{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,18]],"date-time":"2026-08-18T14:24:20Z","timestamp":1787063060161,"version":"3.56.0"},"reference-count":45,"publisher":"Springer Science and Business Media LLC","issue":"11-12","license":[{"start":{"date-parts":[[2025,9,29]],"date-time":"2025-09-29T00:00:00Z","timestamp":1759104000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,9,29]],"date-time":"2025-09-29T00:00:00Z","timestamp":1759104000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/100009117","name":"Technische Universit\u00e4t Chemnitz","doi-asserted-by":"crossref","id":[{"id":"10.13039\/100009117","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Ann. Telecommun."],"published-print":{"date-parts":[[2025,12]]},"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>Artificial intelligence (AI)-based intrusion detection systems (IDSs) markedly advance network security by leveraging machine learning (ML) and deep learning (DL) models for accurate, adaptive threat detection. Their main drawback, however, is an inherent \u201cblack-box\u201d character that impedes trust, traceability, and regulatory compliance. To overcome this limitation, we propose an efficient explainable-AI (XAI) framework that enhances both robustness and interpretability. The two-stage process first couples a statistical selector (ANOVA) with global SHAP scores to retain only the ten most informative features, an approximately 70% dimensionality reduction, then retrains a lightweight XGBoost detector whose decisions are explained locally by SHAP and LIME. Cross-validating the two explanation modalities adds a reliability check absent from earlier hybrids, while the inclusion of a time-efficiency evaluation for explanation generation provides a new performance dimension that prior XAI-IDS studies have not addressed. To our knowledge, this is the first framework to jointly apply dual-stage statistical\u2013model-based feature selection and SHAP\u2013LIME cross-validation in IDS, enabling near-real-time explainability without sacrificing accuracy. Comprehensive experiments on three representative traces, CIC-DDoS2019 (legacy IP DDoS), CICIoT2023 (IoT malware), and 5\u00a0G PFCP (control-plane attacks), confirm the framework\u2019s versatility: it sustains an F1 Score of at least 99 % while accelerating LIME explanation time from 36 to 4.9\u00a0s, an 87 % speed-up. These results demonstrate that high detection accuracy and transparent, near-real-time interpretability can be achieved simultaneously in modern IDS deployments.<\/jats:p>","DOI":"10.1007\/s12243-025-01118-9","type":"journal-article","created":{"date-parts":[[2025,9,29]],"date-time":"2025-09-29T03:37:09Z","timestamp":1759117029000},"page":"1095-1120","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":14,"title":["A versatile XAI-based framework for efficient and explainable intrusion detection systems"],"prefix":"10.1007","volume":"80","author":[{"given":"Beny","family":"Nugraha","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Abhishek Venkatesh","family":"Jnanashree","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Thomas","family":"Bauschert","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,9,29]]},"reference":[{"key":"1118_CR1","doi-asserted-by":"publisher","first-page":"82","DOI":"10.1016\/j.inffus.2019.12.012","volume":"58","author":"AB Arrieta","year":"2020","unstructured":"Arrieta AB et al (2020) Explainable artificial intelligence (XAI): concepts, taxonomies, opportunities and challenges toward responsible AI. Information Fusion 58:82\u2013115","journal-title":"Information Fusion"},{"issue":"7623","key":"1118_CR2","doi-asserted-by":"publisher","first-page":"20","DOI":"10.1038\/538020a","volume":"538","author":"D Castelvecchi","year":"2016","unstructured":"Castelvecchi D (2016) Can we open the black box of AI? Nature 538(7623):20","journal-title":"Nature"},{"key":"1118_CR3","unstructured":"Lundberg SM, Lee S-I (2017) A unified approach to interpreting model predictions. In: Proceedings of the Advances in Neural Information Processing Systems (NeurIPS), pp. 4768\u20134777"},{"key":"1118_CR4","doi-asserted-by":"crossref","unstructured":"Ribeiro MT, Singh S, Guestrin C (2016) \u2019Why should I trust you?