Skip to content
All projects
AI for CybersecurityActive

Explainable AI for Security Operations

Studying how well post-hoc explanation methods actually serve analysts working with deep learning intrusion detectors.

SHAP-style feature attribution chart over a network alert dashboard

Overview

A deep learning intrusion detector that flags an attack without saying why is hard to trust in a security operations centre. This project examines whether popular explainability tools — like SHAP — genuinely help analysts, or just produce statistically faithful attributions that are operationally unhelpful, and explores causal alternatives that are more directly actionable.

  • Mind the Gap: On the Practical Utility of SHAP for Deep Learning-Based Intrusion Detection — 2025 RIVF International Conference on Computing and Communication Technologies
  • Explanation-Surface Governance in XAI-Enabled Network Intrusion Detection under Resource Constraints — Research Square preprint, 2026

Status

Active. Findings from “Mind the Gap” are informing follow-up work on governing what an explainable model is allowed to reveal under resource-constrained deployment.

Interested in this line of research?

Get in touch to discuss collaboration, data access, or joining the project as a student researcher.