{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,30]],"date-time":"2026-07-30T05:17:22Z","timestamp":1785388642921,"version":"3.55.0"},"reference-count":70,"publisher":"MDPI AG","issue":"3","license":[{"start":{"date-parts":[[2022,2,3]],"date-time":"2022-02-03T00:00:00Z","timestamp":1643846400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>In recent years, many methods for intrusion detection systems (IDS) have been designed and developed in the research community, which have achieved a perfect detection rate using IDS datasets. Deep neural networks (DNNs) are representative examples applied widely in IDS. However, DNN models are becoming increasingly complex in model architectures with high resource computing in hardware requirements. In addition, it is difficult for humans to obtain explanations behind the decisions made by these DNN models using large IoT-based IDS datasets. Many proposed IDS methods have not been applied in practical deployments, because of the lack of explanation given to cybersecurity experts, to support them in terms of optimizing their decisions according to the judgments of the IDS models. This paper aims to enhance the attack detection performance of IDS with big IoT-based IDS datasets as well as provide explanations of machine learning (ML) model predictions. The proposed ML-based IDS method is based on the ensemble trees approach, including decision tree (DT) and random forest (RF) classifiers which do not require high computing resources for training models. In addition, two big datasets are used for the experimental evaluation of the proposed method, NF-BoT-IoT-v2, and NF-ToN-IoT-v2 (new versions of the original BoT-IoT and ToN-IoT datasets), through the feature set of the net flow meter. In addition, the IoTDS20 dataset is used for experiments. Furthermore, the SHapley additive exPlanations (SHAP) is applied to the eXplainable AI (XAI) methodology to explain and interpret the classification decisions of DT and RF models; this is not only effective in interpreting the final decision of the ensemble tree approach but also supports cybersecurity experts in quickly optimizing and evaluating the correctness of their judgments based on the explanations of the results.<\/jats:p>","DOI":"10.3390\/s22031154","type":"journal-article","created":{"date-parts":[[2022,2,6]],"date-time":"2022-02-06T20:40:18Z","timestamp":1644180018000},"page":"1154","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":186,"title":["Classification and Explanation for Intrusion Detection System Based on Ensemble Trees and SHAP Method"],"prefix":"10.3390","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-8366-9396","authenticated-orcid":false,"given":"Thi-Thu-Huong","family":"Le","sequence":"first","affiliation":[{"name":"IoT Research Center, Pusan National University, Busan 609735, Korea"},{"name":"Faculty of Information Technology, Hung Yen University of Technology and Education, Hung Yen 160000, Vietnam"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Haeyoung","family":"Kim","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Pusan National University, Busan 609735, Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9651-7439","authenticated-orcid":false,"given":"Hyoeun","family":"Kang","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Pusan National University, Busan 609735, Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8475-7294","authenticated-orcid":false,"given":"Howon","family":"Kim","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Pusan National University, Busan 609735, Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2022,2,3]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"493","DOI":"10.1007\/s12083-017-0630-0","article-title":"Survey on SDN based network intrusion detection system using machine learning approaches","volume":"12","author":"Sultana","year":"2019","journal-title":"Peer Netw. Appl."