论文标题

网络安全中的可解释人工智能应用:研究的最新技术

Explainable Artificial Intelligence Applications in Cyber Security: State-of-the-Art in Research

论文作者

Zhang, Zhibo, Hamadi, Hussam Al, Damiani, Ernesto, Yeun, Chan Yeob, Taher, Fatma

论文摘要

这项调查对有关网络安全应用程序的可解释人工智能方法(XAI)方法进行了全面综述。近年来,由于互联网连接的系统和人工智能的快速发展,包括机器学习(ML)和深度学习(DL)在内的人工智能已被广泛用于网络安全领域,包括入侵检测,恶意软件检测和垃圾邮件过滤。但是,尽管与传统的基于签名和基于规则的网络安全策略相比,基于人工智能的检测和防御网络攻击和威胁的方法更高级,更有效,但大多数基于ML的技术和基于DL的技术和基于DL的技术都以黑箱方式部署,这意味着安全专家和客户无法解释该过程的方式。现有人工智能技术的透明度和解释性的不足将减少人类用户对用于防御网络攻击的模型的信心,尤其是在当前网络攻击变得越来越多样化和复杂的情况下。因此,必须将XAI应用于建立网络安全模型,以创建更具解释的模型,同时保持高准确性并允许人类用户理解,信任和管理下一代的网络防御机制。尽管有一些论文审查网络安全领域中的人工智能应用程序以及有关在包括医疗保健,金融服务和刑事司法在内的许多领域应用XAI的大量文献,但令人惊讶的事实是,目前尚无关注网络安全中XAI应用的调查研究文章。

This survey presents a comprehensive review of current literature on Explainable Artificial Intelligence (XAI) methods for cyber security applications. Due to the rapid development of Internet-connected systems and Artificial Intelligence in recent years, Artificial Intelligence including Machine Learning (ML) and Deep Learning (DL) has been widely utilized in the fields of cyber security including intrusion detection, malware detection, and spam filtering. However, although Artificial Intelligence-based approaches for the detection and defense of cyber attacks and threats are more advanced and efficient compared to the conventional signature-based and rule-based cyber security strategies, most ML-based techniques and DL-based techniques are deployed in the black-box manner, meaning that security experts and customers are unable to explain how such procedures reach particular conclusions. The deficiencies of transparency and interpretability of existing Artificial Intelligence techniques would decrease human users' confidence in the models utilized for the defense against cyber attacks, especially in current situations where cyber attacks become increasingly diverse and complicated. Therefore, it is essential to apply XAI in the establishment of cyber security models to create more explainable models while maintaining high accuracy and allowing human users to comprehend, trust, and manage the next generation of cyber defense mechanisms. Although there are papers reviewing Artificial Intelligence applications in cyber security areas and the vast literature on applying XAI in many fields including healthcare, financial services, and criminal justice, the surprising fact is that there are currently no survey research articles that concentrate on XAI applications in cyber security.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源