{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,8]],"date-time":"2026-03-08T23:48:14Z","timestamp":1773013694555,"version":"3.50.1"},"reference-count":65,"publisher":"Institution of Engineering and Technology (IET)","issue":"1","license":[{"start":{"date-parts":[[2025,10,29]],"date-time":"2025-10-29T00:00:00Z","timestamp":1761696000000},"content-version":"vor","delay-in-days":301,"URL":"http:\/\/creativecommons.org\/licenses\/by\/4.0\/"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/doi.wiley.com\/10.1002\/tdm_license_1.1"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62372410"],"award-info":[{"award-number":["62372410"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U22B2028"],"award-info":[{"award-number":["U22B2028"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004731","name":"Natural Science Foundation of Zhejiang Province","doi-asserted-by":"publisher","award":["LZ23F020011"],"award-info":[{"award-number":["LZ23F020011"]}],"id":[{"id":"10.13039\/501100004731","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004731","name":"Natural Science Foundation of Zhejiang Province","doi-asserted-by":"publisher","award":["LD22F020002"],"award-info":[{"award-number":["LD22F020002"]}],"id":[{"id":"10.13039\/501100004731","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["ietresearch.onlinelibrary.wiley.com"],"crossmark-restriction":true},"short-container-title":["IET Information Security"],"published-print":{"date-parts":[[2025,1]]},"abstract":"<jats:p>Network intrusion detection (NID) plays a crucial role in cybersecurity by identifying network attacks from network traffic. In recent years, the deep learning technique has become a tendency for the NID problem. However, a major drawback of deep learning is the lack of interpretability, making NID systems (NIDSs) difficult to diagnose and response to the detected network attacks. At the same time, the existing interpretable deep learning techniques cannot adapt to the NID problem due to its specific challenges, including the cross\u2010feature effect and the absence of self\u2010interpretable features. To this end, this article proposes a decision Tree enhanced deep Attention Network (TAN), an interpretable deep learning model specifically designed for the NID problem by integrating a decision tree (DT) into a deep attention network. TAN utilizes a DT to extract self\u2010interpretable features and then uses a deep hierarchical attention network to capture the cross\u2010feature effect and pinpoint the most important self\u2010interpretable features. A series of experiments and case studies were performed on public datasets, including KDD99, NSL\u2010KDD, UNSW\u2010NB15, and CICIDS2017. The results indicate that TAN achieves competitive detection performance compared to existing deep learning models, while offering a more intuitive interpretation.<\/jats:p>","DOI":"10.1049\/ise2\/5552833","type":"journal-article","created":{"date-parts":[[2025,10,29]],"date-time":"2025-10-29T18:51:05Z","timestamp":1761763865000},"update-policy":"https:\/\/doi.org\/10.1002\/crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["An Interpretable Network Intrusion Detection Model via Decision Tree Enhanced Deep Attention Network"],"prefix":"10.1049","volume":"2025","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4810-7491","authenticated-orcid":false,"given":"Mingqi","family":"Lv","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7335-5721","authenticated-orcid":false,"given":"Shengduo","family":"Gan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kang","family":"Xu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4664-3311","authenticated-orcid":false,"given":"Tieming","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8657-662X","authenticated-orcid":false,"given":"Tiantian","family":"Zhu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7153-2755","authenticated-orcid":false,"given":"Jinyin","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"265","published-online":{"date-parts":[[2025,10,29]]},"reference":[{"key":"e_1_2_11_1_2","doi-asserted-by":"publisher","DOI":"10.1145\/2808691"},{"key":"e_1_2_11_2_2","first-page":"24","article-title":"Big