{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,10]],"date-time":"2026-07-10T17:21:50Z","timestamp":1783704110961,"version":"3.55.0"},"reference-count":76,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2025,4,24]],"date-time":"2025-04-24T00:00:00Z","timestamp":1745452800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,4,24]],"date-time":"2025-04-24T00:00:00Z","timestamp":1745452800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"name":"Enhanced Mentoring Program with Opportunities for Ways to Excel in Research"},{"name":"1st Year Research Immersion Program (1RIP) grants from the office of the Vice Chancellor for Research at Indiana University-Purdue University Indianapolis."},{"name":"AnalytixIN"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["EURASIP J. on Info. Security"],"abstract":"<jats:title>Abstract<\/jats:title>\n          <jats:p>New research focuses on creating artificial intelligence (AI) solutions for network intrusion detection systems (NIDS), drawing its inspiration from the ever-growing number of intrusions on networked systems, increasing its complexity and intelligibility. Hence, the use of explainable AI (XAI) techniques in real-world intrusion detection systems comes from the requirement to comprehend and elucidate black-box AI models to security analysts. In an effort to meet such requirements, this paper focuses on applying and evaluating white-box XAI techniques (particularly LRP, IG, and DeepLift) for NIDS via an end-to-end framework for neural network models, using three widely used network intrusion datasets (NSL-KDD, CICIDS-2017, and RoEduNet-SIMARGL2021), assessing its global and local scopes, and examining six distinct assessment measures (descriptive accuracy, sparsity, stability, robustness, efficiency, and completeness). We also compare the performance of white-box XAI methods with black-box XAI methods. The results show that using white-box XAI techniques scores high in robustness and completeness, which are crucial metrics for IDS. Moreover, the source codes for the programs developed for our XAI evaluation framework are available to be improved and used by the research community.<\/jats:p>","DOI":"10.1186\/s13635-025-00201-x","type":"journal-article","created":{"date-parts":[[2025,4,24]],"date-time":"2025-04-24T09:28:48Z","timestamp":1745486928000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":13,"title":["A comparative analysis of DNN-based white-box explainable AI methods in network security"],"prefix":"10.1186","volume":"2025","author":[{"given":"Osvaldo","family":"Arreche","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mustafa","family":"Abdallah","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,4,24]]},"reference":[{"issue":"2","key":"201_CR1","doi-asserted-by":"publisher","first-page":"1153","DOI":"10.1109\/COMST.2015.2494502","volume":"18","author":"AL Buczak","year":"2015","unstructured":"A.L. Buczak, E. Guven, A survey of data mining and machine learning methods for cyber security intrusion detection. IEEE Commun. Surv. Tutor. 18(2), 1153\u20131176 (2015)","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"201_CR2","doi-asserted-by":"crossref","unstructured":"A.S. Dina, D.\u00a0Manivannan, Intrusion detection based on machine learning techniques in computer networks. Internet Things. 16, 100462 (2021)","DOI":"10.1016\/j.iot.2021.100462"},{"issue":"3","key":"201_CR3","doi-asserted-by":"publisher","first-page":"44","DOI":"10.3390\/fi12030044","volume":"12","author":"MA Ferrag","year":"2020","unstructured":"M.A. Ferrag, L. Maglaras, A. Ahmim, M. Derdour, H. Janicke, Rdtids: Rules and decision tree-based intrusion detection system for internet-of-things networks. Futur. Internet. 