{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,2]],"date-time":"2026-06-02T20:34:50Z","timestamp":1780432490560,"version":"3.54.1"},"reference-count":46,"publisher":"MDPI AG","issue":"3","license":[{"start":{"date-parts":[[2025,9,5]],"date-time":"2025-09-05T00:00:00Z","timestamp":1757030400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100000038","name":"Natural Sciences and Engineering Research Council of Canada (NSERC)","doi-asserted-by":"publisher","award":["RGPIN-2017-04755"],"award-info":[{"award-number":["RGPIN-2017-04755"]}],"id":[{"id":"10.13039\/501100000038","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JCP"],"abstract":"<jats:p>Modern network intrusion detection systems (NIDSs) rely on complex deep learning models. However, the \u201cblack-box\u201d nature of deep learning methods hinders transparency and trust in predictions, preventing the timely implementation of countermeasures against intrusion attacks. Although explainable AI (XAI) methods provide a solution to this problem by providing insights into the reasons behind the predictions, the explanations provided by the majority of them cannot be trivially converted into actionable countermeasures. In this work, we propose a novel tabular diffusion-based counterfactual explanation framework that can provide actionable explanations for network intrusion attacks. We evaluated our proposed algorithm against several other publicly available counterfactual explanation algorithms on three modern network intrusion datasets. To the best of our knowledge, this work also presents the first comparative analysis of the existing counterfactual explanation algorithms within the context of NIDSs. Our proposed method provides plausible and diverse counterfactual explanations more efficiently than the tested counterfactual algorithms, reducing the time required to generate explanations. We also demonstrate how the proposed method can provide actionable explanations for NIDSs by summarizing them into a set of actionable global counterfactual rules, which effectively filter out incoming attack queries. This ability of the rules is crucial for efficient intrusion detection and defense mechanisms. We have made our implementation publicly available on GitHub.<\/jats:p>","DOI":"10.3390\/jcp5030068","type":"journal-article","created":{"date-parts":[[2025,9,5]],"date-time":"2025-09-05T12:18:18Z","timestamp":1757074698000},"page":"68","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["Novel Actionable Counterfactual Explanations for Intrusion Detection Using Diffusion Models"],"prefix":"10.3390","volume":"5","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2650-797X","authenticated-orcid":false,"given":"Vinura","family":"Galwaduge","sequence":"first","affiliation":[{"name":"Department of Electrical and Computer Engineering, University of Western Ontario, London, ON N6A 5B9, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-5871-6548","authenticated-orcid":false,"given":"Jagath","family":"Samarabandu","sequence":"additional","affiliation":[{"name":"Department of Electrical and Computer Engineering, University of Western Ontario, London, ON N6A 5B9, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2025,9,5]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"102767","DOI":"10.1016\/j.jnca.2020.102767","article-title":"Deep learning methods in network intrusion detection: A survey and an objective comparison","volume":"169","author":"Gamage","year":"2020","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"181","DOI":"10.1016\/j.icte.2025.01.005","article-title":"Deep learning-driven methods for network-based intrusion detection systems: A systematic review","volume":"11","author":"Chinnasamy","year":"2025","journal-title":"ICT Express"},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"1164","DOI":"10.1109\/OJCOMS.2022.3188750","article-title":"\u201cWhy Should I Trust Your IDS?\u201d: An Explainable Deep Learning Framework for Intrusion Detection Systems in Internet of Things Networks","volume":"3","author":"Houda","year":"2022","journal-title":"IEEE Open J. Commun. Soc."