<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xml:lang="en" article-type="research-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">CMC</journal-id>
<journal-id journal-id-type="nlm-ta">CMC</journal-id>
<journal-id journal-id-type="publisher-id">CMC</journal-id>
<journal-title-group>
<journal-title>Computers, Materials &#x0026; Continua</journal-title>
</journal-title-group>
<issn pub-type="epub">1546-2226</issn>
<issn pub-type="ppub">1546-2218</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">52599</article-id>
<article-id pub-id-type="doi">10.32604/cmc.2024.052599</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Article</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>Explainable AI-Based DDoS Attacks Classification Using Deep Transfer Learning</article-title>
<alt-title alt-title-type="left-running-head">Explainable AI-Based DDoS Attacks Classification Using Deep Transfer Learning</alt-title>
<alt-title alt-title-type="right-running-head">Explainable AI-Based DDoS Attacks Classification Using Deep Transfer Learning</alt-title>
</title-group>
<contrib-group>
<contrib id="author-1" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Alzu&#x2019;bi</surname><given-names>Ahmad</given-names></name><xref ref-type="aff" rid="aff-1">1</xref><email>agalazubi@just.edu.jo</email></contrib>
<contrib id="author-2" contrib-type="author">
<name name-style="western"><surname>Albashayreh</surname><given-names>Amjad</given-names></name><xref ref-type="aff" rid="aff-2">2</xref></contrib>
<contrib id="author-3" contrib-type="author">
<name name-style="western"><surname>Abuarqoub</surname><given-names>Abdelrahman</given-names></name><xref ref-type="aff" rid="aff-3">3</xref></contrib>
<contrib id="author-4" contrib-type="author">
<name name-style="western"><surname>Alfawair</surname><given-names>Mai A. M.</given-names></name><xref ref-type="aff" rid="aff-4">4</xref></contrib>
<aff id="aff-1"><label>1</label><institution>Department of Computer Science, Jordan University of Science and Technology</institution>, <addr-line>Irbid, 22110</addr-line>, <country>Jordan</country></aff>
<aff id="aff-2"><label>2</label><institution>Department of Computer Science, The University of Jordan</institution>, <addr-line>Amman, 11942</addr-line>, <country>Jordan</country></aff>
<aff id="aff-3"><label>3</label><institution>Cardiff School of Technologies, Cardiff Metropolitan University</institution>, <addr-line>Cardiff, CF5 2YB</addr-line>, <country>UK</country></aff>
<aff id="aff-4"><label>4</label><institution>Prince Abdullah bin Ghazi Faculty of Information and Communication Technology, Al-Balqa Applied University</institution>, <addr-line>Salt, 19117</addr-line>, <country>Jordan</country></aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><label>&#x002A;</label>Corresponding Author: Ahmad Alzu&#x2019;bi. Email: <email>agalazubi@just.edu.jo</email></corresp>
</author-notes>
<pub-date date-type="collection" publication-format="electronic">
<year>2024</year></pub-date>
<pub-date date-type="pub" publication-format="electronic"><day>12</day><month>9</month><year>2024</year></pub-date>
<volume>80</volume>
<issue>3</issue>
<fpage>3785</fpage>
<lpage>3802</lpage>
<history>
<date date-type="received">
<day>08</day>
<month>4</month>
<year>2024</year>
</date>
<date date-type="accepted">
<day>24</day>
<month>6</month>
<year>2024</year>
</date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2024 The Authors.</copyright-statement>
<copyright-year>2024</copyright-year>
<copyright-holder>Published by Tech Science Press.</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_CMC_52599.pdf"></self-uri>
<abstract>