},{"key":"ref_2","unstructured":"Lee, W., Stolfo, S.J., and Mok, K.W. (1999, January 14). A data mining framework for building intrusion detection models. Proceedings of the 1999 IEEE Symposium on Security and Privacy, Oakland, CA, USA."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"1153","DOI":"10.1109\/COMST.2015.2494502","article-title":"A survey of data mining and machine learning methods for cyber security intrusion detection","volume":"18","author":"Buczak","year":"2016","journal-title":"IEEE Commun. Surveys Tuts."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"431","DOI":"10.1016\/j.bushor.2015.03.008","article-title":"The internet of things (iot): Applications, investments, and challenges for enterprises","volume":"58","author":"Lee","year":"2015","journal-title":"Bus. Horizons"},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Zhang, Z.K., Cho, M.C.Y., Wang, C.W., Hsu, C.W., Chen, C.K., and Shieh, S. (2014, January 17\u201319). Iot security: Ongoing challenges and research opportunities. Proceedings of the 2014 IEEE 7th International Conference on Service-Oriented Computing and Applications, Matsue, Japan.","DOI":"10.1109\/SOCA.2014.58"},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"10","DOI":"10.1016\/j.jnca.2017.04.002","article-title":"Internet of things security: A survey","volume":"88","author":"Alaba","year":"2017","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_7","unstructured":"Sarica, A.K., and Angin, P. (2020, January 2\u20136). A Novel SDN Dataset for Intrusion Detection in IoT Networks. Proceedings of the 16th International Conference on Network and Service Management (CNSM), Izmir, Turkey."},{"key":"ref_8","unstructured":"Spadaccino, P., and Cuomo, F. Intrusion Detection Systems for IoT: Opportunities and Challenges offered by Edge Computing. arXiv, 1\u201320. Available online: Https:\/\/arxiv.org\/pdf\/2012.01174.pdf."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Amarasinghe, K., Kenney, K., and Manic, M. (2018, January 4\u20136). Toward explainable deep neural network based anomaly detection. Proceedings of the 11th International Conference on Human System Interaction (HSI), Gdansk, Poland.","DOI":"10.1109\/HSI.2018.8430788"},{"key":"ref_10","unstructured":"(2021, December 21). Pycaret Open Source. Available online: Https:\/\/github.com\/pycaret\/pycaret."},{"key":"ref_11","unstructured":"Lundberg, S.M., and Lee, S.I. (2017, January 4\u20139). A unified approach to interpreting model predictions. Proceedings of the 31st International Conference on Neural Information Processing Systems, Long Beach, CA, USA."},{"key":"ref_12","unstructured":"Lundberg, S.M., Erion, G.G., and Lee, S.I. (2018). Consistent individualized feature attribution for tree ensembles. arXiv."},{"key":"ref_13","unstructured":"Heba, F.E., Darwish, A., Hassanien Aboul, E., and Abraham, A. (December, January 29). Principle components analysis and support vector machine based intrusion detection system. Proceedings of the 10th International Conference on Intelligent Systems Design and Applications, Cairo, Egypt."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Jia, N., and Liu, D. (2017). Application of svm based on information entropy in intrusion detection. International Conference on Intelligent and Interactive Systems and Applications, Springer.","DOI":"10.1007\/978-3-319-69096-4_64"},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"130","DOI":"10.1016\/j.knosys.2017.09.014","article-title":"An effective intrusion detection framework based on svm with feature augmentation","volume":"136","author":"Wang","year":"2017","journal-title":"Knowl.-Based Syst."},{"key":"ref_16","unstructured":"Kruegel, C., Mutz, D., Robertson, W., and Valeur, F. (2003, January 8\u201312). Bayesian event classification for intrusion detection. Proceedings of the 19th Annual Computer Security Applications, Washington, DC, USA."