12(3), 44 (2020)","journal-title":"Futur. Internet."},{"issue":"2","key":"201_CR4","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s10922-021-09591-y","volume":"29","author":"M Al-Omari","year":"2021","unstructured":"M. Al-Omari, M. Rawashdeh, F. Qutaishat, M. Alshira\u2019H, N. Ababneh, An intelligent tree-based intrusion detection model for cyber security. J. Netw. Syst. Manag. 29(2), 1\u201318 (2021)","journal-title":"J. Netw. Syst. Manag."},{"key":"201_CR5","doi-asserted-by":"crossref","unstructured":"N.B. Amor, S. Benferhat, Z. Elouedi, In Proceedings of the 2004 ACM symposium on Applied computing, Naive bayes vs decision trees in intrusion detection systems (Association for Computing Machinery, New York, NY, USA, 2004), pp.420\u2013424","DOI":"10.1145\/967900.967989"},{"key":"201_CR6","doi-asserted-by":"publisher","first-page":"133","DOI":"10.1016\/j.comcom.2022.03.009","volume":"188","author":"R Panigrahi","year":"2022","unstructured":"R. Panigrahi, S. Borah, M. Pramanik, A.K. Bhoi, P. Barsocchi, S.R. Nayak, W. Alnumay, Intrusion detection in cyber-physical environment using hybrid na\u00efve bayes\u2014decision table and multi-objective evolutionary feature selection. Comput. Commun. 188, 133\u2013144 (2022)","journal-title":"Comput. Commun."},{"key":"201_CR7","doi-asserted-by":"publisher","first-page":"4059","DOI":"10.1109\/JIOT.2022.3203249","volume":"10","author":"S Arisdakessian","year":"2022","unstructured":"S. Arisdakessian, O.A. Wahab, A. Mourad, H. Otrok, M. Guizani, A survey on iot intrusion detection: Federated learning, game theory, social psychology and explainable ai as future directions. IEEE Internet Things J. 10, 4059\u20134092 (2022)","journal-title":"IEEE Internet Things J."},{"key":"201_CR8","unstructured":"S.I. Sabev, Integrated approach to cyber defence: Human in the loop. technical evaluation report. Inf. Secur. Int. J. 44, 76\u201392 (2020)"},{"key":"201_CR9","unstructured":"A.\u00a0Das, P.\u00a0Rad, Opportunities and challenges in explainable artificial intelligence (xai): A survey (2020). arXiv preprint arXiv:2006.11371"},{"key":"201_CR10","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1155\/2021\/6634811","volume":"2021","author":"B Mahbooba","year":"2021","unstructured":"B. Mahbooba, M. Timilsina, R. Sahal, M. Serrano, Explainable artificial intelligence (xai) to enhance trust management in intrusion detection systems using decision tree model. Complexity. 2021, 1\u201311 (2021)","journal-title":"Complexity."},{"issue":"19","key":"201_CR11","doi-asserted-by":"publisher","first-page":"3079","DOI":"10.3390\/electronics11193079","volume":"11","author":"S Patil","year":"2022","unstructured":"S. Patil, V. Varadarajan, S.M. Mazhar, A. Sahibzada, N. Ahmed, O. Sinha, S. Kumar, K. Shaw, K. Kotecha, Explainable artificial intelligence for intrusion detection system. Electronics 11(19), 3079 (2022)","journal-title":"Electronics"},{"key":"201_CR12","unstructured":"S.R. Islam, W.\u00a0Eberle, S.K. Ghafoor, A.\u00a0Siraj, M.\u00a0Rogers, Domain knowledge aided explainable artificial intelligence for intrusion detection and response (2019). arXiv preprint arXiv:1911.09853"},{"key":"201_CR13","doi-asserted-by":"crossref","unstructured":"E.\u00a0Roponena, J.\u00a0Kampars, J.\u00a0Grabis, A.\u00a0Gail\u012btis, in CEUR Workshop Proceedings, Towards a human-in-the-loop intelligent intrusion detection system (Baltic DB&IS 2022 Doctoral Consortium and Forum,\u00a0University in Riga, Latvia, 2022), pp. 71\u201381","DOI":"10.22364\/bjmc.2022.10.4.06"},{"key":"201_CR14","doi-asserted-by":"crossref","unstructured":"D.\u00a0Han, Z.\u00a0Wang, W.\u00a0Chen, K.\u00a0Wang, R.\u00a0Yu, S.\u00a0Wang, H.\u00a0Zhang, Z.\u00a0Wang, M.\u00a0Jin, J.