{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,24]],"date-time":"2026-07-24T13:06:03Z","timestamp":1784898363664,"version":"3.55.0"},"publisher-location":"Cham","reference-count":29,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032006295","type":"print"},{"value":"9783032006301","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-3-032-00630-1_4","type":"book-chapter","created":{"date-parts":[[2025,8,8]],"date-time":"2025-08-08T13:37:07Z","timestamp":1754660227000},"page":"55-72","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Evaluating Explanation Quality in\u00a0X-IDS Using Feature Alignment Metrics"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0003-0598-8150","authenticated-orcid":false,"given":"Mohammed","family":"Alquliti","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8250-4389","authenticated-orcid":false,"given":"Erisa","family":"Karafili","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5984-9867","authenticated-orcid":false,"given":"BooJoong","family":"Kang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,8,9]]},"reference":[{"issue":"10","key":"4_CR1","doi-asserted-by":"publisher","first-page":"4170","DOI":"10.3390\/app14104170","volume":"14","author":"O Arreche","year":"2024","unstructured":"Arreche, O., Guntur, T., Abdallah, M.: XAI-IDS: toward proposing an explainable artificial intelligence framework for enhancing network intrusion detection systems. Appl. Sci. 14(10), 4170 (2024)","journal-title":"Appl. Sci."},{"key":"4_CR2","unstructured":"Arya, V., Bellamy, R.K., Chen, et\u00a0al.: One explanation does not fit all: a toolkit and taxonomy of AI explainability techniques. arXiv preprint arXiv:1909.03012 (2019)"},{"key":"4_CR3","doi-asserted-by":"publisher","first-page":"93575","DOI":"10.1109\/ACCESS.2022.3204171","volume":"10","author":"N Capuano","year":"2022","unstructured":"Capuano, N., Fenza, G., Loia, V., Stanzione, C.: Explainable artificial intelligence in cybersecurity: a survey. IEEE Access 10, 93575\u201393600 (2022)","journal-title":"IEEE Access"},{"key":"4_CR4","unstructured":"Cybersecurity and Infrastructure Security Agency (CISA): Best practices: Mitre ATT &CK\u00ae mapping. CISA Insights (2023). https:\/\/www.cisa.gov\/news-events\/news\/best-practices-mitre-attckr-mapping. Accessed 12 Apr 2025"},{"key":"4_CR5","unstructured":"Dieber, J., Kirrane, S.: Why model why? Assessing the strengths and limitations of lime. arXiv preprint arXiv:2012.00093 (2020)"},{"key":"4_CR6","unstructured":"Hedstr\u00f6m, A., Weber, L., Krakowczyk, D., Bareeva, D., Motzkus, et\u00a0al.: Quantus: an explainable AI toolkit for responsible evaluation of neural network explanations and beyond. J. Mach. Learn. Res. 24(34), 1\u201311 (2023)"},{"key":"4_CR7","first-page":"2021","volume":"11","author":"PE Kaloroumakis","year":"2021","unstructured":"Kaloroumakis, P.E., Smith, M.J.: Toward a knowledge graph of cybersecurity countermeasures. MITRE Corporation 11, 2021 (2021)","journal-title":"MITRE Corporation"},{"key":"4_CR8","first-page":"343","volume":"23","author":"K Kostas","year":"2018","unstructured":"Kostas, K.: Anomaly detection in networks using machine learning. Res. Proposal 23, 343 (2018)","journal-title":"Res. Proposal"},{"key":"4_CR9","doi-asserted-by":"crossref","unstructured":"Lanvin, M., Gimenez, P.F., Han, Y., Majorczyk, et\u00a0al.: Towards understanding alerts raised by unsupervised network intrusion detection systems. In: Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses, pp. 135\u2013150 (2023)","DOI":"10.1145\/3607199.3607247"},{"key":"4_CR10","doi-asserted-by":"crossref","unstructured":"Lin, Y.S., Lee, et\u00a0al.: What do you see? Evaluation of explainable artificial intelligence (XAI) interpretability through neural