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Jemili, F., Zaghdoud, M., and Mohamed, B. (2007). A framework for an adaptive intrusion detection system using Bayesian network. IEEE Intelligence and Security Informatics, IEEE.","DOI":"10.1109\/ISI.2007.379535"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Heckerman, D. (2008). A tutorial on learning with bayesian networks. Innovations in Bayesian Networks, Springer.","DOI":"10.1007\/978-3-540-85066-3_3"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Vigna, G., Kruegel, C., and Jonsson, E. (2003). Using Decision Trees to Improve Signature-Based Intrusion Detection. Recent Advances in Intrusion Detection, Springer.","DOI":"10.1007\/b13476"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Kumar, M., Hanumanthappa, M., and Kumar, T.S. (2012, January 9\u201311). Intrusion Detection System using decision tree algorithm. Proceedings of the IEEE 14th International Conference on Communication Technology, Chengdu, China.","DOI":"10.1109\/ICCT.2012.6511281"},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"4680867","DOI":"10.1155\/2018\/4680867","article-title":"Intrusion Detection System Based on Decision Tree over Big Data in Fog Environment","volume":"2018","author":"Peng","year":"2018","journal-title":"Wirel. Commun. Mob. Comput."},{"key":"ref_22","unstructured":"Alfred, R., Lim, Y., Haviluddin, H., and On, C. (2003). Decision Tree with Sensitive Pruning in Network-based Intrusion Detection System. Computational Science and Technology. Lecture Notes in Electrical Engineering, Springer."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Tesfahun, A., and Bhaskari, D.L. (2013, January 15\u201316). Intrusion Detection Using Random Forests Classifier with SMOTE and Feature Reduction. Proceedings of the 2013 International Conference on Cloud & Ubiquitous Computing & Emerging Technologies, Pune, India.","DOI":"10.1109\/CUBE.2013.31"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"213","DOI":"10.1016\/j.procs.2016.06.047","article-title":"Random Forest Modeling for Network Intrusion Detection System","volume":"89","author":"Farnaaz","year":"2016","journal-title":"Procedia Comput. Sci."},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Aung, Y.Y., and Min, M.M. (2017, January 26\u201328). An analysis of random forest algorithm based network intrusion detection system. Proceedings of the 2017 18th IEEE\/ACIS International Conference on Software Engineering, Artificial Intelligence, Networking and Parallel\/Distributed Computing (SNPD), Kanazawa, Japan.","DOI":"10.1109\/SNPD.2017.8022711"},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Primartha, R., and Tama, B.A. (2017, January 1\u20132). Anomaly detection using random forest: A performance revisited. Proceedings of the 2017 International Conference on Data and Software Engineering (ICoDSE), Palembang, Indonesia.","DOI":"10.1109\/ICODSE.2017.8285847"},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Zhang, H., Dai, S., Li, Y., and Zhang, W. (2018, January 17\u201319). Real-time Distributed-Random-Forest-Based Network Intrusion Detection System Using Apache Spark. Proceedings of the 2018 IEEE 37th International Performance Computing and Communications Conference (IPCCC), Orlando, FL, USA.","DOI":"10.1109\/PCCC.2018.8711068"},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Iman, A.N., and Ahmad, T. (2020, January 20). Improving Intrusion Detection System by Estimating Parameters of Random Forest in Boruta. Proceedings of the 2020 International Conference on Smart Technology and Applications (ICoSTA), Surabaya, Indonesia.","DOI":"10.1109\/ICoSTA48221.2020.1570609975"},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Waskle, S., Parashar, L., and Singh, U. (2020, January 2\u20134). Intrusion Detection System Using PCA with Random Forest Approach. Proceedings of the 2020 International Conference on Electronics and Sustainable Communication Systems (ICESC), Coimbatore, India.","DOI":"10.1109\/ICESC48915.2020.9155656"},{"key":"ref_30","unstructured":"Park, T., Cho, D., and Kim, H. (2018, January 3\u20136). An Effective Classification for DoS Attacks in Wireless Sensor Networks. Proceedings of the 2018 Tenth International Conference on Ubiquitous and Future Networks (ICUFN), Prague, Czech Republic."