\u00a0Yang, et\u00a0al., in 30th Annual Network and Distributed System Security Symposium (NDSS), Anomaly detection in the open world: Normality shift detection, explanation, and adaptation (NDSS Symposium 2023,\u00a0San Diego, California, 2023)","DOI":"10.14722\/ndss.2023.24830"},{"issue":"6","key":"201_CR15","first-page":"446","volume":"4","author":"L Dhanabal","year":"2015","unstructured":"L. Dhanabal, S. Shantharajah, A study on nsl-kdd dataset for intrusion detection system based on classification algorithms. Int. J. Adv. Res. Comput. Commun. Eng. 4(6), 446\u2013452 (2015)","journal-title":"Int. J. Adv. Res. Comput. Commun. Eng."},{"key":"201_CR16","unstructured":"J.\u00a0Dieber, S.\u00a0Kirrane, Why model why? assessing the strengths and limitations of lime (2020). arXiv preprint arXiv:2012.00093"},{"key":"201_CR17","doi-asserted-by":"crossref","unstructured":"A.\u00a0Warnecke, D.\u00a0Arp, C.\u00a0Wressnegger, K.\u00a0Rieck, in 2020 IEEE european symposium on security and privacy (EuroS &P), Evaluating explanation methods for deep learning in security (IEEE, 2020), pp. 158\u2013174","DOI":"10.1109\/EuroSP48549.2020.00018"},{"key":"201_CR18","doi-asserted-by":"crossref","unstructured":"M.T. Ribeiro, S.\u00a0Singh, C.\u00a0Guestrin, \u201cwhy should I trust you?\u201d: Explaining the predictions of any classifier. CoRR. abs\/1602.04938 (2016). arXiv:1602.04938","DOI":"10.18653\/v1\/N16-3020"},{"issue":"1","key":"201_CR19","doi-asserted-by":"publisher","first-page":"2522","DOI":"10.1038\/s42256-019-0138-9","volume":"2","author":"SM Lundberg","year":"2020","unstructured":"S.M. Lundberg, G. Erion, H. Chen, A. DeGrave, J.M. Prutkin, B. Nair, R. Katz, J. Himmelfarb, N. Bansal, S.I. Lee, From local explanations to global understanding with explainable ai for trees. Nat. Mach. Intell. 2(1), 2522\u20135839 (2020)","journal-title":"Nat. Mach. Intell."},{"key":"201_CR20","unstructured":"M.\u00a0Sundararajan, A.\u00a0Taly, Q.\u00a0Yan, in Proceedings of the 34th International Conference on Machine Learning, Proceedings of Machine Learning Research, ed. by D.\u00a0Precup, Y.W. Teh, Axiomatic attribution for deep networks, vol.\u00a070 (PMLR, 2017), pp. 3319\u20133328. https:\/\/proceedings.mlr.press\/v70\/sundararajan17a.html"},{"issue":"2","key":"201_CR21","doi-asserted-by":"publisher","first-page":"44","DOI":"10.1609\/aimag.v40i2.2850","volume":"40","author":"D Gunning","year":"2019","unstructured":"D. Gunning, D. Aha, Darpa\u2019s explainable artificial intelligence (xai) program. AI Mag. 40(2), 44\u201358 (2019). https:\/\/doi.org\/10.1609\/aimag.v40i2.2850","journal-title":"AI Mag."},{"key":"201_CR22","unstructured":"A.\u00a0Shrikumar, P.\u00a0Greenside, A.\u00a0Kundaje, in Proceedings of the 34th International Conference on Machine Learning, Proceedings of Machine Learning Research, vol.\u00a070, ed. by D.\u00a0Precup, Y.W. Teh, Learning important features through propagating activation differences (PMLR, 2017), pp. 3145\u20133153. https:\/\/proceedings.mlr.press\/v70\/shrikumar17a.html"},{"key":"201_CR23","unstructured":"S.M. Lundberg, S.I. Lee, in Advances in Neural Information Processing Systems, vol.\u00a030, ed. by I.\u00a0Guyon, U.V. Luxburg, S.\u00a0Bengio, H.\u00a0Wallach, R.\u00a0Fergus, S.\u00a0Vishwanathan, R.\u00a0Garnett, A unified approach to interpreting model predictions (Curran Associates, Inc., 2017). https:\/\/proceedings.neurips.cc\/paper_files\/paper\/2017\/file\/8a20a8621978632d76c43dfd28b67767-Paper.pdf"},{"key":"201_CR24","unstructured":"A.\u00a0Shrikumar, P.\u00a0Greenside, A.