Data Analytics for Network Intrusion Detection: A Survey","volume":"7","author":"Wang L.","year":"2017","journal-title":"International Journal of Networks and Communications"},{"key":"e_1_2_11_3_2","doi-asserted-by":"crossref","unstructured":"AlthubitiS. A. JonesE. M. andRoyK. LSTM for Anomaly-Based Network Intrusion Detection 28th International Telecommunication Networks and Applications Conference (ITNAC) 2018 IEEE 1\u20133.","DOI":"10.1109\/ATNAC.2018.8615300"},{"key":"e_1_2_11_4_2","doi-asserted-by":"crossref","unstructured":"FarahnakianF.andHeikkonenJ. A Deep Auto-Encoder Based Approach for Intrusion Detection System 20th International Conference on Advanced Communication Technology (ICACT) 2018 IEEE 178\u2013183.","DOI":"10.23919\/ICACT.2018.8323688"},{"key":"e_1_2_11_5_2","unstructured":"GwonH. LeeC. andKeumR. et al.Network Intrusion Detection Based on LSTM and Feature Embedding 2019 arXiv preprint arXiv: 1911.11552."},{"key":"e_1_2_11_6_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2904620"},{"key":"e_1_2_11_7_2","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2018.2854724"},{"key":"e_1_2_11_8_2","doi-asserted-by":"publisher","DOI":"10.1145\/3236386.3241340"},{"key":"e_1_2_11_9_2","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243792"},{"key":"e_1_2_11_10_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-98131-4"},{"key":"e_1_2_11_11_2","unstructured":"DanilevskyM. QianK. andAharonovR. A Survey of the State of Explainable AI for Natural Language Processing 2020 arXiv preprint arXiv: 2010.00711."},{"key":"e_1_2_11_12_2","unstructured":"ZhangY.andChenX. Explainable Recommendation: A Survey and New Perspectives 2018 arXiv preprint arXiv: 1804.11192."},{"key":"e_1_2_11_13_2","unstructured":"ChoiE. BahadoriM. T. andSchuetzA. et al.RETAIN: Interpretable Predictive Model in Healthcare Using Reverse Time Attention Mechanism 2016 CoRR: abs\/1608.05745."},{"key":"e_1_2_11_14_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2021.115736"},{"key":"e_1_2_11_15_2","unstructured":"ManeS.andRaoD. Explaining Network Intrusion Detection System Using Explainable AI Framework 2021 arXiv preprint arXiv: 2103.07110."},{"key":"e_1_2_11_16_2","unstructured":"LundbergS. M.andLeeS. I. A Unified Approach to Interpreting Model Predictions Proceedings of the 31st International Conference on Neural Information Processing Systems 2017 Curran Associates Inc. 4768\u20134777."},{"key":"e_1_2_11_17_2","doi-asserted-by":"crossref","unstructured":"RibeiroM. T. SinghS. andGuestrinC. Why Should I Trust You?\u201d Explaining the Predictions of any Classifier Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining 2016 Association for Computational Linguistics 1135\u20131144.","DOI":"10.1145\/2939672.2939778"},{"key":"e_1_2_11_18_2","unstructured":"DhurandharA. ChenP. Y. andLussR. et al.Explanations Based on the Missing: Towards Contrastive Explanations With Pertinent Negatives 2018 arXiv preprint arXiv: 1802.07623."},{"key":"e_1_2_11_19_2","doi-asserted-by":"publisher","DOI":"10.1049\/iet-ifs.2018.5258"},{"key":"e_1_2_11_20_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23247"},{"key":"e_1_2_11_21_2","doi-asserted-by":"publisher","DOI":"10.1214\/aos\/1013203451"},{"key":"e_1_2_11_22_2","doi-asserted-by":"publisher","DOI":"10.1145\/3472753"},{"key":"e_1_2_11_23_2","first-page":"258","article-title":"Network Intrusion Detection Using Naive Bayes","volume":"7","author":"Panda M.","year":"2007","journal-title":"International Journal of Computer Science and Network