},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Vigneswaran, R.K., Vinayakumar, R., Soman, K.P., and Poornachandran, P. (2018, January 10\u201312). Evaluating Shallow and Deep Neural Networks for Network Intrusion Detection Systems in Cyber Security. Proceedings of the 2018 9th International Conference on Computing, Communication and Networking Technologies (ICCCNT), Bengaluru, India.","DOI":"10.1109\/ICCCNT.2018.8494096"},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Ieracitano, C., Adeel, A., Gogate, M., Dashtipour, K., Morabito, F.C., Larijani, H., Raza, A., and Hussain, A. (2018, January 7\u20138). Statistical Analysis Driven Optimized Deep Learning System for Intrusion Detection. Proceedings of the 9th International Conference on Brain Inspired Cognitive Systems (BICS 2018), Xi\u2019an, China.","DOI":"10.1007\/978-3-030-00563-4_74"},{"key":"ref_33","first-page":"91","article-title":"Analyzing Effective of Activation Functions on Recurrent Neural Networks for Intrusion Detection","volume":"3","author":"Le","year":"2016","journal-title":"J. Multimed. Inf. Syst."},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Kim, J., Kim, J., Thu, H.L.T., and Kim, H. (2016, January 15\u201317). Long Short Term Memory Recurrent Neural Network Classifier for Intrusion Detection. Proceedings of the 2016 International Conference on Platform Technology and Service (PlatCon), Jeju, Korea.","DOI":"10.1109\/PlatCon.2016.7456805"},{"key":"ref_35","unstructured":"Kim, J., and Kim, H. (2017, January 13\u201315). An Effective Intrusion Detection Classifier Using Long Short-Term Memory with Gradient Descent Optimization. Proceedings of the 2017 International Conference on Platform Technology and Service (PlatCon), Busan, Korea."},{"key":"ref_36","unstructured":"Kang, H., and Kim, H. (2019, January 28\u201330). The Impact of PCA-Scale Improving GRU Performance for Intrusion Detection. Proceedings of the 2019 International Conference on Platform Technology and Service (PlatCon), Jeju, Korea."},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Le, T.-T.-H., Kim, Y., and Kim, H. (2019). Network Intrusion Detection Based on Novel Feature Selection Model and Various Recurrent Neural Networks. Appl. Sci., 9.","DOI":"10.3390\/app9071392"},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Mirsky, Y., Doitshman, T., Elovici, Y., and Shabtai, A. (2018). Kitsune: An Ensemble of Autoencoders for Online Network Intrusion Detection. arXiv.","DOI":"10.14722\/ndss.2018.23204"},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Roopak, M., Tian, G.Y., and Chambers, J. (2020, January 6\u20138). An Intrusion Detection System Against DDoS Attacks in IoT Networks. Proceedings of the 10th Annual Computing and Communication Workshop and Conference (CCWC), Las Vegas, Nevada, USA.","DOI":"10.1109\/CCWC47524.2020.9031206"},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"357","DOI":"10.1016\/j.cose.2011.12.012","article-title":"Toward developing a systematic approach to generate benchmark datasets for intrusion detection","volume":"31","author":"Shiravi","year":"2012","journal-title":"Comput. Secur."},{"key":"ref_41","doi-asserted-by":"crossref","unstructured":"Moustafa, N., and Slay, J. (2015, January 10\u201312). UNSW-NB15: A comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set). Proceedings of the 2015 Military Communications and Information Systems Conference (MilCIS), Canberra, Australia.","DOI":"10.1109\/MilCIS.2015.7348942"},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"Sharafaldin, I., Lashkari, A.H., and Ghorbani, A.A. (2018, January 22\u201324). Toward generating a new intrusion detection dataset and intrusion traffic characterization. Proceedings of the 4th International Conference on Information Systems Security and Privacy (ICISSP 2018), Funchal, Portugal.","DOI":"10.5220\/0006639801080116"},{"key":"ref_43","doi-asserted-by":"crossref","first-page":"779","DOI":"10.1016\/j.future.2019.05.041","article-title":"Towards the development of realistic botnet dataset in the internet of things for network forensic analytics: Bot-iot dataset","volume":"100","author":"Koroniotis","year":"2019","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_44","unstructured":"Moustafa, N. (2019, January 21\u201325). New Generations of Internet of Things Datasets for Cybersecurity Applications based Machine Learning: TON_IoT_Datasets. Proceedings of the eResearch Australasia Conference, Brisbane, Australia."