International Journal of Innovative Research in Computer and Communication Engineering

ISSN Approved Journal | Impact factor: 8.771 | ESTD: 2013 | Follows UGC CARE Journal Norms and Guidelines

| Monthly, Peer-Reviewed, Refereed, Scholarly, Multidisciplinary and Open Access Journal | High Impact Factor 8.771 (Calculated by Google Scholar and Semantic Scholar | AI-Powered Research Tool | Indexing in all Major Database & Metadata, Citation Generator | Digital Object Identifier (DOI) |


TITLE XAI-driven False Positive Filtering in Anomaly-Based Intrusion Detection System
ABSTRACT As dependence on online platforms grows for accessing and managing sensitive information, Intrusion Detection Systems (IDS) are now recognized as a crucial part of contemporary cybersecurity structures. The rapid advancement of machine learning, combined with access to extensive network traffic datasets, has greatly enhanced anomaly-based intrusion detection research; however, a persistent challenge in these systems is the frequent occurrence of incorrect alerts, which reduces the reliability and efficiency of security monitoring. This work introduces an enhanced method for detecting false positives by combining Explainable Artificial Intelligence (XAI) with conventional machine learning models. Rather than relying solely on prediction confidence, the proposed method analyses the relevance of input features contributing to each decision using SHAP and LIME, and trains a dedicated post-processing false positive detector on the extracted feature-importance patterns. The approach is evaluated on the LYCOS-IDS2017 dataset using Random Forest, K-Nearest Neighbors, Decision Tree, Naive Bayes, Neural Network, Voting Classifier and Stacking Classifier. Experimental results demonstrate that incorporating XAI-based feature relevance significantly improves the identification of false positives while maintaining a minimal reduction in true positives, outperforming conventional confidence-based filtering, which eliminates approximately 50% of false positives at the cost of a 0.42% loss in true positives.
AUTHOR MAMIDALA LIKHITHA, DR. M. DHANALAKSHMI Post Graduate Student, Department of Computer Science and Engineering, Jawaharlal Nehru Technological University, Hyderabad, India Professor, Department of Computer Science and Engineering, Jawaharlal Nehru Technological University, Hyderabad, India
VOLUME 187
DOI DOI: 10.15680/IJIRCCE.2026.1408010
PDF pdf/10_XAI-driven False Positive Filtering in Anomaly-Based Intrusion Detection System.pdf
KEYWORDS
References [1] Lippmann, R., et al., “The 1999 DARPA Off-Line Intrusion Detection Evaluation,” Computer Networks, vol. 34, no. 4, pp. 579–595, 2000.
[2] Spathoulas, G. P., and S. K. Katsikas, “Reducing False Positives in Intrusion Detection Systems,” Computers & Security, vol. 29, no. 1, pp. 35–44, 2010.
[3] Kim, D., et al., “A Cost-Effective Method for Evaluating AI Prediction Reliability in Intrusion Detection Using Explainable AI,” IEEE Access, 2022.
[4] Sommer, R., and V. Paxson, “Outside the Closed World: On Using Machine Learning for Network Intrusion Detection,” IEEE Symposium on Security and Privacy, pp. 305–316, 2010.
[5] Nisioti, A., A. Mylonas, P. D. Yoo, and V. Katos, “From Intrusion Detection to Attacker Attribution: A Comprehensive Survey of Unsupervised Methods,” IEEE Communications Surveys & Tutorials, vol. 20, no. 4, pp. 3369–3388, 2018.
[6] Viegas, E., A. Santin, and L. Oliveira, “Toward a Reliable Anomaly-Based Intrusion Detection in Real-World Environments,” Computer Networks, vol. 127, pp. 200–216, 2017.
[7] Ring, M., S. Wunderlich, D. Scheuring, D. Landes, and A. Hotho, “A Survey of Network-Based Intrusion Detection Data Sets,” Computers & Security, vol. 86, pp. 147–167, 2019.
[8] Lundberg, S. M., and S.-I. Lee, “A Unified Approach to Interpreting Model Predictions,” Advances in Neural Information Processing Systems (NeurIPS), vol. 30, 2017.
[9] Shapley, L. S., “A Value for n-Person Games,” Contributions to the Theory of Games, vol. 2, no. 28, pp. 307–317, 1953.
[10] Ribeiro, M. T., S. Singh, and C. Guestrin, “‘Why Should I Trust You?’: Explaining the Predictions of Any Classifier,” Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, pp. 1135–1144, 2016.
[11] Marino, D. L., C. S. Wickramasinghe, and M. Manic, “An Adversarial Approach for Explainable AI in Intrusion Detection Systems,” Proceedings of IECON 2018 - 44th Annual Conference of the IEEE Industrial Electronics Society, pp. 3237–3243, 2018.
[12] Shrikumar, A., P. Greenside, A. Shcherbina, and A. Kundaje, “Not Just a Black Box: Learning Important Features Through Propagating Activation Differences,” arXiv:1605.01713, 2016.
[13] Bach, S., A. Binder, G. Montavon, F. Klauschen, K.-R. Müller, and W. Samek, “On Pixel-Wise Explanations for Non-Linear Classifier Decisions by Layer-Wise Relevance Propagation,” PLOS ONE, vol. 10, no. 7, 2015.
[14] Pitre, A., K. Gandhi, V. Konde, P. Adhao, and V. Pachghare, “A Machine Learning Based Intrusion Detection System for Zero-Day Attack Detection with Reduced False Positives,” International Journal of Computer Applications, 2021.
[15] Alshammari, A., A. Sonamthiang, M. Teimouri, and D. Riordan, “Using Neuro-Fuzzy Approach to Reduce False Positive Alerts,” Proceedings of the 5th Annual Conference on Communication Networks and Services Research, pp. 345–349, 2007.
[16] Breiman, L., “Random Forests,” Machine Learning, vol. 45, no. 1, pp. 5–32, 2001.
image
Copyright © IJIRCCE 2020.All right reserved