\u00a0Kundaje, Learning important features through propagating activation differences. CoRR. abs\/1704.02685 (2017). arXiv:1704.02685"},{"key":"201_CR25","doi-asserted-by":"publisher","first-page":"23954","DOI":"10.1109\/ACCESS.2024.3365140","volume":"12","author":"O Arreche","year":"2024","unstructured":"O. Arreche, T.R. Guntur, J.W. Roberts, M. Abdallah, E-xai: Evaluating black-box explainable ai frameworks for network intrusion detection. IEEE Access 12, 23954\u201323988 (2024). https:\/\/doi.org\/10.1109\/ACCESS.2024.3365140","journal-title":"IEEE Access"},{"key":"201_CR26","doi-asserted-by":"crossref","unstructured":"D.\u00a0Slack, S.\u00a0Hilgard, E.\u00a0Jia, S.\u00a0Singh, H.\u00a0Lakkaraju, in Proceedings of the AAAI\/ACM Conference on AI, Ethics, and Society, Fooling lime and shap: Adversarial attacks on post hoc explanation methods (Association for Computing Machinery,\u00a0New York, NY, USA, 2020), pp. 180\u2013186","DOI":"10.1145\/3375627.3375830"},{"issue":"13","key":"201_CR27","doi-asserted-by":"publisher","first-page":"4319","DOI":"10.3390\/s21134319","volume":"21","author":"ME Mihailescu","year":"2021","unstructured":"M.E. Mihailescu, D. Mihai, M. Carabas, M. Komisarek, M. Pawlicki, W. Ho\u0142ubowicz, R. Kozik, The proposition and evaluation of the roedunet-simargl2021 network intrusion detection dataset. Sensors. 21(13), 4319 (2021)","journal-title":"Sensors."},{"key":"201_CR28","unstructured":"R.\u00a0Panigrahi, S.\u00a0Borah, A detailed analysis of cicids2017 dataset for designing intrusion detection systems. Int. J. Eng. Technol. 7(3.24), 479\u2013482 (2018)"},{"key":"201_CR29","doi-asserted-by":"publisher","first-page":"112392","DOI":"10.1109\/ACCESS.2022.3216617","volume":"10","author":"S Neupane","year":"2022","unstructured":"S. Neupane, J. Ables, W. Anderson, S. Mittal, S. Rahimi, I. Banicescu, M. Seale, Explainable intrusion detection systems (x-ids): A survey of current methods, challenges, and opportunities. IEEE Access. 10, 112392\u2013112415 (2022). (IEEE)","journal-title":"IEEE Access."},{"key":"201_CR30","doi-asserted-by":"publisher","unstructured":"W.\u00a0Saeed, C.\u00a0Omlin, Explainable ai (xai): A systematic meta-survey of current challenges and future opportunities. Knowl.-Based Syst. 263, 110273 (2023). https:\/\/doi.org\/10.1016\/j.knosys.2023.110273","DOI":"10.1016\/j.knosys.2023.110273"},{"key":"201_CR31","unstructured":"A.\u00a0Das, P.\u00a0Rad. Opportunities and challenges in explainable artificial intelligence (xai): A survey (2020). arXiv:2006.11371"},{"key":"201_CR32","doi-asserted-by":"publisher","unstructured":"R.\u00a0Dwivedi, D.\u00a0Dave, H.\u00a0Naik, S.\u00a0Singhal, R.\u00a0Omer, P.\u00a0Patel, B.\u00a0Qian, Z.\u00a0Wen, T.\u00a0Shah, G.\u00a0Morgan, R.\u00a0Ranjan, Explainable ai (xai): Core ideas, techniques, and solutions. ACM Comput. Surv. 55(9) (2023). https:\/\/doi.org\/10.1145\/3561048","DOI":"10.1145\/3561048"},{"key":"201_CR33","doi-asserted-by":"publisher","unstructured":"A.\u00a0Barredo Arrieta, N.\u00a0D\u00edaz-Rodr\u00edguez, J.\u00a0Del Ser, A.\u00a0Bennetot, S.\u00a0Tabik, A.\u00a0Barbado, S.\u00a0Garcia, S.\u00a0Gil-Lopez, D.\u00a0Molina, R.\u00a0Benjamins, R.\u00a0Chatila, F.\u00a0Herrera, Explainable artificial intelligence (xai): Concepts, taxonomies, opportunities and challenges toward responsible ai. Inf. Fusion. 58, 82\u2013115 (2020). https:\/\/doi.org\/10.1016\/j.inffus.2019.12.012","DOI":"10.1016\/j.inffus.2019.12.012"},{"issue":"11","key":"201_CR34","doi-asserted-by":"publisher","first-page":"4793","DOI":"10.1109\/tnnls.2020.3027314","volume":"32","author":"E Tjoa","year":"2021","unstructured":"E. Tjoa, C. Guan, A survey on explainable artificial intelligence (xai): Toward medical xai. IEEE Trans. Neural Netw. Learn. Syst. 32(11), 4793\u20134813 (2021). https:\/\/doi.org\/10.1109\/tnnls.2020.3027314","journal-title":"IEEE Trans. Neural Netw. Learn. Syst."