中文

领域知识辅助的可解释人工智能用于入侵检测与响应

人工智能 2020-02-25 v2 密码学与安全

摘要

人工智能(AI)因其学习非常复杂函数和处理“大数据”的能力,已成为现代安全解决方案中不可或缺的一部分。然而,成功的人工智能模型缺乏可解释性和 Interpretability(可解释性),在模型预测的信任至关重要时是一个关键障碍。这导致人工干预,进而造成响应或决策的延迟。尽管基于人工智能的入侵检测系统在速度和性能上已取得重大进展,但在解释和解读特定预测或决策时,响应仍停留在人工速度。在这项工作中,我们将流行的领域知识(即CIA原则)注入我们的模型以获得更好的可解释性,并在一个网络入侵检测测试用例上验证了该方法。我们的实验结果表明,领域知识的注入提供了更好的可解释性以及更快的决策或响应。此外,注入的领域知识使模型泛化到能很好地应对未知攻击,并为适应来自众多物联网设备的大量网络流量流开辟了路径。

关键词

引用

@article{arxiv.1911.09853,
  title  = {Domain Knowledge Aided Explainable Artificial Intelligence for Intrusion Detection and Response},
  author = {Sheikh Rabiul Islam and William Eberle and Sheikh K. Ghafoor and Ambareen Siraj and Mike Rogers},
  journal= {arXiv preprint arXiv:1911.09853},
  year   = {2020}
}

备注

Accepted to be published in the Proceedings of the AAAI 2020 Spring Symposium on Combining Machine Learning and Knowledge Engineering in Practice (AAAI-MAKE 2020). Stanford University, Palo Alto, California, USA, March 23-25, 2020