<p>In the era of the Internet of Things (IoT), the proliferation of connected devices has raised security concerns, increasing the risk of intrusions into diverse systems. Despite the convenience and efficiency offered by IoT technology, the growing number of IoT devices escalates the likelihood of attacks, emphasizing the need for robust security tools to automatically detect and explain threats. This paper introduces a deep learning methodology for detecting and classifying distributed denial of service (DDoS) attacks, addressing a significant security concern within IoT environments. An effective procedure of deep transfer learning is applied to utilize deep learning backbones, which is then evaluated on two benchmarking datasets of DDoS attacks in terms of accuracy and time complexity. By leveraging several deep architectures, the study conducts thorough binary and multiclass experiments, each varying in the complexity of classifying attack types and demonstrating real-world scenarios. Additionally, this study employs an explainable artificial intelligence (XAI) AI technique to elucidate the contribution of extracted features in the process of attack detection. The experimental results demonstrate the effectiveness of the proposed method, achieving a recall of 99.39% by the XAI bidirectional long short-term memory (XAI-BiLSTM) model.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>DDoS attack classification</kwd>
<kwd>deep learning</kwd>
<kwd>explainable AI</kwd>
<kwd>cybersecurity</kwd>
</kwd-group>
</article-meta>
</front>
<body>
<sec id="s1">
<label>1</label>
<title>Introduction</title>
<p>The advent of the Internet of Things (IoT) has heightened cybersecurity research by integrating numerous devices into networks to deliver complicated services. By 2025, it is estimated that there will be 75 billion smart devices, which will transform everyday life [<xref ref-type="bibr" rid="ref-1">1</xref>]. The transportation, healthcare, manufacturing, and agriculture industries, among others, are becoming increasingly dependent on IoT technology [<xref ref-type="bibr" rid="ref-2">2</xref>]. This technology is rapidly expanding and connecting a wide range of products, from businesses and residences to transportation. It is reshaping daily duties and how people conduct their personal and professional activities, potentially decreasing the demand for human labor while increasing the intelligence of our daily lives [<xref ref-type="bibr" rid="ref-3">3</xref>]. However, the rapid expansion of IoT devices poses substantial security issues due to their interconnected nature, sensors, and massive data creation. Also, they are numerous, diverse, need little computational power, and typically operate at the periphery of computer networks. These devices frequently have fundamental vulnerabilities because of their limited computational capability, affordable design, and lack of regular security upgrades [<xref ref-type="bibr" rid="ref-4">4</xref>,<xref ref-type="bibr" rid="ref-5">5</xref>]. As a result, consumers are more vulnerable to cyberattacks. Different manufacturers&#x2019; security requirements can lead to new types of attacks on IoT systems, despite numerous security measures in place. Connecting IoT devices to an unprotected network exposes them to a variety of threats, even if they are otherwise safe. Therefore, it must preserve user privacy while combating cyberattacks such as distributed denial of service (DDoS), which change over time and pose new risks on a daily basis. The complexity of the number of IoT devices and networks allows attackers to transform basic devices into destructive botnets to launch potentially damaging attacks [<xref ref-type="bibr" rid="ref-6">6</xref>]. Traditional cybersecurity techniques frequently focus on protecting against local attacks or breaches inside a limited network environment. Yet, the environment of IoT offers a new level of complexity.</p>
<p>IoT attacks present new challenges that surpass the capabilities of traditional security measures. These attacks can vary from minor invasions of privacy to complex, systematic attacks on interconnected networks [<xref ref-type="bibr" rid="ref-7">7</xref>]. IoT system attacks are more widespread and severe than local transmission attacks, which are limited to nodes near a small domain, causing significant damage [<xref ref-type="bibr" rid="ref-8">8</xref>,<xref ref-type="bibr" rid="ref-9">9</xref>]. The crucial necessity to secure user privacy and prevent more sophisticated assaults drives the urgency of addressing IoT security challenges. Unlike isolated breaches, IoT assaults may have far-reaching implications, affecting not only individual users but whole networks and infrastructures. As a result, the focus should be on developing