Explainable AI for Security Operations
Studying how well post-hoc explanation methods actually serve analysts working with deep learning intrusion detectors.
SHAP-style feature attribution chart over a network alert dashboard
Overview
A deep learning intrusion detector that flags an attack without saying why is hard to trust in a security operations centre. This project examines whether popular explainability tools — like SHAP — genuinely help analysts, or just produce statistically faithful attributions that are operationally unhelpful, and explores causal alternatives that are more directly actionable.
Related publications
- Mind the Gap: On the Practical Utility of SHAP for Deep Learning-Based Intrusion Detection — 2025 RIVF International Conference on Computing and Communication Technologies
- Explanation-Surface Governance in XAI-Enabled Network Intrusion Detection under Resource Constraints — Research Square preprint, 2026
Status
Active. Findings from “Mind the Gap” are informing follow-up work on governing what an explainable model is allowed to reveal under resource-constrained deployment.