},{"key":"ref_4","unstructured":"Guyon, I., Luxburg, U.V., Bengio, S., Wallach, H., Fergus, R., Vishwanathan, S., and Garnett, R. (2017). A Unified Approach to Interpreting Model Predictions. Advances in Neural Information Processing Systems, Curran Associates, Inc."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"186","DOI":"10.1109\/MNET.001.1900252","article-title":"AI-Driven Zero Touch Network and Service Management in 5G and Beyond: Challenges and Research Directions","volume":"34","author":"Benzaid","year":"2020","journal-title":"IEEE Netw."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Wachter, S., Mittelstadt, B., and Russell, C. (2018). Counterfactual Explanations without Opening the Black Box: Automated Decisions and the GDPR. arXiv.","DOI":"10.2139\/ssrn.3063289"},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"2770","DOI":"10.1007\/s10618-022-00831-6","article-title":"Counterfactual explanations and how to find them: Literature review and benchmarking","volume":"38","author":"Guidotti","year":"2022","journal-title":"Data Min. Knowl. Discov."},{"key":"ref_8","unstructured":"Verma, S., Dickerson, J.P., and Hines, K. (2020). Counterfactual Explanations for Machine Learning: A Review. arXiv."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"11974","DOI":"10.1109\/ACCESS.2021.3051315","article-title":"A Survey of Contrastive and Counterfactual Explanation Generation Methods for Explainable Artificial Intelligence","volume":"9","author":"Stepin","year":"2021","journal-title":"IEEE Access"},{"key":"ref_10","unstructured":"Pawelczyk, M., Broelemann, K., and Kasneci, G. (2020, January 3\u20136). On Counterfactual Explanations under Predictive Multiplicity. Proceedings of the 36th Conference on Uncertainty in Artificial Intelligence (UAI), PMLR, Virtual."},{"key":"ref_11","unstructured":"Gupta, V., Nokhiz, P., Roy, C.D., and Venkatasubramanian, S. (2019). Equalizing Recourse across Groups. arXiv."},{"key":"ref_12","unstructured":"Krause, A., Brunskill, E., Cho, K., Engelhardt, B., Sabato, S., and Scarlett, J. (2023, January 23\u201329). TabDDPM: Modelling Tabular Data with Diffusion Models. Proceedings of the 40th International Conference on Machine Learning, PMLR, Honolulu, HI, USA."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"59","DOI":"10.1016\/j.inffus.2021.11.003","article-title":"Counterfactuals and causability in explainable artificial intelligence: Theory, algorithms, and applications","volume":"81","author":"Chou","year":"2022","journal-title":"Inf. Fusion"},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Leemann, T., Pawelczyk, M., Prenkaj, B., and Kasneci, G. (2024). Towards Non-Adversarial Algorithmic Recourse. arXiv.","DOI":"10.1007\/978-3-031-63800-8_20"},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"e70113","DOI":"10.1111\/coin.70113","article-title":"Taming the Triangle: On the Interplays Between Fairness, Interpretability, and Privacy in Machine Learning","volume":"41","author":"Ferry","year":"2025","journal-title":"Comput. Intell."},{"key":"ref_16","unstructured":"(2025, August 16). General Data Protection Regulation (GDPR)\u2013Legal Text\u2014gdpr-info.eu. Available online: https:\/\/gdpr-info.eu\/."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"93104","DOI":"10.1109\/ACCESS.2022.3204051","article-title":"Explainable Artificial Intelligence Applications in Cyber Security: State-of-the-Art in Research","volume":"10","author":"Zhang","year":"2022","journal-title":"IEEE Access"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"83","DOI":"10.1007\/s43926-025-00184-8","article-title":"Explainable AI for Zero-Day Attack Detection in IoT Networks Using Attention Fusion Model","volume":"5","author":"Krishnan","year":"2025","journal-title":"Discov. Internet Things"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"119000","DOI":"10.1016\/j.ins.2023.119000","article-title":"An explainable deep learning-enabled intrusion detection framework in IoT networks","volume":"639","author":"Keshk","year":"2023","journal-title":"Inf. Sci."