robust security procedures tailored to the intricate nature of IoT systems, necessitating advanced detection techniques. Deep learning (DL) models are particularly well-suited for identifying subtle attack patterns in network traffic. To address concerns about the opaque nature of artificial intelligence (AI), explainable AI (XAI) techniques can be employed [<xref ref-type="bibr" rid="ref-10">10</xref>], improving transparency and interpretability. By integrating deep learning models with explainable AI, transparent DDoS detection systems can be developed to mitigate risks and facilitate informed decision-making and response actions. Such an approach fosters trust among stakeholders and enhances DDoS detection in dynamic and complex environments, where the impact of these attacks can be most severe.</p>
<p>This study aims to introduce a framework for identifying incoming DDoS attacks through deep learning models with an effective transfer learning mechanism that relies on the interpretations of attack features. We evaluate two datasets sourced predominantly from the IoT network, featuring diverse network flows. Additionally, the study seeks to elucidate the generated predictions by analyzing the data features&#x2019; contribution to the decision-making process using XAI techniques. The main contribution of this study is three-fold:
<list list-type="simple">
<list-item>
<label>-</label><p>A DDoS detection framework is introduced to identify DDoS attacks in IoT environments automatically. The proposed deep learning model formulates generic discriminating descriptors of network data with various pre-trained deep backbones to scrutinize and classify potential threats in network traffic.</p></list-item>
<list-item>
<label>-</label><p>Local interpretable model-agnostic explanations are provided to explain the decision-making process of deep learning models with effective model fine-tuning, which increases the transparency and reliability of the detection process.</p></list-item>
<list-item>
<label>-</label><p>In addition to accuracy measurements, the performance of the DDoS detector is evaluated in terms of time complexity, which is done by rigorously conducted experiments demonstrating a range of potential threat scenarios, i.e., binary network flows, detection of 8 attacks, and detection of 34 attacks.</p></list-item>
</list></p>
<p>The rest of this paper is organized as follows: <xref ref-type="sec" rid="s2">Section 2</xref> reviews the prior work; the methodology of the DDoS detection system is presented in <xref ref-type="sec" rid="s3">Section 3</xref>; <xref ref-type="sec" rid="s4">Section 4</xref> discusses the experimental results; and <xref ref-type="sec" rid="s5">Section 5</xref> concludes this paper.</p>
</sec>
<sec id="s2">
<label>2</label>
<title>Related Work</title>
<p>This section presents recent research work dedicated to detecting DDoS attacks in IoT networks and explaining DDoS features utilizing XAI techniques.</p>
<sec id="s2_1">
<label>2.1</label>
<title>DDoS in IoT Networks</title>
<p>In recent years, researchers have dedicated substantial efforts to examining attacks within IoT networks, utilizing traditional statistical methods and machine learning algorithms to differentiate between normal activity and malicious behavior. Various machine learning and DL models were utilized to consider diverse features of DDoS flows using the Canadian Institute for Cybersecurity IoT (CICIoT2023) dataset [<xref ref-type="bibr" rid="ref-11">11</xref>], leading to varying results due to the utilization of different techniques. Abbas et al. [<xref ref-type="bibr" rid="ref-3">3</xref>] presented a unique technique for detecting large IoT device threats via federated learning, which employs a deep neural network for accurate classification. Sharmin et al. [<xref ref-type="bibr" rid="ref-12">12</xref>] examined reconnaissance assaults on IoT devices utilizing time-based features and flag qualities and employed Bayesian optimization to pick a representative sample for the best flow duration range.</p>
