":"Alani, M.M., Miri, A.: Towards an explainable universal feature set for IoT intrusion detection. Sensors 22(15), 5690 (2022). https:\/\/doi.org\/10.3390\/s22155690","journal-title":"Sensors"},{"key":"25_CR2","doi-asserted-by":"publisher","unstructured":"Antwarg, L., Miller, R.M., Shapira, B., Rokach, L.: Explaining anomalies detected by autoencoders using Shapley Additive Explanations. Expert Syst. Appl. 186, 115736 (2021). https:\/\/doi.org\/10.1016\/j.eswa.2021.115736","DOI":"10.1016\/j.eswa.2021.115736"},{"issue":"2","key":"25_CR3","doi-asserted-by":"publisher","first-page":"1153","DOI":"10.1109\/COMST.2015.2494502","volume":"18","author":"AL Buczak","year":"2016","unstructured":"Buczak, A.L., Guven, E.: A survey of data mining and machine learning methods for cyber security intrusion detection. IEEE Commun. Surv. Tutor. 18(2), 1153\u20131176 (2016). https:\/\/doi.org\/10.1109\/COMST.2015.2494502","journal-title":"IEEE Commun. Surv. Tutor."},{"issue":"7","key":"25_CR4","doi-asserted-by":"publisher","first-page":"772","DOI":"10.1016\/j.comcom.2012.01.016","volume":"35","author":"P Casas","year":"2012","unstructured":"Casas, P., Mazel, J., Owezarski, P.: Unsupervised network intrusion detection systems: detecting the unknown without knowledge. Comput. Commun. 35(7), 772\u2013783 (2012). https:\/\/doi.org\/10.1016\/j.comcom.2012.01.016","journal-title":"Comput. Commun."},{"issue":"5","key":"25_CR5","doi-asserted-by":"publisher","first-page":"537","DOI":"10.1108\/IJWIS-03-2021-0022","volume":"17","author":"QV Dang","year":"2021","unstructured":"Dang, Q.V.: Improving the performance of the intrusion detection systems by the machine learning explainability. Int. J. Web Inf. Syst. 17(5), 537\u2013555 (2021). https:\/\/doi.org\/10.1108\/IJWIS-03-2021-0022","journal-title":"Int. J. Web Inf. Syst."},{"key":"25_CR6","doi-asserted-by":"crossref","unstructured":"Davis, J., Goadrich, M.: The relationship between precision-recall and ROC curves. In: Proceedings of the 23rd International Conference on Machine Learning, pp. 233\u2013240 (2006)","DOI":"10.1145\/1143844.1143874"},{"issue":"6","key":"25_CR7","doi-asserted-by":"publisher","first-page":"353","DOI":"10.1016\/j.cose.2011.05.008","volume":"30","author":"JJ Davis","year":"2011","unstructured":"Davis, J.J., Clark, A.J.: Data preprocessing for anomaly based network intrusion detection: a review. Comput. Secur. 30(6), 353\u2013375 (2011)","journal-title":"Comput. Secur."},{"key":"25_CR8","unstructured":"Doshi-Velez, F., Kim, B.: Towards a rigorous science of interpretable machine learning (2017)"},{"key":"25_CR9","unstructured":"Goodfellow, I., Bengio, Y., Courville, A.: Deep Learning. MIT Press (2016). http:\/\/www.deeplearningbook.org"},{"key":"25_CR10","doi-asserted-by":"publisher","first-page":"1164","DOI":"10.1109\/OJCOMS.2022.3188750","volume":"3","author":"ZAE Houda","year":"2022","unstructured":"Houda, Z.A.E., Brik, B., Khoukhi, L.: \u201cWhy should i trust your IDS?\u2019\u2019: an explainable deep learning framework for intrusion detection systems in internet of things networks. IEEE Open J. Commun. Soc. 3, 1164\u20131176 (2022). https:\/\/doi.org\/10.1109\/OJCOMS.2022.3188750","journal-title":"IEEE Open J. Commun. Soc."},{"key":"25_CR11","unstructured":"Krippendorff, K.: Content Analysis: An Introduction to Its Methodology, pp. 145\u2013154. Sage Publications, Beverly Hills (1980)"},{"issue":"3","key":"25_CR12","doi-asserted-by":"publisher","first-page":"1154","DOI":"10.3390\/s22031154","volume":"22","author":"TTH Le","year":"2022","unstructured":"Le, T.T.H., Kim, H., Kang, H., Kim, H.: Classification and explanation for intrusion detection system based on ensemble trees and SHAP method. Sensors 22(3), 1154 (2022). https:\/\/doi.org\/10.3390\/s22031154","journal-title":"Sensors"},{"key":"25_CR13","doi-asserted-by":"crossref","unstructured":"Liu, F.T., Ting, K.M., Zhou, Z.H.: Isolation forest. In: 2008 Eighth IEEE International Conference on Data Mining, pp. 413\u2013422. IEEE (2008)","DOI":"10.1109\/ICDM.2008.17"},{"key":"25_CR14","unstructured":"Lundberg, S., Lee, S.I.: A unified approach to interpreting model predictions. CoRR abs\/1705.07874 (2017)"},{"key":"25_CR15","unstructured":"Mane, S., Rao, D.: Explaining network intrusion