\u2019: explaining the predictions of any classifier. In: Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, pp. 1135\u20131144","DOI":"10.1145\/2939672.2939778"},{"key":"1118_CR5","doi-asserted-by":"publisher","first-page":"112392","DOI":"10.1109\/ACCESS.2022.3216617","volume":"10","author":"S Neupane","year":"2022","unstructured":"Neupane S et al (2022) Explainable intrusion detection systems (x-ids): a survey of current methods, challenges, and opportunities. IEEE Access 10:112392\u2013112415. https:\/\/doi.org\/10.1109\/ACCESS.2022.3216617","journal-title":"IEEE Access"},{"key":"1118_CR6","unstructured":"Chuang Y-N, Wang G, Yang F, Liu Z, Cai X, Du M, Hu X (2023) Efficient XAI techniques: a taxonomic survey. arXiv preprint. arXiv:2302.03225"},{"issue":"4","key":"1118_CR7","doi-asserted-by":"publisher","first-page":"259","DOI":"10.1016\/0169-7439(89)80095-4","volume":"6","author":"L Sthle","year":"1989","unstructured":"Sthle L, Wold S (1989) Analysis of variance (ANOVA). Chemom Intell Lab Syst 6(4):259\u2013272. https:\/\/doi.org\/10.1016\/0169-7439(89)80095-4","journal-title":"Chemom Intell Lab Syst"},{"key":"1118_CR8","doi-asserted-by":"publisher","unstructured":"Nugraha B, Jnanashree AV, Bauschert T (2024) An efficient explainable artificial intelligence (XAI)-based framework for a robust and explainable IDS. In: 2024 8th Cyber Security in Networking Conference (CSNet), pp. 173\u2013181. https:\/\/doi.org\/10.1109\/CSNet64211.2024.10851760","DOI":"10.1109\/CSNet64211.2024.10851760"},{"key":"1118_CR9","doi-asserted-by":"publisher","unstructured":"Ferreira P, Martins E, Silva J, Teixeira P (2025) Feature selection and XGBoost for enhanced intrusion detection: a comparative study across benchmark datasets. In: 2025 13th International Symposium on Digital Forensics and Security (ISDFS), pp. 1\u20136.\u00a0https:\/\/doi.org\/10.1109\/ISDFS65363.2025.11012060","DOI":"10.1109\/ISDFS65363.2025.11012060"},{"key":"1118_CR10","doi-asserted-by":"publisher","unstructured":"Khani P et al (2024) Explainable artificial intelligence for feature selection in network traffic classification: a comparative study. Transactions on Emerging Telecommunications Technologies. 35(4).\u00a0https:\/\/doi.org\/10.1002\/ett.4970 . Early access or final version, depending on publication status","DOI":"10.1002\/ett.4970"},{"key":"1118_CR11","unstructured":"Shaker BN, Al-Musawi B, Hassan MF (2025) A lightweight IDS for early APT detection using a novel feature selection method. https:\/\/arxiv.org\/abs\/2506.12108"},{"key":"1118_CR12","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2025.104541","volume":"157","author":"AS Anagha","year":"2025","unstructured":"Anagha AS, Thomas C, Balakrishnan N (2025) Optimized intrusion predictions through feature selection methods. Computers & Security 157:104541. https:\/\/doi.org\/10.1016\/j.cose.2025.104541","journal-title":"Computers & Security"},{"issue":"4","key":"1118_CR13","doi-asserted-by":"publisher","first-page":"5115","DOI":"10.1109\/TNSM.2023.3282740","volume":"20","author":"G Rjoub","year":"2023","unstructured":"Rjoub G et al (2023) A survey on explainable artificial intelligence for cybersecurity. IEEE Trans Netw Serv Manage 20(4):5115\u20135140. https:\/\/doi.org\/10.1109\/TNSM.2023.3282740","journal-title":"IEEE Trans Netw Serv Manage"},{"key":"1118_CR14","doi-asserted-by":"publisher","first-page":"93104","DOI":"10.1109\/ACCESS.2022.3204051","volume":"10","author":"Z Zhang","year":"2022","unstructured":"Zhang Z, Hamadi HA, Damiani E, Yeun CY, Taher F (2022) Explainable artificial intelligence applications in cyber security: state-of-the-art in research. IEEE Access 10:93104\u201393139. https:\/\/doi.org\/10.1109\/ACCESS.2022.3204051","journal-title":"IEEE