<p>Wang et al. [<xref ref-type="bibr" rid="ref-13">13</xref>] proposed a hybrid intrusion detection model that combines deep neural network (DNN) and bidirectional long short-term memory (BiLSTM) to develop a lightweight IoT intrusion identification system. The model reduces feature dimensionality, extracts nonlinear and bidirectional long-range features, and dynamically quantifies its unit structure. Khan et al. [<xref ref-type="bibr" rid="ref-14">14</xref>] investigated the utilization of supervised machine learning algorithms to identify abnormal behavior by applying the synthetic minority over-sampling technique (SMOTE). The outcomes revealed that Random Forest is the most efficient model in comparison to prior works. Additionally, the authors found that removing highly correlated features improves performance but reduces computational response time. Yaras et al. [<xref ref-type="bibr" rid="ref-15">15</xref>] developed a hybrid deep learning algorithm using convolutional neural network (CNN) and long short-term memory (LSTM) models to detect DDoS attacks. The proposed model was tested on the CICIoT2023 and telemetry of network_IoT (ToN_IoT) [<xref ref-type="bibr" rid="ref-16">16</xref>]. <xref ref-type="table" rid="table-1">Table 1</xref> provides a summary of the previous research conducted on the CICIoT2023 dataset.</p>
<table-wrap id="table-1">
<label>Table 1</label>
<caption>
<title>A summary of the previous research on CICIoT2023</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th>Ref.</th>
<th>Technique</th>
<th>Task</th>
<th>Recall (%)</th>
</tr>
</thead>
<tbody>
<tr>
<td>[<xref ref-type="bibr" rid="ref-3">3</xref>]</td>
<td>Federated learning with DNN</td>
<td>2-classes</td>
<td>99.00</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-12">12</xref>]</td>
<td>Multiclass model</td>
<td>8-classes</td>
<td>88.00</td>
</tr>
<tr>
<td/>
<td/>
<td>34-classes</td>
<td>70.00</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-13">13</xref>]</td>
<td>DL-BiLSTM</td>
<td>8-classes</td>
<td>93.13</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-14">14</xref>]</td>
<td>Random Forest (RF)</td>
<td>2-classes</td>
<td>99.49</td>
</tr>
<tr>
<td/>
<td/>
<td>8-classes</td>
<td>95.52</td>
</tr>
<tr>
<td/>
<td/>
<td>34-classes</td>
<td>96.54</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-15">15</xref>]</td>
<td>Hybrid deep learning</td>
<td>2-classes</td>
<td>99.99</td>
</tr>
<tr>
<td/>
<td/>
<td>9-classes</td>
<td>99.96</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s2_2">
<label>2.2</label>
<title>DDoS Explanation</title>
<p>Previous studies have employed various XAI techniques to elucidate DDoS attacks, with the goal of enhancing the understanding of attack patterns, behaviors, and detection mechanisms. Gyamfi et al. [<xref ref-type="bibr" rid="ref-17">17</xref>] utilized low-cost IoT sensors for effective intrusion detection, using a network of cameras to record location information. They performed compatibility checks between datasets and features, integrating them to create a new IoT dataset using an explainable AI technique. Hasan et al. [<xref ref-type="bibr" rid="ref-18">18</xref>] developed an explainable ensemble DL based intrusion detection system (IDS) framework that improves the transparency and robustness of DL-based IDSs in IoT networks. The framework&#x2019;s efficacy was evaluated using the ToN_IoT dataset and extreme learning machines model. Bashaiwth et al. [<xref ref-type="bibr" rid="ref-19">19</xref>] studied the LSTM predictions on CIC datasets using local interpretable model-agnostic explanations (LIME) [<xref ref-type="bibr" rid="ref-20">20</xref>], shapley additive explanations (SHAP), Anchor, and local rule-based explanations (LORE) techniques. They conducted binary and multiclass classifications. The binary classification demonstrated high performance across all three datasets, whereas the multiclass classification showed good performance only for the first two versions. However, the LSTM model struggled to differentiate between certain attacks, resulting in poor classification performance. Hassan et al. [<xref ref-type="bibr" rid="ref-21">21</xref>] utilized machine learning techniques to detect malicious traffic data in vehicle ad hoc networks (VANETs) and proposed an IDS capable of identifying threats from 14 types of malicious attacks. Wei et al. [<xref