},{"key":"ref_45","doi-asserted-by":"crossref","unstructured":"Sarhan, M., Layeghy, S., Moustafa, N., and Portmann, M. (2020). Netflow datasets for machine learning-based network intrusion detection systems. arXiv.","DOI":"10.1007\/978-3-030-72802-1_9"},{"key":"ref_46","unstructured":"Sarhan, M., Layeghy, S., Moustafa, N., and Portmann, M. (2021). Towards a standard feature set of nids datasets. arXiv."},{"key":"ref_47","unstructured":"Goutte, C., and Zhu, X. (2020). A Scheme for Generating a Dataset for Anomalous Activity Detection in IoT Networks. Advances in Artificial Intelligence, Springer. Lecture Notes in Computer Science."},{"key":"ref_48","doi-asserted-by":"crossref","unstructured":"Ore\u0161ki, D., and Andro\u010dec, D. (October, January 28). Genetic algorithm and artificial neural network for network forensic analytics. Proceedings of the 2020 43rd International Convention on Information, Communication and Electronic Technology (MIPRO), Opatija, Croatia.","DOI":"10.23919\/MIPRO48935.2020.9245140"},{"key":"ref_49","doi-asserted-by":"crossref","first-page":"6689134","DOI":"10.1155\/2020\/6689134","article-title":"Intrusion Detection System for Internet of Things Based on Temporal Convolution Neural Network and Efficient Feature Engineering","volume":"2020","author":"Derhab","year":"2020","journal-title":"Wireless Commun. Mobile Comput."},{"key":"ref_50","doi-asserted-by":"crossref","unstructured":"Bovenzi, G., Aceto, G., Ciuonzo, D., Persico, V., and Pescap\u00e9, A. (2020, January 7\u201311). A Hierarchical Hybrid Intrusion Detection Approach in IoT Scenarios. Proceedings of the GLOBECOM 2020\u20132020 IEEE Global Communications Conference, Taipei, Taiwan.","DOI":"10.1109\/GLOBECOM42002.2020.9348167"},{"key":"ref_51","doi-asserted-by":"crossref","first-page":"77","DOI":"10.1016\/j.icte.2021.04.012","article-title":"Feature selection for intrusion detection system in Internet-of-Things (IoT)","volume":"7","author":"Nimbalkar","year":"2021","journal-title":"ICT Express"},{"key":"ref_52","doi-asserted-by":"crossref","first-page":"9042","DOI":"10.1109\/JIOT.2019.2926365","article-title":"A supervised intrusion detection system for smart home iot devices","volume":"6","author":"Anthi","year":"2019","journal-title":"IEEE Internet Things J."},{"key":"ref_53","doi-asserted-by":"crossref","unstructured":"Injadat, M., Moubayed, A., and Shami, A. (2020, January 14\u201317). Detecting Botnet Attacks in IoT Environments: An Optimized Machine Learning Approach. Proceedings of the 2020 32nd International Conference on Microelectronics (ICM), Aqaba, Jordan.","DOI":"10.1109\/ICM50269.2020.9331794"},{"key":"ref_54","doi-asserted-by":"crossref","unstructured":"Sarhan, M., Layeghy, S., Moustafa, N., Gallagher, M., and Portmann, M. (2021). Feature Extraction for Machine Learning-based Intrusion Detection in IoT Networks. arXiv.","DOI":"10.21203\/rs.3.rs-2035633\/v1"},{"key":"ref_55","doi-asserted-by":"crossref","unstructured":"Lo, W.W., Layeghy, S., Sarhan, M., Gallagher, M., and Portmann, M. (2021). E-GraphSAGE: A Graph Neural Network based Intrusion Detection System. arXiv.","DOI":"10.1109\/NOMS54207.2022.9789878"},{"key":"ref_56","doi-asserted-by":"crossref","unstructured":"Sarhan, M., Layeghy, S., and Portmann, M. (2021). Feature Analysis for ML-based IIoT Intrusion Detection. arXiv.","DOI":"10.21203\/rs.3.rs-2035633\/v1"},{"key":"ref_57","doi-asserted-by":"crossref","unstructured":"Qaddoura, R., Al-Zoubi, A.M., Almomani, I., and Faris, H. (2021). A Multi-Stage Classification Approach