Explaining Intrusion Alert Decisions of Deep Learning-based Network Intrusion Detection Systems for Security Analysts
This work addresses the limited interpretability of alerts generated by existing deep learning–based network intrusion detection systems (NIDS), which hinders effective analyst-driven triage in practice. To bridge this gap, the authors propose EXP-SEC, a novel framework that incorporates a forensic module to pinpoint suspicious traffic and introduces a fine-grained explanation mechanism capable of handling feature overlap and group-wise dependencies. By leveraging a multi-stage mapping strategy, EXP-SEC translates model predictions into semantically meaningful alerts aligned with the domain knowledge of security operations centers. This framework is the first to deliver domain-aligned explanations tailored for security analysts, significantly outperforming xNIDS in group-level and overlap-aware explanatory utility while maintaining comparable performance in accuracy, sparsity, and stability. The resulting explanations are more intuitive and actionable for human analysts.