ref-type="bibr" rid="ref-22">22</xref>] proposed a framework for detecting normal and malicious DDoS attack traffic, utilizing Kernel SHAP to understand the multilayer perceptron (MLP) classifier prediction results. Tabassun et al. [<xref ref-type="bibr" rid="ref-23">23</xref>] used XAI techniques such as SHAP, LIME, and explain like I&#x2019;m 5 (ELI5) to classify DDoS attacks in IoT networks using machine learning and deep learning models. The results reveal that SHAP offers both local and global explanations, LIME provides local explanations, and ELI5 highlights important features. Antwarg et al. [<xref ref-type="bibr" rid="ref-24">24</xref>] employed Kenal SHAP to explain anomalies in the knowledge discovery in databases (KDD) dataset using autoencoder&#x2019;s unsupervised model. The approach explained the influence of low and high reconstruction error characteristics, proving its resilience in comparison to existing LIME explanation methods.</p>
<p>Senevirathna et al. [<xref ref-type="bibr" rid="ref-25">25</xref>] proposed a new framework for scaffolding attacks in security contexts, combining XAI outputs with domain knowledge to identify target features. The approach identifies essential aspects an attacker would conceal while building a model and presents an effective attack detection method. The authors utilized various models including MLP, support vector machine (SVM), RF, LSTM, gaussian naive bayes (GNB), and k-nearest neighbour (KNN), with MLP achieving an F1-score of 99.40. Arreche et al. [<xref ref-type="bibr" rid="ref-26">26</xref>] developed a framework for evaluating black-box XAI algorithms for network intrusion detection. The framework evaluates global and local scopes, examining six metrics for SHAP and LIME, including network security and AI. It is being tested with three datasets and seven AI algorithms adaptive (ADA), LSTM, DNN, light gradient boosting machine (LGBM), MLP, RF, and KNN, serving as a baseline for network security. The authors achieved a recall score of 99.98 using the KNN model. Do et al. [<xref ref-type="bibr" rid="ref-27">27</xref>] utilized XAI algorithms such as LIME, SHAP, gradient-weighted class activation mapping (Grad-CAM), and guided backpropagation (GBP) to analyze network traffic patterns, distinguishing between malicious and benign connections. The authors empirically found that XAI algorithms like SHAP and LIME can identify complex correlations between characteristics and anomalies, enabling precise identification of benign traffic. The authors used different models such as RF and CNN and achieved a recall score equal to 99.90. <xref ref-type="table" rid="table-2">Table 2</xref> summarizes previous research that utilized explainable AI techniques to explain DDoS attacks.</p>
<table-wrap id="table-2">
<label>Table 2</label>
<caption>
<title>A summary of previous research utilized XAI to explain DDoS attacks</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th>Ref.</th>
<th>Model</th>
<th>Explainable-AI</th>
<th>Dataset</th>
</tr>
</thead>
<tbody>
<tr>
<td>[<xref ref-type="bibr" rid="ref-17">17</xref>]</td>
<td>XGBoost</td>
<td>TreeSHAP</td>
<td>IoTID20</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-18">18</xref>]</td>
<td>CNN</td>
<td>SHAP, LIME</td>
<td>ToN_IoT</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-19">19</xref>]</td>
<td>LSTM</td>
<td>LIME, SHAP, Anchor, and LORE</td>
<td>CICDDoS2017/2018/2019</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-21">21</xref>]</td>
<td>RF</td>
<td>SHAP, LIME</td>
<td>IIoT</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-22">22</xref>]</td>
<td>MLP</td>
<td>Kernel SHAP</td>
<td>CICDDoS2019</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-23">23</xref>]</td>
<td>Decision tree</td>
<td>SHAP, ELI5, and LIME</td>
<td>Artificial dataset</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-24">24</xref>]</td>
<td>Autoencoder</td>
<td>Kenal SHAP</td>
<td>NSL-KDD</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-25">25</xref>]</td>
<td>MLP</td>
<td>SHAP</td>
<td>5GNIDD, NLS-KDD</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-26">26</xref>]</td>
<td>KNN</td>
<td>SHAP, LIME</td>
<td>RoEduNetSIMARGL2021 CICIDS-2017, NSL-KDD</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-27">27</xref>]</td>