},{"key":"201_CR35","doi-asserted-by":"publisher","unstructured":"Z.A.E. Houda, B. Brik, L. Khoukhi, \u201cwhy should i trust your ids?\u201d: An explainable deep learning framework for intrusion detection systems in internet of things networks. IEEE Open J. Commun. Soc. 3, 1164\u20131176 (2022). https:\/\/doi.org\/10.1109\/OJCOMS.2022.3188750","DOI":"10.1109\/OJCOMS.2022.3188750"},{"issue":"2","key":"201_CR36","doi-asserted-by":"publisher","first-page":"20","DOI":"10.1109\/IOTM.005.2200028","volume":"5","author":"ZA El Houda","year":"2022","unstructured":"Z.A. El Houda, B. Brik, S.M. Senouci, A novel iot-based explainable deep learning framework for intrusion detection systems. IEEE Internet Things Mag. 5(2), 20\u201323 (2022). https:\/\/doi.org\/10.1109\/IOTM.005.2200028","journal-title":"IEEE Internet Things Mag."},{"key":"201_CR37","doi-asserted-by":"publisher","unstructured":"D.\u00a0Han, Z.\u00a0Wang, W.\u00a0Chen, Y.\u00a0Zhong, S.\u00a0Wang, H.\u00a0Zhang, J.\u00a0Yang, X.\u00a0Shi, X.\u00a0Yin. Deepaid: Interpreting and improving deep learning-based anomaly detection in security applications (Association for Computing Machinery,\u00a0New York, NY, USA, 2021),\u00a09781450384544. https:\/\/doi.org\/10.1145\/3460120.3484589","DOI":"10.1145\/3460120.3484589"},{"key":"201_CR38","doi-asserted-by":"crossref","unstructured":"Y.\u00a0Mirsky, T.\u00a0Doitshman, Y.\u00a0Elovici, A.\u00a0Shabtai. Kitsune: An ensemble of autoencoders for online network intrusion detection (2018),\u00a01802.09089.\u00a0arXiv.\u00a0cs.CR. https:\/\/arxiv.org\/abs\/1802.09089","DOI":"10.14722\/ndss.2018.23204"},{"key":"201_CR39","doi-asserted-by":"publisher","unstructured":"C. Wu, A. Qian, X. Dong, Y. Zhang, in 2020 International Symposium on Theoretical Aspects of Software Engineering (TASE), Feature-oriented design of visual analytics system for interpretable deep learning based intrusion detection (2020), pp. 73\u201380. https:\/\/doi.org\/10.1109\/TASE49443.2020.00019","DOI":"10.1109\/TASE49443.2020.00019"},{"key":"201_CR40","doi-asserted-by":"publisher","first-page":"73127","DOI":"10.1109\/ACCESS.2020.2988359","volume":"8","author":"M Wang","year":"2020","unstructured":"M. Wang, K. Zheng, Y. Yang, X. Wang, An explainable machine learning framework for intrusion detection systems. IEEE Access. 8, 73127\u201373141 (2020). https:\/\/doi.org\/10.1109\/ACCESS.2020.2988359","journal-title":"IEEE Access."},{"key":"201_CR41","unstructured":"B.E. Strom, A. Applebaum, D.P. Miller, K.C. Nickels, A.G. Pennington, C.B. Thomas, in Technical report, Mitre att &ck: Design and philosophy (The MITRE Corporation, 2018)"},{"key":"201_CR42","doi-asserted-by":"publisher","unstructured":"Y.\u00a0Chen, Q.\u00a0Lin, W.\u00a0Wei, J.\u00a0Ji, K.C. Wong, C.A. Coello\u00a0Coello, Intrusion detection using multi-objective evolutionary convolutional neural network for internet of things in fog computing. Knowl.-Based Syst. 244, 108505 (2022). https:\/\/doi.org\/10.1016\/j.knosys.2022.108505","DOI":"10.1016\/j.knosys.2022.108505"},{"key":"201_CR43","doi-asserted-by":"crossref","unstructured":"V.\u00a0Gorodetski, I.\u00a0Kotenko, in International Workshop on Recent Advances in Intrusion Detection, Attacks against computer network: Formal grammar-based framework and simulation tool (Springer, 2002), pp. 219\u2013238","DOI":"10.1007\/3-540-36084-0_12"},{"key":"201_CR44","doi-asserted-by":"crossref","unstructured":"M.\u00a0Skwarek, M.\u00a0Korczynski, W.\u00a0Mazurczyk, A.