detection system using explainable AI framework. arXiv preprint arXiv:2103.07110 (2021)"},{"key":"25_CR16","doi-asserted-by":"crossref","unstructured":"Neupane, S., et al.: Explainable intrusion detection systems (X-IDS): a survey of current methods, challenges, and opportunities (2022)","DOI":"10.1109\/ACCESS.2022.3216617"},{"key":"25_CR17","doi-asserted-by":"crossref","unstructured":"Nguyen, Q.P., Lim, K.W., Divakaran, D.M., Low, K.H., Chan, M.C.: GEE: a gradient-based explainable variational autoencoder for network anomaly detection. In: 2019 IEEE Conference on Communications and Network Security (CNS), pp. 91\u201399 (2019)","DOI":"10.1109\/CNS.2019.8802833"},{"issue":"1","key":"25_CR18","doi-asserted-by":"publisher","first-page":"1000","DOI":"10.1109\/TITS.2022.3188671","volume":"24","author":"A Oseni","year":"2023","unstructured":"Oseni, A., et al.: An explainable deep learning framework for resilient intrusion detection in IoT-enabled transportation networks. IEEE Trans. Intell. Transp. Syst. 24(1), 1000\u20131014 (2023). https:\/\/doi.org\/10.1109\/TITS.2022.3188671","journal-title":"IEEE Trans. Intell. Transp. Syst."},{"issue":"6","key":"25_CR19","doi-asserted-by":"publisher","first-page":"923","DOI":"10.3390\/electronics9060923","volume":"9","author":"D Patel","year":"2020","unstructured":"Patel, D., Srinivasan, K., Chang, C.Y., Gupta, T., Kataria, A.: Network anomaly detection inside consumer networks\u2014a hybrid approach. Electronics 9(6), 923 (2020)","journal-title":"Electronics"},{"key":"25_CR20","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"82","DOI":"10.1007\/978-3-031-23492-7_8","volume-title":"Artificial Intelligence and Soft Computing","author":"M Pawlicki","year":"2023","unstructured":"Pawlicki, M., Zadnik, M., Kozik, R., Chora\u015b, M.: Analysis and detection of DDoS backscatter using NetFlow data, hyperband-optimised deep learning and explainability techniques. In: Rutkowski, L., Scherer, R., Korytkowski, M., Pedrycz, W., Tadeusiewicz, R., Zurada, J.M. (eds.) ICAISC 2022. LNCS, vol. 13588, pp. 82\u201392. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-23492-7_8"},{"key":"25_CR21","doi-asserted-by":"crossref","unstructured":"Ravi, A., Yu, X., Santelices, I., Karray, F., Fidan, B.: General frameworks for anomaly detection explainability: comparative study. In: 2021 IEEE International Conference on Autonomous Systems (ICAS), pp. 1\u20135 (2021)","DOI":"10.1109\/ICAS49788.2021.9551129"},{"key":"25_CR22","doi-asserted-by":"publisher","first-page":"156","DOI":"10.1016\/j.cose.2018.12.012","volume":"82","author":"M Ring","year":"2019","unstructured":"Ring, M., Schl\u00f6r, D., Landes, D., Hotho, A.: Flow-based network traffic generation using generative adversarial networks. Comput. Secur. 82, 156\u2013172 (2019)","journal-title":"Comput. Secur."},{"key":"25_CR23","first-page":"40","volume":"16","author":"M Ring","year":"2017","unstructured":"Ring, M., Wunderlich, S., Gr\u00fcdl, D., Landes, D., Hotho, A.: Creation of flow-based data sets for intrusion detection. J. Inf. Warfare 16, 40\u201353 (2017)","journal-title":"J. Inf. Warfare"},{"key":"25_CR24","unstructured":"Ring, M., Wunderlich, S., Gr\u00fcdl, D., Landes, D., Hotho, A.: Flow-based benchmark data sets for intrusion detection. In: Proceedings of the 16th European Conference on Cyber Warfare and Security (ECCWS), pp. 361\u2013369. ACPI (2017)"},{"key":"25_CR25","doi-asserted-by":"crossref","unstructured":"Sarhan, M., Layeghy, S., Portmann, M.: Evaluating standard feature sets towards increased generalisability and explainability of ML-based network intrusion detection (2021)","DOI":"10.1016\/j.bdr.2022.100359"},{"issue":"13","key":"25_CR26","doi-asserted-by":"publisher","first-page":"6451","DOI":"10.3390\/app12136451","volume":"12","author":"K Sauka","year":"2022","unstructured":"Sauka, K., Shin, G.Y., Kim, D.W., Han, M.M.: Adversarial robust and explainable network intrusion detection systems based on deep learning. Appl. Sci. 12(13), 6451 (2022). https:\/\/doi.org\/10.3390\/app12136451","journal-title":"Appl. Sci."},{"issue":"7","key":"25_CR27","doi-asserted-by":"publisher","first-page":"1443","DOI":"10.1162\/089976601750264965","volume":"13","author":"B Sch\u00f6lkopf","year":"2001","unstructured":"Sch\u00f6lkopf, B., Platt, J.C., Shawe-Taylor, J., Smola, A.J., Williamson, R.C.: Estimating the support of a high-dimensional distribution. Neural Comput. 