SHAP happens: an explainable IDS for industrial IoT networks

Loi, Pierangelo
First
;
Regano, Leonardo
;
Maiorca, Davide
;
Giacinto, Giorgio
2025-01-01

Abstract

Industrial Internet of Things (IIoT) technologies have been increasingly leveraged across various industry sectors, due to their benefits in terms of automation, monitoring, and operational efficiency. However, the increased connectivity and heterogeneity of IIoT devices have also broadened the attack surface, making these systems attractive targets for cyber threats. In this context, machine learning–based Intrusion Detection Systems (IDS) have emerged as promising solutions due to their ability to detect complex patterns in network traffic without relying on static rules or deep packet inspection. A key limitation of such systems, however, lies in their lack of interpretability, posing challenges for adoption in safety-critical industrial settings.In this work, we propose an explainable IDS that leverages a Random Forest classifier for accurate traffic classification and integrates SHAP (SHapley Additive Explanations) to provide transparent explanations of model decisions. We evaluate our system using the CIC IoT-DIAD 2024 dataset, which includes a broad spectrum of network attacks. Our approach demonstrates good detection performance while also delivering intuitive explanations for each prediction. By analyzing the specific network features, such as inter-arrival times and packet sizes, that most influence each alert, security analysts may better assess, validate, and act upon IDS outputs.
2025
Inglese
2025 IEEE 9th Forum on Research and Technologies for Society and Industry (RTSI)
979-8-3315-9789-4
IEEE
71
76
6
2025 IEEE 9th Forum on Research and Technologies for Society and Industry (RTSI)
Esperti anonimi
24-26 Aug. 2025
Tunis, Tunisia
internazionale
scientifica
Internet of Things; Intrusion detection; Explain able AI
no
4 Contributo in Atti di Convegno (Proceeding)::4.1 Contributo in Atti di convegno
Loi, Pierangelo; Canavese, Daniele; Regano, Leonardo; Maiorca, Davide; Giacinto, Giorgio
273
5
4.1 Contributo in Atti di convegno
partially_open
info:eu-repo/semantics/conferencePaper
Files in This Item:
File Size Format  
SHAP_happens_an_Explainable_IDS_for_Industrial_IoT_Networks.pdf

Solo gestori archivio

Description: VoR
Type: versione editoriale
Size 1.11 MB
Format Adobe PDF
1.11 MB Adobe PDF & nbsp; View / Open   Request a copy
Explainable_IDS-3_Iris.pdf

open access

Description: AAM
Type: Author’s Accepted Manuscript AAM, Post-print, (version accepted by the publisher)
Size 977.32 kB
Format Adobe PDF
977.32 kB Adobe PDF View/Open

Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.

Questionnaire and social

Share on:
Impostazioni cookie