\u00a0Duda, in 2019 IEEE Security and Privacy Workshops (SPW), Characterizing vulnerability of dns axfr transfers with global-scale scanning (IEEE, 2019), pp. 193\u2013198","DOI":"10.1109\/SPW.2019.00044"},{"key":"201_CR45","volume-title":"Detection and characterization of port scan attacks","author":"CB Lee","year":"2003","unstructured":"C.B. Lee, C. Roedel, E. Silenok, Detection and characterization of port scan attacks (Univeristy of California, Department of Computer Science and Engineering, 2003)"},{"key":"201_CR46","doi-asserted-by":"publisher","unstructured":"Kurniabudi, D.\u00a0Stiawan, Darmawijoyo, M.Y. Bin\u00a0Idris, A.M. Bamhdi, R.\u00a0Budiarto, Cicids-2017 dataset feature analysis with information gain for anomaly detection. IEEE Access. 8, 132911\u2013132921 (2020). https:\/\/doi.org\/10.1109\/ACCESS.2020.3009843","DOI":"10.1109\/ACCESS.2020.3009843"},{"key":"201_CR47","doi-asserted-by":"publisher","unstructured":"M.E. Mihailescu, D.\u00a0Mihai, M.\u00a0Carabas, M.\u00a0Komisarek, M.\u00a0Pawlicki, W.\u00a0Ho\u0142ubowicz, R.\u00a0Kozik, The proposition and evaluation of the roedunet-simargl2021 network intrusion detection dataset. Sensors. 21(13) (2021). https:\/\/doi.org\/10.3390\/s21134319","DOI":"10.3390\/s21134319"},{"key":"201_CR48","unstructured":"D.\u00a0by\u00a0Comprmoise. Drive-by Compromise (2023). https:\/\/attack.mitre.org\/techniques\/T1189\/. Accessed 21 Oct 2023"},{"key":"201_CR49","doi-asserted-by":"crossref","unstructured":"B.\u00a0Stone-Gross, M.\u00a0Cova, L.\u00a0Cavallaro, B.\u00a0Gilbert, M.\u00a0Szydlowski, R.\u00a0Kemmerer, C.\u00a0Kruegel, G.\u00a0Vigna, in Proceedings of the 16th ACM conference on Computer and communications security, Your botnet is my botnet: analysis of a botnet takeover (2009), pp. 635\u2013647","DOI":"10.1145\/1653662.1653738"},{"key":"201_CR50","unstructured":"A.\u00a0Khan, H.\u00a0Kim, B.\u00a0Lee, M2mon: Building an mmio-based security reference monitor for unmanned vehicles,\u00a030th USENIX Security Symposium (USENIX Security 21) (USENIX Association, 2021), pp. 285--302. 978-1-939133-24-3. https:\/\/www.usenix.org\/conference\/usenixsecurity21\/presentation\/khan-arslan"},{"key":"201_CR51","doi-asserted-by":"crossref","unstructured":"S.R. Hussain, I.\u00a0Karim, A.A. Ishtiaq, O.\u00a0Chowdhury, E.\u00a0Bertino, in Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security, Noncompliance as deviant behavior: An automated black-box noncompliance checker for 4g lte cellular devices (Association for Computing Machinery,\u00a0New York, NY, USA, 2021), pp. 1082\u20131099","DOI":"10.1145\/3460120.3485388"},{"key":"201_CR52","doi-asserted-by":"crossref","unstructured":"O.\u00a0Mirzaei, R.\u00a0Vasilenko, E.\u00a0Kirda, L.\u00a0Lu, A.\u00a0Kharraz, in Detection of Intrusions and Malware, and Vulnerability Assessment: 18th International Conference, DIMVA 2021, Virtual Event, July 14\u201316, 2021, Proceedings 18, Scrutinizer: Detecting code reuse in malware via decompilation and machine learning (Springer, 2021), pp. 130\u2013150","DOI":"10.1007\/978-3-030-80825-9_7"},{"key":"201_CR53","unstructured":"S.\u00a0Lukacs, D.H. Lutas, A.V. COLESA, et\u00a0al. Strongly isolated malware scanning using secure virtual containers (Google Patents, 2015). US Patent 9,117,081"},{"key":"201_CR54","doi-asserted-by":"publisher","first-page":"70245","DOI":"10.1109\/ACCESS.2020.2986882","volume":"8","author":"A Kim","year":"2020","unstructured":"A. Kim, M. Park, D.H. Lee, Ai-ids: Application of deep learning to real-time web intrusion detection. IEEE Access. 8, 70245\u201370261 (2020)","journal-title":"IEEE Access."},{"key":"201_CR55","doi-asserted-by":"publisher","first-page":"102287","DOI":"10.1016\/j.cose.2021.102287","volume":"106","author":"M Botacin","year":"2021","unstructured":"M. Botacin, F. Ceschin, R. Sun, D. Oliveira, A. Gr\u00e9gio, Challenges and pitfalls in malware research. Comput. Secur. 106, 102287 (2021)","journal-title":"Comput. Secur."