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"1775","DOI":"10.1109\/COMST.2023.3280465","article-title":"Explainable Intrusion Detection for Cyber Defences in the Internet of Things: Opportunities and Solutions","volume":"25","author":"Moustafa","year":"2023","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"167","DOI":"10.1109\/LNET.2022.3186589","article-title":"Robust Network Intrusion Detection Through Explainable Artificial Intelligence (XAI)","volume":"4","author":"Barnard","year":"2022","journal-title":"IEEE Netw. Lett."},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Kalakoti, R., Vaarandi, R., Bahsi, H., and N\u00f5mm, S. (2025). Evaluating Explainable AI for Deep Learning-Based Network Intrusion Detection System Alert Classification. arXiv.","DOI":"10.5220\/0013180700003899"},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"e496","DOI":"10.1002\/spy2.496","article-title":"Enhancing Intrusion Detection Systems with Advanced Machine Learning Techniques: An Ensemble and Explainable Artificial Intelligence (AI) Approach","volume":"8","year":"2025","journal-title":"Secur. Priv."},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"23954","DOI":"10.1109\/ACCESS.2024.3365140","article-title":"E-XAI: Evaluating Black-Box Explainable AI Frameworks for Network Intrusion Detection","volume":"12","author":"Arreche","year":"2024","journal-title":"IEEE Access"},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Dietz, K., Hajizadeh, M., Schleicher, J., Wehner, N., Gei\u00dfler, S., Casas, P., Seufert, M., and Ho\u00dffeld, T. (2024, January 28\u201331). Agree to Disagree: Exploring Consensus of XAI Methods for ML-based NIDS. Proceedings of the 2024 20th International Conference on Network and Service Management (CNSM), Prague, Czech Republic.","DOI":"10.23919\/CNSM62983.2024.10814448"},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Marino, D.L., Wickramasinghe, C.S., and Manic, M. (2018, January 21\u201323). An Adversarial Approach for Explainable AI in Intrusion Detection Systems. Proceedings of the IECON 2018\u201444th Annual Conference of the IEEE Industrial Electronics Society, Washington, DC, USA.","DOI":"10.1109\/IECON.2018.8591457"},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"34613","DOI":"10.1109\/ACCESS.2022.3162588","article-title":"Robust Botnet DGA Detection: Blending XAI and OSINT for Cyber Threat Intelligence Sharing","volume":"10","author":"Suryotrisongko","year":"2022","journal-title":"IEEE Access"},{"key":"ref_28","first-page":"103124","article-title":"Intrusion detection framework based on causal reasoning for DDoS","volume":"65","author":"Zeng","year":"2022","journal-title":"J. Inf. Secur. Appl."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Gyawali, S., Huang, J., and Jiang, Y. (2024, January 23\u201326). Leveraging Explainable AI for Actionable Insights in IoT Intrusion Detection. Proceedings of the 2024 19th Annual System of Systems Engineering Conference (SoSE), Tacoma, WA, USA.","DOI":"10.1109\/SOSE62659.2024.10620966"},{"key":"ref_30","unstructured":"Evangelatos, S., Veroni, E., Efthymiou, V., Nikolopoulos, C., Papadopoulos, G.T., and Sarigiannidis, P. (2025). Exploring Energy Landscapes for Minimal Counterfactual Explanations: Applications in Cybersecurity and Beyond. arXiv."},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Amini, M.R., Canu, S., Fischer, A., Guns, T., Kralj Novak, P., and Tsoumakas, G. (2022, January 19\u201323). VCNet: A Self-explaining Model for Realistic Counterfactual Generation. Proceedings of the Machine Learning and Knowledge Discovery in Databases, Grenoble, France.","DOI":"10.1007\/978-3-031-26387-3"},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Guo, H., Nguyen, T.H., and Yadav, A. (2023, January 6\u201310). CounterNet: End-to-End Training of Prediction Aware Counterfactual Explanations. Proceedings of the KDD \u201923: 29th ACM SIGKDD Conference on Knowledge Discovery and Data Mining, Long Beach, CA, USA.","DOI":"10.1145\/3580305.3599290"},{"key":"ref_33","unstructured":"Dhariwal, P., and Nichol, A. (2021). Diffusion Models Beat GANs on Image Synthesis. arXiv."},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Madaan, N., and Bedathur, S. (2023). Navigating the Structured What-If Spaces: Counterfactual Generation via Structured Diffusion. arXiv.","DOI":"10.1109\/SaTML59370.2024.00041"},{"key":"ref_35","unstructured":"Salimans, T., and Ho, J. (2022, January 25\u201329). Progressive Distillation for Fast Sampling of Diffusion Models. Proceedings of the The Tenth International Conference on Learning Representations, ICLR 2022, Virtual Event."