{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,23]],"date-time":"2026-07-23T14:31:00Z","timestamp":1784817060983,"version":"3.55.0"},"reference-count":50,"publisher":"MDPI AG","issue":"5","license":[{"start":{"date-parts":[[2025,4,25]],"date-time":"2025-04-25T00:00:00Z","timestamp":1745539200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Computers"],"abstract":"<jats:p>The increase in malicious cyber activities has generated the need to produce effective tools for the field of digital forensics and incident response. Artificial intelligence (AI) and its fields, specifically machine learning (ML) and deep learning (DL), have shown great potential to aid the task of processing and analyzing large amounts of information. However, models generated by DL are often considered \u201cblack boxes\u201d, a name derived due to the difficulties faced by users when trying to understand the decision-making process for obtaining results. This research seeks to address the challenges of transparency, explainability, and reliability posed by black-box models in digital forensics. To accomplish this, explainable artificial intelligence (XAI) is explored as a solution. This approach seeks to make DL models more interpretable and understandable by humans. The SHAP (SHapley Additive eXplanations) and LIME (Local Interpretable Model-agnostic Explanations) methods will be implemented and evaluated as a model-agnostic technique to explain predictions of the generated models for forensic analysis. By applying these methods to the XGBoost and TabNet models trained on the UNSW-NB15 dataset, the results indicated distinct global feature importance rankings between the model types and revealed greater consistency of local explanations for the tree-based XGBoost model compared to the deep learning-based TabNet. This study aims to make the decision-making process in these models transparent and to assess the confidence and consistency of XAI-generated explanations in a forensic context.<\/jats:p>","DOI":"10.3390\/computers14050160","type":"journal-article","created":{"date-parts":[[2025,4,25]],"date-time":"2025-04-25T08:57:47Z","timestamp":1745571467000},"page":"160","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":13,"title":["Use of Explainable Artificial Intelligence for Analyzing and Explaining Intrusion Detection Systems"],"prefix":"10.3390","volume":"14","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5775-6536","authenticated-orcid":false,"given":"Pamela","family":"Hermosilla","sequence":"first","affiliation":[{"name":"Escuela de Ingenier\u00eda Inform\u00e1tica, Pontificia Universidad Cat\u00f3lica de Valpara\u00edso, Valpara\u00edso 2362807, Chile"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mauricio","family":"D\u00edaz","sequence":"additional","affiliation":[{"name":"Escuela de Ingenier\u00eda Inform\u00e1tica, Pontificia Universidad Cat\u00f3lica de Valpara\u00edso, Valpara\u00edso 2362807, Chile"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-9384-2515","authenticated-orcid":false,"given":"Sebasti\u00e1n","family":"Berr\u00edos","sequence":"additional","affiliation":[{"name":"Escuela de Ingenier\u00eda Inform\u00e1tica, Pontificia Universidad Cat\u00f3lica de Valpara\u00edso, Valpara\u00edso 2362807, Chile"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9899-0051","authenticated-orcid":false,"given":"H\u00e9ctor","family":"Allende-Cid","sequence":"additional","affiliation":[{"name":"Escuela de Ingenier\u00eda Inform\u00e1tica, Pontificia Universidad Cat\u00f3lica de Valpara\u00edso, Valpara\u00edso 2362807, Chile"},{"name":"Knowledge Discovery, Fraunhofer-Institute of Intelligent Analysis and Information Systems (IAIS), 53757 Sankt Augustin, Germany"},{"name":"Lamarr Institute for Machine Learning and Artificial Intelligence, 44227 Dortmund, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2025,4,25]]},"reference":[{"key":"ref_1","unstructured":"Fleck, A. (2025, March 02). Infographic: Cybercrime Expected To Skyrocket in Coming Years. Available online: https:\/\/www.statista.com\/chart\/28878\/expected-cost-of-cybercrime-until-2027\/."},{"key":"ref_2","first-page":"78","article-title":"Emerging trends in cybercrime and their impact on digital security","volume":"15","author":"Sharma","year":"2022","journal-title":"Cybersecur. Rev."},{"key":"ref_3","unstructured":"Stallings, W. (2023). Cyber Attacks and Countermeasures, Pearson."},{"key":"ref_4","unstructured":"National Institute of Standards and Technology (2016). Digital Evidence, NIST."},{"key":"ref_5","first-page":"1","article-title":"Digital forensics: Science and technology of the 21st century","volume":"15","author":"Casey","year":"2018","journal-title":"J. Digit. Investig."},{"key":"ref_6","first-page":"110235","article-title":"Artificial Intelligence in digital forensics: Opportunities and challenges","volume":"310","author":"Lin","year":"2020","journal-title":"Forensic Sci. Int."},{"key":"ref_7","first-page":"201","article-title":"Machine learning for digital forensics: A systematic review","volume":"38","author":"Taylor","year":"2021","journal-title":"Digit. Investig."