13(7), 1443\u20131471 (2001)","journal-title":"Neural Comput."},{"key":"25_CR28","unstructured":"Takeishi, N., Kawahara, Y.: On anomaly interpretation via shapley values. arXiv preprint arXiv:2004.04464 (2020), http:\/\/arxiv.org\/pdf\/2004.04464.pdf"},{"issue":"1","key":"25_CR29","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1186\/s42400-022-00134-9","volume":"6","author":"H Torabi","year":"2023","unstructured":"Torabi, H., Mirtaheri, S.L., Greco, S.: Practical autoencoder based anomaly detection by using vector reconstruction error. Cybersecurity 6(1), 1 (2023)","journal-title":"Cybersecurity"},{"key":"25_CR30","doi-asserted-by":"crossref","unstructured":"Tritscher, J., Krause, A., Hotho, A.: Feature relevance XAI in anomaly detection: reviewing approaches and challenges. Front. Artif. Intell. 6, 1099521 (2023)","DOI":"10.3389\/frai.2023.1099521"},{"key":"25_CR31","series-title":"Communications in Computer and Information Science","doi-asserted-by":"publisher","first-page":"79","DOI":"10.1007\/978-3-031-23633-4_7","volume-title":"Machine Learning and Principles and Practice of Knowledge Discovery in Databases","author":"J Tritscher","year":"2023","unstructured":"Tritscher, J., Schl\u00f6r, D., Gwinner, F., Krause, A., Hotho, A.: Towards explainable occupational fraud detection. In: Koprinska, I., et al. (eds.) ECML PKDD 2022. CCIS, vol. 1753, pp. 79\u201396. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-23633-4_7"},{"key":"25_CR32","doi-asserted-by":"publisher","unstructured":"Wali, S., Khan, I.: Explainable AI and random forest based reliable intrusion detection system (2021). https:\/\/doi.org\/10.36227\/techrxiv.17169080.v1","DOI":"10.36227\/techrxiv.17169080.v1"},{"key":"25_CR33","doi-asserted-by":"publisher","first-page":"73127","DOI":"10.1109\/ACCESS.2020.2988359","volume":"8","author":"M Wang","year":"2020","unstructured":"Wang, M., Zheng, K., Yang, Y., Wang, X.: An explainable machine learning framework for intrusion detection systems. IEEE Access 8, 73127\u201373141 (2020)","journal-title":"IEEE Access"},{"key":"25_CR34","doi-asserted-by":"publisher","first-page":"2339","DOI":"10.1109\/TIFS.2022.3183390","volume":"17","author":"T Zebin","year":"2022","unstructured":"Zebin, T., Rezvy, S., Luo, Y.: An explainable AI-based intrusion detection system for DNS over HTTPS (DoH) attacks. IEEE Trans. Inf. Forensics Secur. 17, 2339\u20132349 (2022). https:\/\/doi.org\/10.1109\/TIFS.2022.3183390","journal-title":"IEEE Trans. Inf. Forensics Secur."}],"container-title":["Communications in Computer and Information Science","Explainable Artificial Intelligence"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-44064-9_25","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,10,29]],"date-time":"2023-10-29T04:23:33Z","timestamp":1698553413000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-44064-9_25"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"ISBN":["9783031440632","9783031440649"],"references-count":34,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-44064-9_25","relation":{},"ISSN":["1865-0929","1865-0937"],"issn-type":[{"value":"1865-0929","type":"print"},{"value":"1865-0937","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023]]},"assertion":[{"value":"30 October 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"xAI","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"World Conference on Explainable Artificial Intelligence","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Lisbon","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Portugal","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26 July 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"28 July 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"1","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"xai2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/xaiworldconference.com\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"220","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"94","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"43% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}