},{"key":"201_CR56","doi-asserted-by":"publisher","unstructured":"C.O. Retzlaff, A. Angerschmid, A. Saranti, D. Schneeberger, R. R\u00f6ttger, H. M\u00fcller, A. Holzinger, Post-hoc vs ante-hoc explanations: xai design guidelines for data scientists. Cogn. Syst. Res. 86, 101243 (2024). https:\/\/doi.org\/10.1016\/j.cogsys.2024.101243","DOI":"10.1016\/j.cogsys.2024.101243"},{"key":"201_CR57","unstructured":"I.\u00a0Amit, J.\u00a0Matherly, W.\u00a0Hewlett, Z.\u00a0Xu, Y.\u00a0Meshi, Y.\u00a0Weinberger, Machine learning in cyber-security - problems, challenges and data sets (2018). arXiv:1812.07858"},{"key":"201_CR58","doi-asserted-by":"publisher","first-page":"93575","DOI":"10.1109\/ACCESS.2022.3204171","volume":"10","author":"N Capuano","year":"2022","unstructured":"N. Capuano, G. Fenza, V. Loia, C. Stanzione, Explainable artificial intelligence in cybersecurity: A survey. IEEE Access. 10, 93575\u201393600 (2022)","journal-title":"IEEE Access."},{"key":"201_CR59","unstructured":"Flow information elements - nprobe 10.1 documentation. https:\/\/www.ntop.org\/guides\/nprobe\/flow_information_elements.html.\u00a0Accessed 20 Jul 2024"},{"key":"201_CR60","unstructured":"Ahlashkari. Cicflowmeter\/readme.txt. (2021). https:\/\/github.com\/ahlashkari\/CICFlowMeter\/blob\/master\/ReadMe.txt.\u00a0Access 20 Jul 2024"},{"key":"201_CR61","doi-asserted-by":"publisher","unstructured":"M.\u00a0Tavallaee, E.\u00a0Bagheri, W.\u00a0Lu, A.A. Ghorbani, in 2009 IEEE Symposium on Computational Intelligence for Security and Defense Applications, A detailed analysis of the kdd cup 99 data set (2009), pp. 1\u20136. https:\/\/doi.org\/10.1109\/CISDA.2009.5356528","DOI":"10.1109\/CISDA.2009.5356528"},{"key":"201_CR62","doi-asserted-by":"publisher","unstructured":"R.\u00a0ZHAO. Nsl-kdd (2022). https:\/\/doi.org\/10.21227\/8rpg-qt98","DOI":"10.21227\/8rpg-qt98"},{"key":"201_CR63","doi-asserted-by":"crossref","unstructured":"B. Claise, Cisco systems netflow services export version 9.\u00a0Technical Report\u00a0(2004)","DOI":"10.17487\/rfc3954"},{"issue":"1","key":"201_CR64","first-page":"177","volume":"2018","author":"I Sharafaldin","year":"2018","unstructured":"I. Sharafaldin, A. Gharib, A.H. Lashkari, A.A. Ghorbani, Towards a reliable intrusion detection benchmark dataset. Softw. Netw. 2018(1), 177\u2013200 (2018)","journal-title":"Softw. Netw."},{"key":"201_CR65","doi-asserted-by":"publisher","unstructured":"C.A. Stewart, V.\u00a0Welch, B.\u00a0Plale, G.C. Fox, M.\u00a0Pierce, T.\u00a0Sterling, Indiana university pervasive technology institute (2017). https:\/\/doi.org\/10.5072\/FK2154N14D","DOI":"10.5072\/FK2154N14D"},{"key":"201_CR66","unstructured":"S.\u00a0Lundberg. shap.DeepExplainer (2018). https:\/\/shap.readthedocs.io\/en\/latest\/generated\/shap.DeepExplainer.html. Accessed 2w Feb 2025"},{"key":"201_CR67","unstructured":"Y.\u00a0Dong, W.\u00a0Guo, Y.\u00a0Chen, X.\u00a0Xing, Towards the detection of inconsistencies in public security vulnerability reports,\u00a028th USENIX Security Symposium (USENIX Security 19) (USENIX Association,\u00a0Santa Clara, CA, 2019), pp.\u00a0869--885.\u00a0978-1-939133-06-9. https:\/\/www.usenix.org\/conference\/usenixsecurity19\/presentation\/dong"},{"key":"201_CR68","unstructured":"U.T. Repository. UMass Trace Repository (2021). http:\/\/traces.cs.umass.edu\/index.php\/Network\/Network. Accessed 21 Nov 2022"},{"key":"201_CR69","doi-asserted-by":"crossref","unstructured":"N.\u00a0Moustafa, J.\u00a0Slay, in 2015 military communications and information systems conference (MilCIS), Unsw-nb15: a comprehensive data set for network intrusion detection systems (unsw-nb15 network data set) (IEEE, 2015), pp. 1\u20136","DOI":"10.1109\/MilCIS.2015.7348942"},{"key":"201_CR70","unstructured":"P.J. Kindermans, K.T. Sch\u00fctt, M.