Security"},{"key":"e_1_2_11_24_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2017.09.014"},{"key":"e_1_2_11_25_2","doi-asserted-by":"publisher","DOI":"10.1145\/3178582"},{"key":"e_1_2_11_26_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSMCB.2007.914695"},{"key":"e_1_2_11_27_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.micpro.2023.104964"},{"key":"e_1_2_11_28_2","doi-asserted-by":"publisher","DOI":"10.1109\/TCSS.2022.3164993"},{"key":"e_1_2_11_29_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3118573"},{"key":"e_1_2_11_30_2","doi-asserted-by":"publisher","DOI":"10.1109\/TETCI.2017.2772792"},{"key":"e_1_2_11_31_2","doi-asserted-by":"publisher","DOI":"10.1049\/iet-ifs.2019.0294"},{"key":"e_1_2_11_32_2","doi-asserted-by":"crossref","unstructured":"XiaY. DongS. PengT. andWangT. Wireless Network Abnormal Traffic Detection Method Based on Deep Transfer Reinforcement Learning 2021 17th International Conference on Mobility Sensing and Networking (MSN) 2021 IEEE 528\u2013535.","DOI":"10.1109\/MSN53354.2021.00083"},{"key":"e_1_2_11_33_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2021.3120804"},{"key":"e_1_2_11_34_2","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2013.50"},{"key":"e_1_2_11_35_2","doi-asserted-by":"crossref","unstructured":"HsuY.-F. HeZ. TarutaniY. andMatsuokaM. Toward an Online Network Intrusion Detection System Based on Ensemble Learning IEEE 12th International Conference on Cloud Computing (CLOUD) 2019 IEEE 174\u2013178.","DOI":"10.1109\/CLOUD.2019.00037"},{"key":"e_1_2_11_36_2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.2993410"},{"key":"e_1_2_11_37_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.compeleceng.2022.108025"},{"key":"e_1_2_11_38_2","doi-asserted-by":"publisher","DOI":"10.1007\/s12243-021-00876-6"},{"key":"e_1_2_11_39_2","unstructured":"Doshi-VelezF.andKimB. Towards a Rigorous Science of Interpretable Machine Learning 2017 arXiv preprint arXiv: 1702.08608."},{"key":"e_1_2_11_40_2","doi-asserted-by":"crossref","unstructured":"HariharanS. VelichetiA. AnaghaA. S. ThomasC. andBalakrishnanN. Explainable Artificial Intelligence in Cybersecurity: A Brief Review 2021 4th International Conference on Security and Privacy (ISEA-ISAP) 2021 IEEE 1\u201312.","DOI":"10.1109\/ISEA-ISAP54304.2021.9689765"},{"key":"e_1_2_11_41_2","doi-asserted-by":"crossref","unstructured":"NadeemA. VosD. andCaoC. et al.SoK: Explainable Machine Learning for Computer Security Applications 2023 IEEE 8th European Symposium on Security and Privacy (EuroS&P) 2023 IEEE 221\u2013240.","DOI":"10.1109\/EuroSP57164.2023.00022"},{"key":"e_1_2_11_42_2","unstructured":"MohankumarA. K. NemaP. andNarasimhanS. et al.Towards Transparent and Explainable Attention Models 2020 arXiv preprint arXiv: 2004.14243."},{"key":"e_1_2_11_43_2","doi-asserted-by":"crossref","unstructured":"DuM. LiuN. SongQ. andHuX. Towards Explanation of DNN-Based Prediction With Guided Feature Inversion Proceedings of the 24th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining 2018 Association for Computing Machinery 1358\u20131367.","DOI":"10.1145\/3219819.3220099"},{"key":"e_1_2_11_44_2","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0130140"},{"key":"e_1_2_11_45_2","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2023.3280465"},{"key":"e_1_2_11_46_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.2988359"},{"key":"e_1_2_11_47_2","doi-asserted-by":"publisher","DOI":"10.1109\/OJCOMS.2022.3188750"},{"key":"e_1_2_11_48_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2023.120057"},{"key":"e_1_2_11_49_2","article-title":"Deep Explainable Method for Encrypted Traffic Classification","volume":"43","author":"Cui J.","year":"2023","journal-title":"Journal of Computer Applications"},{"key":"e_1_2_11_50_2","doi-asserted-by":"crossref","unstructured":"HeX. PanJ. andJinO. et al.Practical Lessons From Predicting Clicks on ads at Facebook Proceedings of the Eighth International Workshop on Data Mining for Online Advertising 2014 Association for Computing Machinery 