Explainable Artificial Intelligence in CyberSecurity: A Survey
Объяснимый искусственный интеллект в кибербезопасности: обзор
2022-01-01
SCID: 54.1/m5gaa7fy
Discuss with AI
Adversarial attacksCybersecurityExplainable artificial intelligenceIntrusion detection systemsMalware detection
Figures from the paper
Abstract (AI)
Nowadays, Artificial Intelligence (AI) is widely applied in every area of human being’s daily life. Despite the AI benefits, its application suffer from the opacity of complex internal mechanisms and doesn’t satisfy by design the principles of Explainable Artificial Intelligence (XAI). The lack of transparency further exacerbates the problem in the field of Cybersecurity because entrusting crucial decisions to a system that cannot explain itself presents obvious dangers. There are several methods in the literature capable of providing explainability of AI results. Anyway, the application of XAI in Cybersecurity can be a double-edged sword. It substantially improves the Cybersecurity practices but simultaneously leaves the system vulnerable to adversary attacks. Therefore, there is a need to analyze the state-of-the-art of XAI methods in Cybersecurity to provide a clear vision for future research. This study presents an in-depth examination of the application of XAI in Cybersecurity. It considers more than 300 papers to comprehensively analyze the main Cybersecurity application fields, like Intrusion Detection Systems,Malware detection, Phishing and Spam detection, BotNets detection, Fraud detection, Zero-Day vulnerabilities, Digital Forensics and Crypto-Jacking. Specifically, this study focuses on the explainability methods adopted or proposed in these fields, pointing out promising works and new challenges.
Key Findings
1
AI’s opacity creates safety risks in cybersecurity, where critical decisions require transparent and understandable explanations.
2
Explainable AI can substantially improve cybersecurity practices, but exposing model reasoning may simultaneously increase vulnerability to adversarial attacks.
3
The findings highlight the need to balance improved transparency with the security risks introduced by explainability in cybersecurity systems.
4
The study categorizes explainability methods used or proposed across major cybersecurity domains and identifies promising approaches and unresolved research challenges.
5
The survey analyzes more than 300 papers on XAI applications across intrusion detection, malware, phishing and spam, botnet, fraud, zero-day, digital forensics, and crypto-jacking detection.
Research Object
the application of Explainable Artificial Intelligence (XAI) methods in cybersecurity systems and application fields
Research Subject
the explainability, benefits, vulnerabilities, and research challenges of AI-based cybersecurity decisions across intrusion, malware, phishing/spam, botnet, fraud, zero-day, digital forensics, and crypto-jacking detection
Publication Details
Publication Date
2022-01-01
Journal
Publisher
ISSN
Cited by
313
Open access PDF
Access Type
Author Information
Download PDF
Subscribe to digest
References available in scid.ai7
Peeking Inside the Black-Box: A Survey on Explainable Artificial Intelligence (XAI)2018
A survey of methods for explaining black box models2019
A Survey on Explainable Artificial Intelligence (XAI): Toward Medical XAI2020
Machine Learning Interpretability: A Survey on Methods and Metrics2019
Network intrusion detection system: A systematic study of machine learning and deep learning approaches2020
Machine Learning and Deep Learning Methods for Cybersecurity2018
A Survey on Machine Learning Techniques for Cyber Security in the Last Decade2020