<td>RF</td>
<td>LIME, SHAP, Grad-CAM, and GBP</td>
<td>MQTTset, CICIDS-2017</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>However, there is still a demand for handling the impact and utilization of any explained features in the training procedure, providing effective feedback for the training engine, i.e., linear regression in our study. We demonstrate in this work how several deep architectures can interpret and explain the extracted features from network traffic and update the weights accordingly. Additionally, the time complexity of model training is calculated and discussed&#x2013;usually neglected in the existing approaches. We have also performed more evaluation experiments on a new dataset that has been released recently with diverse traffic data, including unknown attacks, demonstrating real-world scenarios.</p>
</sec>
</sec>
<sec id="s3">
<label>3</label>
<title>Methodology</title>
<sec id="s3_1">
<label>3.1</label>
<title>DDoS Evaluation Datasets</title>
<p>This paper examines DoS/DDoS attacks using the recent intrusion data for DDoS detection systems, primarily based on the CICIoT2023 [<xref ref-type="bibr" rid="ref-11">11</xref>] and CICDDOS2019 [<xref ref-type="bibr" rid="ref-28">28</xref>] datasets, chosen due to their diverse range of DDoS network flows, demonstrating real-world scenarios and posing significant detection challenges.</p>
<sec id="s3_1_1">
<label>3.1.1</label>
<title>CICIoT2023 Dataset</title>
<p>The CICIoT2023 dataset [<xref ref-type="bibr" rid="ref-11">11</xref>] is a comprehensive IoT attack dataset that was released to advance the development of security analytics applications within real IoT environments. It includes 33 distinct attacks across seven categories, including DDoS, DoS, Recon, Web-based, Brute Force, Spoofing, and Mirai, executed within an IoT network consisting of 105 devices. DDoS includes acknowledgment (ACK) fragmentation, User Datagram Protocol (UDP) flood, SlowLoris, internet control message protocol (ICMP) flood, reset finish (RSTFIN) flood, PSH acknowledgment (PSHACK) flood, hypertext transfer protocol (HTTP) flood, UDP fragmentation, transmission control protocol (TCP) flood, synchronize (SYN) flood, and SynonymousIP flood. DoS includes TCP flood, HTTP flood, SYN flood, and UDP flood. Brute Force includes Dictionary brute force, Spoofing includes address resolution protocol (ARP) spoofing and domain name system (DNS) spoofing. Recon includes Ping sweep, operating system (OS) scan, Vulnerability scan, Port scan, and Host discovery. Web-based includes structured query language (SQL) injection, Command injection, Backdoor malware, Uploading attacks, cross-site scripting (XSS), and Browser hijacking. Mirai includes generic routing encapsulation internet protocol (GRE-IP) flood, Greeth flood, and UDPPlain.</p>
<p>The CICIoT2023 experiment investigates the utilization of IoT devices in smart home environments, with 105 devices participating in the attacks. The topology is separated into two components: a router that connects the network to the Internet with a Windows 10 desktop computer, and a Cisco switch that connects seven Raspberry Pi devices. These devices carry out assaults and criminal behaviors, exhibiting a unique feature of CICIoT2023. The Cisco switch is linked to the second component via a Gigamon Network Tap, which captures all IoT traffic and routes it to two network monitors. These monitors use Wireshark to store traffic, allowing for full-duplex, non-intrusive, and passive access to network traffic without interfering with routine operations. The device includes two networks and two monitoring ports, with one connected to attackers and the other to victims&#x2019; networks. A network tap and two traffic monitors are used to monitor network traffic, with each packet saved on different computers. Wireshark monitors network activity, which is saved in pcap format. Mergecap combines pcap files for each experiment. Each assault is unique on all relevant devices, targeting rogue IoT devices in all circumstances. This technique helps assess potential risks and vulnerabilities in IoT systems. <xref ref-type="table" rid="table-3">Tables 3</xref> and <xref ref-type="table" rid="table-4">4</xref> present data statistics for binary classification and eight-class classification tasks, respectively. <xref ref-type="fig" rid="fig-1">Fig. 1</xref> also depicts the data statistics for 34-classes in the multiclassification experiment.</p>