for IoT Intrusion Detection Based on Clustering with Oversampling. Appl. Sci., 11.","DOI":"10.3390\/app11073022"},{"key":"ref_58","doi-asserted-by":"crossref","first-page":"5579851","DOI":"10.1155\/2021\/5579851","article-title":"Intrusion Detection System to Advance Internet of Things Infrastructure-Based Deep Learning Algorithms","volume":"2021","author":"Alkahtani","year":"2021","journal-title":"Complexity"},{"key":"ref_59","first-page":"1801","article-title":"Towards Machine Learning Based Intrusion Detection in IoT Networks","volume":"69","author":"Islam","year":"2021","journal-title":"Comput. Mater. Contin."},{"key":"ref_60","doi-asserted-by":"crossref","unstructured":"Song, Y., Hyun, S., and Cheong, Y.-G. (2021). Analysis of Autoencoders for Network Intrusion Detection. Sensors, 21.","DOI":"10.3390\/s21134294"},{"key":"ref_61","first-page":"579","article-title":"Enhancement performance of random forest algorithm via one hot encoding for IoT IDS","volume":"9","author":"Hussein","year":"2021","journal-title":"Period. Eng. Nat. Sci."},{"key":"ref_62","doi-asserted-by":"crossref","first-page":"4225","DOI":"10.1109\/TNSM.2021.3098157","article-title":"XAI Meets Mobile Traffic Classification: Understanding and Improving Multimodal Deep Learning Architectures","volume":"18","author":"Nascita","year":"2021","journal-title":"IEEE Trans. Netw. Service Manag."},{"key":"ref_63","doi-asserted-by":"crossref","unstructured":"Marino, D.L., Wickramasinghe, C.S., and Manic, M. (2018). An Adversarial Approach for Explainable AI in Intrusion Detection Systems. arXiv.","DOI":"10.1109\/IECON.2018.8591457"},{"key":"ref_64","unstructured":"Mane, S., and Rao, D. (2021). Explaining Network Intrusion Detection System Using Explainable AI Framework. arXiv."},{"key":"ref_65","first-page":"3127","article-title":"An Explainable Machine Learning Framework for Intrusion Detection Systems","volume":"8","author":"Wang","year":"2020","journal-title":"IEEE Access"},{"key":"ref_66","doi-asserted-by":"crossref","first-page":"6634811","DOI":"10.1155\/2021\/6634811","article-title":"Explainable Artificial Intelligence (XAI) to Enhance Trust Management in Intrusion Detection Systems Using Decision Tree Model","volume":"2021","author":"Mahbooba","year":"2021","journal-title":"Complexity"},{"key":"ref_67","doi-asserted-by":"crossref","unstructured":"Szczepa\u0144ski, M., Chora\u015b, M., Pawlicki, M., and Kozik, R. (2020, January 19\u201324). Achieving Explainability of Intrusion Detection System by Hybrid Oracle-Explainer Approach. Proceedings of the 2020 International Joint Conference on Neural Networks (IJCNN), Glasgow, UK.","DOI":"10.1109\/IJCNN48605.2020.9207199"},{"key":"ref_68","doi-asserted-by":"crossref","unstructured":"Sarhan, M., Layeghy, S., and Portmann, M. (2021). An Explainable Machine Learning-based Network Intrusion Detection System for Enabling Generalisability in Securing IoT Networks. arXiv.","DOI":"10.21203\/rs.3.rs-2035633\/v1"},{"key":"ref_69","doi-asserted-by":"crossref","unstructured":"Sarhan, M., Layeghy, S., and Portmann, M. (2021). Evaluating Standard Feature Sets Towards Increased Generalisability and Explainability of ML-based Network Intrusion Detection. arXiv.","DOI":"10.1016\/j.bdr.2022.100359"},{"key":"ref_70","doi-asserted-by":"crossref","first-page":"647","DOI":"10.1007\/s10115-013-0679-x","article-title":"Explaining prediction models and individual predictions with feature contributions","volume":"41","author":"Kononenko","year":"2014","journal-title":"Knowl. Inf. Syst."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/3\/1154\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T22:13:21Z","timestamp":1760134401000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/3\/1154"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,2,3]]},"references-count":70,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2022,2]]}},"alternative-id":["s22031154"],"URL":"https:\/\/doi.org\/10.3390\/s22031154","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,2,3]]}}}