\u00a0Alber, K.R. M\u00fcller, D.\u00a0Erhan, B.\u00a0Kim, S.\u00a0D\u00e4hne. Learning how to explain neural networks: Patternnet and patternattribution (2017). arXiv:1705.05598"},{"key":"201_CR71","doi-asserted-by":"crossref","unstructured":"M.D. Zeiler, R.\u00a0Fergus. Visualizing and understanding convolutional networks (2013). arXiv:1311.2901","DOI":"10.1007\/978-3-319-10590-1_53"},{"key":"201_CR72","unstructured":"J.T. Springenberg, A.\u00a0Dosovitskiy, T.\u00a0Brox, M.\u00a0Riedmiller. Striving for simplicity: The all convolutional net (2015). arXiv:1412.6806"},{"key":"201_CR73","doi-asserted-by":"publisher","unstructured":"B.\u00a0Zhou, A.\u00a0Khosla, A.\u00a0Lapedriza, A.\u00a0Oliva, A.\u00a0Torralba, in 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), Learning deep features for discriminative localization (2016), pp. 2921\u20132929. https:\/\/doi.org\/10.1109\/CVPR.2016.319","DOI":"10.1109\/CVPR.2016.319"},{"key":"201_CR74","doi-asserted-by":"publisher","unstructured":"R.R. Selvaraju, M.\u00a0Cogswell, A.\u00a0Das, R.\u00a0Vedantam, D.\u00a0Parikh, D.\u00a0Batra, in 2017 IEEE International Conference on Computer Vision (ICCV), Grad-cam: Visual explanations from deep networks via gradient-based localization (2017), pp. 618\u2013626. https:\/\/doi.org\/10.1109\/ICCV.2017.74","DOI":"10.1109\/ICCV.2017.74"},{"key":"201_CR75","doi-asserted-by":"publisher","unstructured":"A.\u00a0Chattopadhay, A.\u00a0Sarkar, P.\u00a0Howlader, V.N. Balasubramanian, in 2018 IEEE Winter Conference on Applications of Computer Vision (WACV), Grad-cam++: Generalized gradient-based visual explanations for deep convolutional networks (2018), pp. 839\u2013847. https:\/\/doi.org\/10.1109\/WACV.2018.00097","DOI":"10.1109\/WACV.2018.00097"},{"key":"201_CR76","doi-asserted-by":"publisher","unstructured":"O.\u00a0Arreche, T.\u00a0Guntur, M.\u00a0Abdallah, Xai-ids: Toward proposing an explainable artificial intelligence framework for enhancing network intrusion detection systems. Appl. Sci. 14(10) (2024). https:\/\/doi.org\/10.3390\/app14104170","DOI":"10.3390\/app14104170"}],"container-title":["EURASIP Journal on Information Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s13635-025-00201-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s13635-025-00201-x\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s13635-025-00201-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,4,24]],"date-time":"2025-04-24T09:29:06Z","timestamp":1745486946000},"score":1,"resource":{"primary":{"URL":"https:\/\/jis-eurasipjournals.springeropen.com\/articles\/10.1186\/s13635-025-00201-x"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,4,24]]},"references-count":76,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["201"],"URL":"https:\/\/doi.org\/10.1186\/s13635-025-00201-x","relation":{},"ISSN":["2510-523X"],"issn-type":[{"value":"2510-523X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,4,24]]},"assertion":[{"value":"31 March 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"9 April 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"24 April 2025","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"Not applicable.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics approval and consent to participate"}},{"value":"The authors give permission for this work to be published in the EURASIP Journal on Information Security, and other publications produced by the EURASIP Journal on Information Security, in print and online.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent for publication"}},{"value":"The authors declare that they have no competing interests.","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"16"}}