Access"},{"key":"1118_CR15","doi-asserted-by":"crossref","unstructured":"Khan N, Ahmad K, Tamimi AA, Alani MM, Bermak A, Khalil I (2024) Explainable AI-based intrusion detection system for Industry 5.0: an overview of the literature, associated challenges, the existing solutions, and potential research directions. https:\/\/arxiv.org\/abs\/2408.03335","DOI":"10.3390\/info16121036"},{"key":"1118_CR16","unstructured":"Mane S, Rao D (2021) Explaining network intrusion detection system using explainable AI framework. arXiv preprint. arXiv:2103.07110"},{"key":"1118_CR17","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1155\/2021\/6634811","volume":"2021","author":"B Mahbooba","year":"2021","unstructured":"Mahbooba B, Timilsina M, Sahal R, Serrano M (2021) Explainable artificial intelligence (XAI) to enhance trust management in intrusion detection systems using decision tree model. Complexity 2021:1\u201311","journal-title":"Complexity"},{"issue":"2","key":"1118_CR18","doi-asserted-by":"publisher","first-page":"1115","DOI":"10.1007\/s11277-023-10472-7","volume":"131","author":"Y Wang","year":"2023","unstructured":"Wang Y, Xu L, Liu W, Li R, Gu J (2023) Network intrusion detection based on explainable artificial intelligence. Wireless Pers Commun 131(2):1115\u20131130. https:\/\/doi.org\/10.1007\/s11277-023-10472-7","journal-title":"Wireless Pers Commun"},{"key":"1118_CR19","doi-asserted-by":"publisher","first-page":"1164","DOI":"10.1109\/OJCOMS.2022.3188750","volume":"3","author":"ZAE Houda","year":"2022","unstructured":"Houda ZAE, Brik B, Khoukhi L (2022) \u201cWhy should I trust your ids?\u2019\u2019: an explainable deep learning framework for intrusion detection systems in internet of things networks. IEEE Open Journal of the Communications Society 3:1164\u20131170. https:\/\/doi.org\/10.1109\/OJCOMS.2022.3188750","journal-title":"IEEE Open Journal of the Communications Society"},{"key":"1118_CR20","doi-asserted-by":"publisher","DOI":"10.1109\/LNET.2022.3186589","author":"P Barnard","year":"2022","unstructured":"Barnard P, Marchetti N, Silva LAD (2022) Robust network intrusion detection through explainable artificial intelligence (XAI). IEEE Networking Letters. https:\/\/doi.org\/10.1109\/LNET.2022.3186589","journal-title":"IEEE Networking Letters"},{"key":"1118_CR21","doi-asserted-by":"publisher","unstructured":"Kaur, N., Gupta, L.: Enhancing IoT security in 6G environment with transparent AI: leveraging XGBoost, SHAP and LIME. In: 2024 IEEE 10th International Conference on Network Softwarization (NetSoft), pp. 180\u2013184 (2024).\u00a0https:\/\/doi.org\/10.1109\/NetSoft60951.2024.10588922","DOI":"10.1109\/NetSoft60951.2024.10588922"},{"key":"1118_CR22","doi-asserted-by":"publisher","unstructured":"Marc\u00edlio WE, Eler DM (2020) From explanations to feature selection: assessing SHAP values as feature selection mechanism. In: 2020 33rd SIBGRAPI Conference on Graphics, Patterns and Images (SIBGRAPI), pp. 340\u2013347.\u00a0https:\/\/doi.org\/10.1109\/SIBGRAPI51738.2020.00053","DOI":"10.1109\/SIBGRAPI51738.2020.00053"},{"key":"1118_CR23","doi-asserted-by":"publisher","first-page":"181","DOI":"10.1016\/j.future.2021.09.010","volume":"127","author":"IA Khan","year":"2022","unstructured":"Khan IA, Moustafa N, Razzak I, Tanveer M, Pi D, Pan Y, Ali BS (2022) XSRU-IoMT: explainable simple recurrent units for threat detection in internet of medical things networks. Futur Gener Comput Syst 127:181\u2013190. https:\/\/doi.org\/10.1016\/j.future.2021.09.010","journal-title":"Futur Gener Comput Syst"},{"issue":"13","key":"1118_CR24","doi-asserted-by":"publisher","first-page":"11604","DOI":"10.1109\/JIOT.2021.3130156","volume":"9","author":"IA Khan","year":"2022","unstructured":"Khan IA, Moustafa N, Pi D, Sallam KM, Zomaya AY, Li B (2022) A new explainable deep learning framework for cyber threat discovery in industrial IoT networks. IEEE Internet Things J 9(13):11604\u201311613. https:\/\/doi.org\/10.1109\/JIOT.2021.3130156","journal-title":"IEEE