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Maratsi, M.I., Popov, O., Alexopoulos, C., and Charalabidis, Y. (2022, January 4\u20137). Ethical and Legal Aspects of Digital Forensics Algorithms: The Case of Digital Evidence Acquisition. Proceedings of the 15th International Conference on Theory and Practice of Electronic Governance, Guimar\u00e3es, Portugal.","DOI":"10.1145\/3560107.3560114"},{"key":"ref_9","unstructured":"Association of Chief Police Officers (ACPO) (2021). Principles for digital evidence in criminal investigations. Digit. Crime J., 12, 45\u201350."},{"key":"ref_10","first-page":"889","article-title":"The Artificial Intelligence Black Box and the Failure of Intent and Causation","volume":"31","author":"Bathaee","year":"2018","journal-title":"Harv. J. Law Technol."},{"key":"ref_11","unstructured":"Defense Advanced Research Projects Agency (DARPA) (2023). Addressing the black-box problem in AI systems. AI Rev., 34, 12\u201320."},{"key":"ref_12","first-page":"112","article-title":"Legal challenges in using AI-generated evidence in courts","volume":"29","author":"Calderon","year":"2022","journal-title":"Leg. Stud. J."},{"key":"ref_13","first-page":"215","article-title":"AI explainability: Legal requirements and SHAP\u2019s role in meeting them","volume":"2","author":"Adadi","year":"2021","journal-title":"AI Ethics"},{"key":"ref_14","unstructured":"IBM (2024). What Is Explainable AI, IBM. Available online: https:\/\/www.ibm.com\/topics\/explainable-ai."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Carvalho, D.V., Pereira, E.M., and Cardoso, J.S. (2019). Machine Learning Interpretability: A Survey on Methods and Metrics. Electronics, 8.","DOI":"10.3390\/electronics8080832"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"52138","DOI":"10.1109\/ACCESS.2018.2870052","article-title":"Peeking inside the black-box: A survey on Explainable Artificial Intelligence (XAI)","volume":"6","author":"Adadi","year":"2018","journal-title":"IEEE Access"},{"key":"ref_17","first-page":"1","article-title":"The role of explainability in artificial intelligence research","volume":"8","author":"Guidotti","year":"2019","journal-title":"AI Ethics"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.artint.2018.07.007","article-title":"Explanation in artificial intelligence: Insights from the social sciences","volume":"267","author":"Miller","year":"2019","journal-title":"Artif. Intell."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"82","DOI":"10.1016\/j.inffus.2019.12.012","article-title":"Explainable Artificial Intelligence (XAI): Concepts, taxonomies, opportunities and challenges toward responsible AI","volume":"58","author":"Arrieta","year":"2020","journal-title":"Inf. Fusion"},{"key":"ref_20","unstructured":"Doshi-Velez, F., and Kim, B. (2017). Towards A Rigorous Science of Interpretable Machine Learning. arXiv."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Molnar, C. (2019). Interpretable Machine Learning, Github.","DOI":"10.21105\/joss.00786"},{"key":"ref_22","first-page":"99","article-title":"Scalable LIME: Enhancing interpretability for massive datasets","volume":"7","author":"Mishra","year":"2023","journal-title":"Big Data Cogn. Comput."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Ribeiro, M.T., Singh, S., and Guestrin, C. (2016). \u201cWhy Should I Trust You?\u201d: Explaining the Predictions of Any Classifier. arXiv.","DOI":"10.18653\/v1\/N16-3020"},{"key":"ref_24","first-page":"210","article-title":"Explainable AI for tree-based models with SHAP and LIME: A comprehensive review","volume":"21","author":"Lundberg","year":"2020","journal-title":"J. Mach. Learn. Res."},{"key":"ref_25","first-page":"2151","article-title":"Model-agnostic interpretability techniques: A survey on LIME and SHAP applications","volume":"55","author":"Zhou","year":"2022","journal-title":"Artif. Intell. Rev."},{"key":"ref_26","first-page":"4","article-title":"Explainable AI: Interpretable models and beyond","volume":"77","author":"Guidotti","year":"2021","journal-title":"Inf. Fusion"},{"key":"ref_27","first-page":"356","article-title":"Interpretable machine learning: Advances in LIME for high-dimensional data","volume":"39","author":"Yang","year":"2023","journal-title":"J. Comput. Intell."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"307","DOI":"10.2307\/1911238","article-title":"Monotonic Solutions to General Cooperative Games","volume":"53","author":"Kalai","year":"1985","journal-title":"Econometrica"},{"key":"ref_29","unstructured":"Lundberg, S., and Lee, S.I. (2017). A Unified Approach to Interpreting Model Predictions. arXiv."},{"key":"ref_30","first-page":"18702","article-title":"Many Shapley value methods: A unified perspective and comparison","volume":"33","author":"Sundararajan","year":"2020","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref_31","unstructured":"Molnar, C. (2022). Interpretable Machine Learning: A Guide for Making Black Box Models Explainable, Leanpub."