backdoors. In: Proceedings 27th ACM SIGKDD Conference on Knowledge Discovery and Data Mining, pp. 1027\u20131035 (2021)","DOI":"10.1145\/3447548.3467213"},{"key":"4_CR11","doi-asserted-by":"crossref","unstructured":"Lopes, P., Silva, E., Braga, C., Oliveira, et\u00a0al.: XAI systems evaluation: a review of human and computer-centred methods. Appl. Sci. 12(19), 9423 (2022)","DOI":"10.3390\/app12199423"},{"key":"4_CR12","unstructured":"Lundberg, S.M., Lee, S.I.: A unified approach to interpreting model predictions. In: Advances in Neural Information Processing Systems, vol. 30 (2017)"},{"key":"4_CR13","unstructured":"MITRE corporation: Mitre ATT &CK\u00ae knowledge base, v16.1 (release 2024-10-31). MITRE ATT &CK Insights (2024). https:\/\/attack.mitre.org\/. Accessed 19 Apr 2025"},{"key":"4_CR14","doi-asserted-by":"publisher","first-page":"1526221","DOI":"10.3389\/frai.2025.1526221","volume":"8","author":"VZ Mohale","year":"2025","unstructured":"Mohale, V.Z., et al.: A systematic review on the integration of explainable artificial intelligence in intrusion detection systems to enhancing transparency and interpretability in cybersecurity. Front. Artif. Intell. 8, 1526221 (2025)","journal-title":"Front. Artif. Intell."},{"issue":"3","key":"4_CR15","doi-asserted-by":"publisher","first-page":"1775","DOI":"10.1109\/COMST.2023.3280465","volume":"25","author":"N Moustafa","year":"2023","unstructured":"Moustafa, N., Koroniotis, N., Keshk, M., Zomaya, A.Y., Tari, Z.: Explainable intrusion detection for cyber defences in the internet of things: opportunities and solutions. IEEE Commun. Surv. Tutorials 25(3), 1775\u20131807 (2023)","journal-title":"IEEE Commun. Surv. Tutorials"},{"key":"4_CR16","doi-asserted-by":"crossref","unstructured":"Nauta, M., Trienes, J., Pathak, S., Nguyen, E., Peters, et\u00a0al.: From anecdotal evidence to quantitative evaluation methods: a systematic review on evaluating explainable AI. ACM Comput. Surv. 55(13s), 1\u201342 (2023)","DOI":"10.1145\/3583558"},{"key":"4_CR17","doi-asserted-by":"publisher","first-page":"112392","DOI":"10.1109\/ACCESS.2022.3216617","volume":"10","author":"S Neupane","year":"2022","unstructured":"Neupane, S., et al.: Explainable intrusion detection systems (X-IDS): a survey of current methods, challenges, and opportunities. IEEE Access 10, 112392\u2013112415 (2022)","journal-title":"IEEE Access"},{"key":"4_CR18","doi-asserted-by":"crossref","unstructured":"Nir, D., Kaiser, F.K., Giladi, S., Sharabi, et\u00a0al.: Labeling network intrusion detection system (NIDS) rules with MITRE ATT &CK techniques: machine learning vs. large language models. Big Data Cognit. Comput. 9(2), 23 (2025)","DOI":"10.3390\/bdcc9020023"},{"key":"4_CR19","doi-asserted-by":"crossref","unstructured":"Patil, S., Varadarajan, V., Mazhar, S.M., Sahibzada, et\u00a0al.: Explainable artificial intelligence for intrusion detection system. Electronics 11(19), 3079 (2022)","DOI":"10.3390\/electronics11193079"},{"issue":"12","key":"4_CR20","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s10462-024-10972-3","volume":"57","author":"M Pawlicki","year":"2024","unstructured":"Pawlicki, M., Pawlicka, A., Kozik, R., Chora\u015b, M.: The survey on the dual nature of XAI challenges in intrusion detection and their potential for AI innovation. Artif. Intell. Rev. 57(12), 1\u201332 (2024)","journal-title":"Artif. Intell. Rev."},{"key":"4_CR21","doi-asserted-by":"crossref","unstructured":"Rosenfeld, A.: Better metrics for evaluating explainable artificial intelligence. In: Proceedings of the 20th International Conference on Autonomous Agents and Multiagent Systems, pp. 45\u201350 (2021)","DOI":"10.65109\/GNWD5518"},{"issue":"5","key":"4_CR22","doi-asserted-by":"publisher","first-page":"3043","DOI":"10.1007\/s10618-022-00867-8","volume":"38","author":"G Schwalbe","year":"2024","unstructured":"Schwalbe, G., Finzel, B.: A comprehensive taxonomy for explainable artificial intelligence: a systematic survey of surveys on methods and concepts. Data Min. Knowl. Disc. 38(5), 3043\u20133101 (2024)","journal-title":"Data Min. Knowl. Disc."