Internet Things J"},{"issue":"6","key":"1118_CR25","doi-asserted-by":"publisher","first-page":"3228","DOI":"10.1109\/JBHI.2024.3352013","volume":"28","author":"IA Khan","year":"2024","unstructured":"Khan IA, Razzak I, Pi D, Zia U, Kamal S, Hussain Y (2024) A novel collaborative SRU network with dynamic behaviour aggregation, reduced communication overhead and explainable features. IEEE J Biomed Health Inform 28(6):3228\u20133235. https:\/\/doi.org\/10.1109\/JBHI.2024.3352013","journal-title":"IEEE J Biomed Health Inform"},{"key":"1118_CR26","doi-asserted-by":"publisher","unstructured":"Burkart N, Franz M, Huber MF (2021) Explanation framework for intrusion detection. In: Beyerer, J., Maier, A., Niggemann, O. (eds.) Machine learning for cyber physical systems. Technologien f\u00fcr die intelligente Automation, vol. 13. Springer, ???. https:\/\/doi.org\/10.1007\/978-3-662-62746-4_9","DOI":"10.1007\/978-3-662-62746-4_9"},{"key":"1118_CR27","unstructured":"Cumi-Guzman BA, Espinosa-Chim AD, Orozco-Del-Castillo MG, Recio-Garc\u00eda JA (2024) Counterfactual explanation of a classification model for detecting SQL injection attacks. In: Proceedings of the Workshops at the 32nd International Conference on Case-Based Reasoning (ICCBR 2024). CEUR Workshop Proceedings, vol. 3708, pp. 49\u201364. CEUR-WS.org, ???"},{"key":"1118_CR28","unstructured":"Ables J, Childers N, Anderson W, Mittal S, Rahimi S, Banicescu I, Seale M (2024) Eclectic rule extraction for explainability of deep neural network based intrusion detection systems. https:\/\/arxiv.org\/abs\/2401.10207"},{"key":"1118_CR29","doi-asserted-by":"publisher","unstructured":"Ouhssini M, Afdel K, Akouhar M, Agherrabi E, Abarda A (2024) Interpretable deep learning for DDoS defense: a SHAP-based approach in cloud computing. In: 2024 International Conference on Circuit, Systems and Communication (ICCSC), pp. 1\u20138. https:\/\/doi.org\/10.1109\/ICCSC62074.2024.10616654","DOI":"10.1109\/ICCSC62074.2024.10616654"},{"key":"1118_CR30","unstructured":"Mutlu G, Rihani N (2025) Intrusion detection system with explainable AI and federated learning. To be updated with publication details"},{"key":"1118_CR31","unstructured":"Yang J (2021) Fast treeshap: Accelerating SHAP value computation for trees. arXiv preprint. arXiv:2109.09847"},{"key":"1118_CR32","unstructured":"Lemaire V, Cl\u00e9rot F, Boull\u00e9 M (2023) An efficient Shapley value computation for the Naive Bayes classifier. arXiv preprint. arXiv:2307.16718. [Online]. Available: https:\/\/arxiv.org\/abs\/2307.16718"},{"key":"1118_CR33","doi-asserted-by":"crossref","unstructured":"Santhiappan S, Reghu MK, Saminathan M, Veerappan A (2024) Speeding up lime using attention weights. In: Proceedings of the 7th Joint International Conference on Data Science & Management of Data (11th ACM IKDD CODS and 29th COMAD), pp. 444\u2013448. Association for Computing Machinery, ??? . [Online]. Available: https:\/\/doi.org\/10.1145\/3632410.3632450","DOI":"10.1145\/3632410.3632450"},{"issue":"13","key":"1118_CR34","doi-asserted-by":"publisher","first-page":"14388","DOI":"10.1609\/aaai.v38i13.29352","volume":"38","author":"M Muschalik","year":"2024","unstructured":"Muschalik M, Fumagalli F, Hammer B, H\u00fcllermeier E (2024) Beyond treeshap: efficient computation of any-order Shapley interactions for tree ensembles. Proceedings of the AAAI Conference on Artificial Intelligence 38(13):14388\u201314396","journal-title":"Proceedings of the AAAI Conference on Artificial Intelligence"},{"key":"1118_CR35","doi-asserted-by":"publisher","unstructured":"Hassan F, Yu J, Syed ZS, Magsi AH, Ahmed N (2023) Developing transparent IDS for VANETs using LIME and SHAP: an empirical study. Computers, Materials and Continua 77(3):3185\u20133208.