},{"key":"ref_32","first-page":"65","article-title":"SHAP explanations in financial AI: A review of applications and challenges","volume":"3","author":"Zhang","year":"2021","journal-title":"J. Financ. Data Sci."},{"key":"ref_33","first-page":"22","article-title":"AI explainability in healthcare: Integrating SHAP for enhanced trust and usability","volume":"5","author":"Chen","year":"2023","journal-title":"Healthc. Anal."},{"key":"ref_34","first-page":"112","article-title":"SHAP compliance in regulatory AI systems: A case study","volume":"12","author":"Yang","year":"2023","journal-title":"J. Artif. Intell. Regul."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"18","DOI":"10.1080\/19393555.2015.1125974","article-title":"The evaluation of Network Anomaly Detection Systems: Statistical analysis of the UNSW-NB15 data set and the comparison with the KDD99 data set","volume":"25","author":"Moustafa","year":"2016","journal-title":"Inf. Secur. J. Glob. Perspect."},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Moustafa, N., and Slay, J. (2015, January 10\u201312). UNSW-NB15: A comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set). Proceedings of the 2015 Military Communications and Information Systems Conference (MilCIS), Canberra, ACT, Australia.","DOI":"10.1109\/MilCIS.2015.7348942"},{"key":"ref_37","first-page":"148","article-title":"A new framework for evaluating cybersecurity solutions in smart cities","volume":"123","author":"Moustafa","year":"2021","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"National Center for Biotechnology Information (2025). Optimizing IoT Intrusion Detection Using Balanced Class Distribution. Sensors, 24, 4293.","DOI":"10.3390\/s24134293"},{"key":"ref_39","first-page":"e3","article-title":"Classification of UNSW-NB15 dataset using Exploratory Data Analysis and Ensemble Learning","volume":"8","author":"Sharma","year":"2021","journal-title":"EAI Endorsed Trans. Ind. Netw. Intell. Syst."},{"key":"ref_40","unstructured":"Zoghi, Z., and Serpen, G. (2021). UNSW-NB15 Computer Security Dataset: Analysis through Visualization. arXiv."},{"key":"ref_41","first-page":"102195","article-title":"UNSW-NB15 dataset: Modernized network traffic benchmark for intrusion detection systems","volume":"104","author":"Moustafa","year":"2021","journal-title":"Comput. Secur."},{"key":"ref_42","first-page":"210","article-title":"Analyzing UNSW-NB15 for Intrusion Detection in Modern Networks","volume":"5","author":"Zaman","year":"2023","journal-title":"Cybersecur. Netw."},{"key":"ref_43","first-page":"103123","article-title":"Evaluation of machine learning models using data splits: A practical approach","volume":"67","author":"Wang","year":"2022","journal-title":"J. Inf. Secur. Appl."},{"key":"ref_44","first-page":"58","article-title":"Benchmarking datasets and methods for cybersecurity applications: An overview","volume":"3","author":"Elrawy","year":"2021","journal-title":"Cyber Threat Intell. Rev."},{"key":"ref_45","first-page":"88","article-title":"Feature selection techniques for improving machine learning models in cybersecurity","volume":"8","author":"Mohamed","year":"2022","journal-title":"Cybersecur. Strateg."},{"key":"ref_46","first-page":"44","article-title":"Robust feature selection methods for modern ML systems: A comparative study","volume":"12","author":"Singh","year":"2023","journal-title":"Adv. Comput. Res."},{"key":"ref_47","first-page":"199","article-title":"Machine learning approaches for anomaly detection in network security","volume":"4","author":"Gupta","year":"2023","journal-title":"Cybersecur. Adv."},{"key":"ref_48","doi-asserted-by":"crossref","unstructured":"Husain, A., Salem, A., Jim, C., and Dimitoglou, G. (2019, January 10\u201312). Development of an Efficient Network Intrusion Detection Model Using Extreme Gradient Boosting (XGBoost) on the UNSW-NB15 Dataset. Proceedings of the 2019 IEEE International Symposium on Signal Processing and Information Technology (ISSPIT), Ajman, United Arab Emirates.","DOI":"10.1109\/ISSPIT47144.2019.9001867"},{"key":"ref_49","unstructured":"Arik, S.O., and Pfister, T. (2019). TabNet: Attentive Interpretable Tabular Learning. arXiv."},{"key":"ref_50","doi-asserted-by":"crossref","first-page":"56","DOI":"10.1038\/s42256-019-0138-9","article-title":"From local explanations to global understanding with explainable AI for trees","volume":"2","author":"Lundberg","year":"2020","journal-title":"Nat. Mach. Intell."}],"container-title":["Computers"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2073-431X\/14\/5\/160\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T17:21:38Z","timestamp":1760030498000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2073-431X\/14\/5\/160"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,4,25]]},"references-count":50,"journal-issue":{"issue":"5","published-online":{"date-parts":[[2025,5]]}},"alternative-id":["computers14050160"],"URL":"https:\/\/doi.org\/10.3390\/computers14050160","relation":{},"ISSN":["2073-431X"],"issn-type":[{"value":"2073-431X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,4,25]]}}}