},{"key":"ref_36","first-page":"6840","article-title":"Denoising Diffusion Probabilistic Models","volume":"Volume 33","author":"Larochelle","year":"2020","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref_37","first-page":"12454","article-title":"Argmax Flows and Multinomial Diffusion: Learning Categorical Distributions","volume":"Volume 34","author":"Ranzato","year":"2021","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Moustafa, N., and Slay, J. (2015, January 10\u201312). UNSW-NB15: A comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set). Proceedings of the 2015 Military Communications and Information Systems Conference (MilCIS), Canberra, Australia.","DOI":"10.1109\/MilCIS.2015.7348942"},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Sharafaldin, I., Habibi Lashkari, A., and Ghorbani, A.A. (2018, January 22\u201324). Toward Generating a New Intrusion Detection Dataset and Intrusion Traffic Characterization. Proceedings of the 4th International Conference on Information Systems Security and Privacy, Funchal, Madeira, Portugal.","DOI":"10.5220\/0006639801080116"},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Sharafaldin, I., Lashkari, A.H., Hakak, S., and Ghorbani, A.A. (2019, January 1\u20133). Developing Realistic Distributed Denial of Service (DDoS) Attack Dataset and Taxonomy. Proceedings of the 2019 International Carnahan Conference on Security Technology (ICCST), Chennai, India.","DOI":"10.1109\/CCST.2019.8888419"},{"key":"ref_41","doi-asserted-by":"crossref","unstructured":"Mothilal, R.K., Sharma, A., and Tan, C. (2020, January 27\u201330). Explaining Machine Learning Classifiers through Diverse Counterfactual Explanations. Proceedings of the 2020 Conference on Fairness, Accountability, and Transparency, Barcelona, Spain.","DOI":"10.1145\/3351095.3372850"},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"Poyiadzi, R., Sokol, K., Santos-Rodriguez, R., De Bie, T., and Flach, P. (2020, January 27\u201330). FACE: Feasible and Actionable Counterfactual Explanations. Proceedings of the AAAI\/ACM Conference on AI, Ethics, and Society, Barcelona, Spain.","DOI":"10.1145\/3375627.3375850"},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Pawelczyk, M., Broelemann, K., and Kasneci, G. (2020, January 20\u201324). Learning Model-Agnostic Counterfactual Explanations for Tabular Data. Proceedings of the WWW \u201920: The Web Conference 2020, Taipei, Taiwan.","DOI":"10.1145\/3366423.3380087"},{"key":"ref_44","unstructured":"Pawelczyk, M., Bielawski, S., den Heuvel, J.V., Richter, T., and Kasneci, G. (2021, January 6\u201314). CARLA: A Python Library to Benchmark Algorithmic Recourse and Counterfactual Explanation Algorithms. Proceedings of the Thirty-Fifth Conference on Neural Information Processing Systems Datasets and Benchmarks Track (Round 1), Virtual."},{"key":"ref_45","first-page":"145","article-title":"Benchmarking Instance-Centric Counterfactual Algorithms for XAI: From White Box to Black Box","volume":"57","author":"Moreira","year":"2024","journal-title":"Acm Comput. Surv."},{"key":"ref_46","doi-asserted-by":"crossref","first-page":"137683","DOI":"10.1109\/ACCESS.2024.3410540","article-title":"Evaluation of Instance-Based Explanations: An In-Depth Analysis of Counterfactual Evaluation Metrics, Challenges, and the CEval Toolkit","volume":"12","author":"Bayrak","year":"2024","journal-title":"IEEE Access"}],"container-title":["Journal of Cybersecurity and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/3\/68\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T18:40:05Z","timestamp":1760035205000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/3\/68"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9,5]]},"references-count":46,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2025,9]]}},"alternative-id":["jcp5030068"],"URL":"https:\/\/doi.org\/10.3390\/jcp5030068","relation":{},"ISSN":["2624-800X"],"issn-type":[{"value":"2624-800X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,9,5]]}}}