\u00a0https:\/\/doi.org\/10.32604\/cmc.2023.044650","DOI":"10.32604\/cmc.2023.044650"},{"key":"1118_CR36","doi-asserted-by":"publisher","first-page":"1440","DOI":"10.7717\/peerj-cs.1440","volume":"9","author":"F Hassan","year":"2023","unstructured":"Hassan F, Yu J, Syed ZS, Ahmed N, Reshan MSA, Shaikh A (2023) Achieving model explainability for intrusion detection in VANETs with LIME. PeerJ Computer Science 9:1440. https:\/\/doi.org\/10.7717\/peerj-cs.1440","journal-title":"PeerJ Computer Science"},{"key":"1118_CR37","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2024.3437248","author":"T Senevirathna","year":"2024","unstructured":"Senevirathna T, La VH, Marchal S, Siniarski B, Liyanage M, Wang S (2024) A survey on XAI for 5g and beyond security: technical aspects, challenges and research directions. IEEE Communications Surveys & Tutorials. https:\/\/doi.org\/10.1109\/COMST.2024.3437248","journal-title":"IEEE Communications Surveys & Tutorials"},{"key":"1118_CR38","unstructured":"Simonyan K, Vedaldi A, Zisserman A (2013) Deep inside convolutional networks: visualising image classification models and saliency maps. CoRR. abs\/1312.6034. [Online]. Available: https:\/\/api.semanticscholar.org\/CorpusID:1450294"},{"key":"1118_CR39","unstructured":"Sundararajan M, Taly A, Yan Q (2017) Axiomatic attribution for deep networks. CoRR. abs\/1703.01365. [Online]. Available: http:\/\/arxiv.org\/abs\/1703.01365"},{"key":"1118_CR40","unstructured":"Shrikumar A, Greenside P, Kundaje A (2017) Learning important features through propagating activation differences. In: Proceedings of the International Conference on Machine Learning (ICML). PMLR, ???"},{"key":"1118_CR41","doi-asserted-by":"crossref","unstructured":"Sharafaldin I, Lashkari AH, Hakak S, Ghorbani AA (2019) Developing realistic distributed denial of service (DDoS) attack dataset and taxonomy. In: 2019 International Carnahan Conference on Security Technology (ICCST), pp. 1\u20138. IEEE, ???","DOI":"10.1109\/CCST.2019.8888419"},{"issue":"13","key":"1118_CR42","doi-asserted-by":"publisher","first-page":"5941","DOI":"10.3390\/s23135941","volume":"23","author":"ECP Neto","year":"2023","unstructured":"Neto ECP, Dadkhah S, Ferreira R, Zohourian A, Lu R, Ghorbani AA (2023) CICIoT 2023: a real-time dataset and benchmark for large-scale attacks in IoT environment. Sensors 23(13):5941","journal-title":"Sensors"},{"key":"1118_CR43","doi-asserted-by":"publisher","unstructured":"Amponis G et al (2023) 5G core PFCP intrusion detection dataset. In: 2023 12th International Conference on Modern Circuits and Systems Technologies (MOCAST), pp. 1\u20134. https:\/\/doi.org\/10.1109\/MOCAST57943.2023.10176693","DOI":"10.1109\/MOCAST57943.2023.10176693"},{"key":"1118_CR44","doi-asserted-by":"crossref","unstructured":"Chen T, Guestrin C (2016) XGBoost: a scalable tree boosting system. In: Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, pp. 785\u2013794","DOI":"10.1145\/2939672.2939785"},{"key":"1118_CR45","unstructured":"Arik S\u00d6, Pfister T (2019) Tabnet: attentive interpretable tabular learning. CoRR. abs\/1908.07442. arXiv:1908.07442"}],"container-title":["Annals of Telecommunications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s12243-025-01118-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s12243-025-01118-9","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s12243-025-01118-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,17]],"date-time":"2026-04-17T07:43:49Z","timestamp":1776411829000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s12243-025-01118-9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9,29]]},"references-count":45,"journal-issue":{"issue":"11-12","published-print":{"date-parts":[[2025,12]]}},"alternative-id":["1118"],"URL":"https:\/\/doi.org\/10.1007\/s12243-025-01118-9","relation":{},"ISSN":["0003-4347","1958-9395"],"issn-type":[{"value":"0003-4347","type":"print"},{"value":"1958-9395","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,9,29]]},"assertion":[{"value":"22 January 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"21 September 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"29 September 2025","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}]}}