},{"key":"4_CR23","doi-asserted-by":"crossref","unstructured":"Sharafaldin, I., Lashkari, et\u00a0al.: Toward generating a new intrusion detection dataset and intrusion traffic characterization. ICISSp 1(2018), 108\u2013116 (2018)","DOI":"10.5220\/0006639801080116"},{"key":"4_CR24","doi-asserted-by":"publisher","first-page":"115047","DOI":"10.1109\/ACCESS.2023.3323573","volume":"11","author":"MM Shtayat","year":"2023","unstructured":"Shtayat, M.M., Hasan, M.K., Sulaiman, R., Islam, S., Khan, A.U.R.: An explainable ensemble deep learning approach for intrusion detection in industrial internet of things. IEEE Access 11, 115047\u2013115061 (2023)","journal-title":"IEEE Access"},{"key":"4_CR25","doi-asserted-by":"crossref","unstructured":"Sinha, J., Manollas, M.: Efficient deep CNN-BILSTM model for network intrusion detection. In: Proceedings of the 2020 3rd International Conference on Artificial Intelligence and Pattern Recognition, pp. 223\u2013231 (2020)","DOI":"10.1145\/3430199.3430224"},{"key":"4_CR26","doi-asserted-by":"crossref","unstructured":"Tritscher, J., Krause, et\u00a0al.: Feature relevance XAI in anomaly detection: reviewing approaches and challenges. Front. Artif. Intell. 6, 1099521 (2023)","DOI":"10.3389\/frai.2023.1099521"},{"key":"4_CR27","doi-asserted-by":"publisher","unstructured":"Tritscher, J., Wolf, M., Hotho, A., Schl\u00f6r, D.: Evaluating feature relevance XAI in network intrusion detection. In: Longo, L. (eds.) World Conference on Explainable Artificial Intelligence, pp. 483\u2013497. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-44064-9_25","DOI":"10.1007\/978-3-031-44064-9_25"},{"key":"4_CR28","doi-asserted-by":"crossref","unstructured":"Wu, Z., Chen, J., Li, Y., Deng, Y., Zhao, H., Hsieh, et\u00a0al.: From black boxes to actionable insights: a perspective on explainable artificial intelligence for scientific discovery. J. Chem. Inf. Model. 63(24), 7617\u20137627 (2023)","DOI":"10.1021\/acs.jcim.3c01642"},{"key":"4_CR29","doi-asserted-by":"crossref","unstructured":"Zhou, J., Gandomi, A.H., Chen, et\u00a0al.: Evaluating the quality of machine learning explanations: a survey on methods and metrics. Electron. 10(5), 593 (2021)","DOI":"10.3390\/electronics10050593"}],"container-title":["Lecture Notes in Computer Science","Availability, Reliability and Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-00630-1_4","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,24]],"date-time":"2026-07-24T12:49:55Z","timestamp":1784897395000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-00630-1_4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"ISBN":["9783032006295","9783032006301"],"references-count":29,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-00630-1_4","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]},"assertion":[{"value":"9 August 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ARES","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Availability, Reliability and Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Ghent","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Belgium","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"11 August 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14 August 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"ares-12025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/2025.ares-conference.eu","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}