A Survey on Explainable Artificial Intelligence for Cybersecurity

Gaith Rjoub,Jamal Bentahar,Omar Abdel Wahab,Rabeb Mizouni,Alyssa Song,Robin Cohen,Hadi Otrok,Azzam Mourad
DOI: https://doi.org/10.1109/TNSM.2023.3282740
2023-06-12
Abstract:The black-box nature of artificial intelligence (AI) models has been the source of many concerns in their use for critical applications. Explainable Artificial Intelligence (XAI) is a rapidly growing research field that aims to create machine learning models that can provide clear and interpretable explanations for their decisions and actions. In the field of network cybersecurity, XAI has the potential to revolutionize the way we approach network security by enabling us to better understand the behavior of cyber threats and to design more effective defenses. In this survey, we review the state of the art in XAI for cybersecurity in network systems and explore the various approaches that have been proposed to address this important problem. The review follows a systematic classification of network-driven cybersecurity threats and issues. We discuss the challenges and limitations of current XAI methods in the context of cybersecurity and outline promising directions for future research.
Cryptography and Security,Artificial Intelligence,Networking and Internet Architecture
What problem does this paper attempt to address?
The main problem this paper attempts to address is the lack of interpretability in the application of Artificial Intelligence (AI) in the field of cybersecurity. Specifically: 1. **Interpretability Issue**: The "black box" nature of AI models makes their decision-making processes difficult to understand, which raises numerous concerns in critical applications. 2. **Trust and Transparency**: By introducing Explainable Artificial Intelligence (XAI), the aim is to enhance the transparency and trustworthiness of AI systems, enabling users to understand, trust, and effectively manage AI systems. 3. **Applications in Cybersecurity**: The paper focuses on how XAI technologies can be applied in cybersecurity, including detecting cyber attacks, identifying vulnerabilities, and improving decision-making in security operations. 4. **Challenges and Limitations of Existing Methods**: It analyzes the challenges and limitations of current XAI methods in cybersecurity and proposes future research directions to overcome these limitations. In summary, the paper aims to promote the development of more reliable and transparent security solutions through a systematic review of XAI technologies in the field of cybersecurity.