1\u20139.","DOI":"10.1145\/2648584.2648589"},{"key":"e_1_2_11_51_2","doi-asserted-by":"crossref","unstructured":"RendleS. Factorization Machines Proceedings of IEEE International Conference on Data Mining 2010 IEEE.","DOI":"10.1109\/ICDM.2010.127"},{"key":"e_1_2_11_52_2","doi-asserted-by":"crossref","unstructured":"GuoH. TangR. YeY. LiZ. andHeX. DeepFM: A Factorization-Machine Based Neural Network for CTR Prediction 2017 arXiv preprint arXiv: 1703.04247.","DOI":"10.24963\/ijcai.2017\/239"},{"key":"e_1_2_11_53_2","doi-asserted-by":"crossref","unstructured":"ViganoL.andMagazzeniD. Explainable Security IEEE European Symposium on Security and Privacy Workshops (EuroS&PW) 2020 IEEE 293\u2013300.","DOI":"10.1109\/EuroSPW51379.2020.00045"},{"key":"e_1_2_11_54_2","doi-asserted-by":"crossref","unstructured":"ShanY. HoensT. R. JiaoJ. WangH. YuD. andMaoJ. C. Deep Crossing: Web-Scale Modeling Without Manually Crafted Combinatorial Features Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining 2016 Association for Computing Machinery 255\u2013262.","DOI":"10.1145\/2939672.2939704"},{"key":"e_1_2_11_55_2","unstructured":"VaswaniA. ShazeerN. andParmarN. et al.Attention Is All You Need Advances in Neural Information Processing Systems 2017 5998\u20136008."},{"key":"e_1_2_11_56_2","unstructured":"KDD99 1999 http:\/\/kdd.ics.uci.edu\/databases\/kddcup99\/kddcup99.html."},{"key":"e_1_2_11_57_2","unstructured":"NSL-KDD 2019 https:\/\/www.kaggle.com\/datasets\/hassan06\/nslkdd?resource=download."},{"key":"e_1_2_11_58_2","unstructured":"UNSW-NB15 2015 https:\/\/research.unsw.edu.au\/projects\/unsw-nb15-dataset."},{"key":"e_1_2_11_59_2","unstructured":"CIC-IDS2017 2017 https:\/\/www.unb.ca\/cic\/datasets\/ids-2017.html."},{"key":"e_1_2_11_60_2","unstructured":"CICFlowMeter 2019 https:\/\/github.com\/ahlashkari\/CICFlowMeter."},{"key":"e_1_2_11_61_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2959131"},{"key":"e_1_2_11_62_2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2021.3084796"},{"key":"e_1_2_11_63_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2023.119000"},{"key":"e_1_2_11_64_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2023.121751"},{"key":"e_1_2_11_65_2","doi-asserted-by":"crossref","unstructured":"MahmoudM. YoussefY. O. andAbdel-HamidA. An Explainable Intelligent Intrusion Detection System 2024 International Symposium on Networks Computers and Communications (ISNCC) 2024 IEEE 1\u20136.","DOI":"10.1109\/ISNCC62547.2024.10758968"}],"container-title":["IET Information Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/ietresearch.onlinelibrary.wiley.com\/doi\/pdf\/10.1049\/ise2\/5552833","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/ietresearch.onlinelibrary.wiley.com\/doi\/full-xml\/10.1049\/ise2\/5552833","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/ietresearch.onlinelibrary.wiley.com\/doi\/pdf\/10.1049\/ise2\/5552833","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,8]],"date-time":"2026-03-08T22:33:01Z","timestamp":1773009181000},"score":1,"resource":{"primary":{"URL":"https:\/\/ietresearch.onlinelibrary.wiley.com\/doi\/10.1049\/ise2\/5552833"}},"subtitle":[],"editor":[{"given":"Taimur","family":"Bakhshi","sequence":"additional","affiliation":[],"role":[{"role":"editor","vocabulary":"crossref"}]}],"short-title":[],"issued":{"date-parts":[[2025,1]]},"references-count":65,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2025,1]]}},"alternative-id":["10.1049\/ise2\/5552833"],"URL":"https:\/\/doi.org\/10.1049\/ise2\/5552833","archive":["Portico"],"relation":{},"ISSN":["1751-8709","1751-8717"],"issn-type":[{"value":"1751-8709","type":"print"},{"value":"1751-8717","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,1]]},"assertion":[{"value":"2024-08-08","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-09-26","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-10-29","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"5552833"}}