|
|
|
|
towards explainable federated graph-based intrusion detection for zero trust critical infrastructures
|
|
|
|
|
|
|
|
نویسنده
|
mortezazadeh daragheh sania
|
|
منبع
|
اولين كنفرانس بين المللي هوش مصنوعي و فناوري هاي مرتبط - 1404 - دوره : 1 - اولین کنفرانس بین المللی هوش مصنوعی و فناوری های مرتبط - کد همایش: 04250-48654 - صفحه:0 -0
|
|
چکیده
|
In this paper, we propose fgnn-ids, anexplainable federated graph-based intrusion detectionframework designed for zero trust criticalinfrastructures. the system integrates three coretechnologies: federated learning (fl) to preserve privacyacross distributed nodes, graph neural networks (gnns)to model complex relational structures between systementities, and explainable ai (xai) techniques to ensuretransparency and trust in detection outcomes. unlikeprior work, fgnn-ids embeds attention mechanismsinto the gnn architecture and applies shap-basedattribution to provide interpretable, instance-leveljustifications for alerts.we evaluate fgnn-ids on three benchmark datasets—ton_iot, unsw-nb15, and darpa-tc-graph—under various threat scenarios, including insider attacksand lateral movement. results demonstrate that fgnnids outperforms state-of-the-art baselines in detectionaccuracy (96.3%), f1 score (95.1%), and latency (142ms). moreover, it offers strong privacy guarantees (ε =1.7) and achieves 83.5% attribution accuracy in top-5shap features, supporting human-in-the-loop securityoperations.thesefindings confirm fgnn-ids as a practical solution forreal-time, interpretable, andprivacy-preserving intrusion detection in decentralized,zero trust environments.
|
|
کلیدواژه
|
explainable ai ,federated learning ,graph neural networks ,intrusion detection ,zero trust architecture ,critical infrastructure
|
|
آدرس
|
, iran
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Authors
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|