<table-wrap id="table-3">
<label>Table 3</label>
<caption>
<title>The data statistics for the binary classification task</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th>Class</th>
<th>Training</th>
<th>Validation</th>
<th>Testing</th>
</tr>
</thead>
<tbody>
<tr>
<td>Attack</td>
<td>3,487,879</td>
<td>387,542</td>
<td>968,856</td>
</tr>
<tr>
<td>Benign</td>
<td>84,021</td>
<td>9336</td>
<td>23,339</td>
</tr>
</tbody>
</table>
</table-wrap><table-wrap id="table-4">
<label>Table 4</label>
<caption>
<title>The data statistics for the (8-classes) classification task</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th>Class</th>
<th>Training</th>
<th>Validation</th>
<th>Testing</th>
</tr>
</thead>
<tbody>
<tr>
<td>DDoS</td>
<td>2,601,180</td>
<td>289,020</td>
<td>722,550</td>
</tr>
<tr>
<td>DoS</td>
<td>618,159</td>
<td>68,685</td>
<td>171,711</td>
</tr>
<tr>
<td>Mirai</td>
<td>201,316</td>
<td>22,368</td>
<td>55,921</td>
</tr>
<tr>
<td>Benign</td>
<td>84,021</td>
<td>9336</td>
<td>23,339</td>
</tr>
<tr>
<td>Spoofing</td>
<td>37,356</td>
<td>4151</td>
<td>10,377</td>
</tr>
<tr>
<td>Recon</td>
<td>27,026</td>
<td>3003</td>
<td>7508</td>
</tr>
<tr>
<td>Web</td>
<td>1867</td>
<td>207</td>
<td>518</td>
</tr>
<tr>
<td>Brute force</td>
<td>975</td>
<td>108</td>
<td>271</td>
</tr>
</tbody>
</table>
</table-wrap><fig id="fig-1">
<label>Figure 1</label>
<caption>
<title>The data statistics for the (34-classes) classification task</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_52599-fig-1.tif"/>
</fig>
</sec>
<sec id="s3_1_2">
<label>3.1.2</label>
<title>CICDDoS2019</title>
<p>The CICDDoS2019 dataset [<xref ref-type="bibr" rid="ref-28">28</xref>] was proposed by the Canadian Institute of Cybersecurity as a new version of CICDDoS2017 and CICDDoS2018. The dataset was created using the B-Profile technology, which profiles abstract human interactions and generates real benign background traffic. It incorporates 25 users&#x2019; abstract behavior based on HTTP, HTTPS, FTP, SSH, and email protocols to provide realistic background traffic. This dataset consists of benign and DDoS network flows that match real-world data. It contains several current DDoS reflection attacks, including such as Port Map, lightweight directory access protocol (LDAP), network basic input/output system (NetBIOS), UDP, Microsoft SQL server (MSSQL), UDP-Lag, SYN, DNS, network time protocol (NTP), simple network management protocol (SNMP) and more, making it an excellent choice for accurately reflecting the current environment, as many outdated datasets are no longer functional. <xref ref-type="table" rid="table-5">Table 5</xref> shows the statistics of the CICDDoS2019 dataset.</p>
<table-wrap id="table-5">
<label>Table 5</label>
<caption>
<title>The CICDDoS2019 statistics</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th>Class</th>
<th>Training</th>
<th>Validation</th>
<th>Testing</th>
</tr>
</thead>
<tbody>
<tr>
<td>Attack</td>
<td>240,148</td>
<td>26,683</td>
<td>66,709</td>
</tr>
<tr>
<td>Benign</td>
<td>70,438</td>
<td>7827</td>
<td>19,566</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
</sec>
<sec id="s3_2">
<label>3.2</label>
<title>The Generic Framework of DDoS Detection</title>
<p>This paper proposes a new systematic framework for DDoS detection to classify the network flows based on the purpose of its occurrence, whether it is a natural induction or a malicious attack, this framework consists of five stages: data preparation, feature engineering, data split, deep learning models, and LIME explanation. <xref ref-type="fig" rid="fig-2">Fig. 2</xref> displays the major phases adopted in the proposed DDoS detection framework, which are detailed in the following subsections.</p>
<fig id="fig-2">
<label>Figure 2</label>
<caption>
<title>The generic pipeline of the DDoS detector</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_52599-fig-2.tif"/>
</fig>
<sec id="s3_2_1">
<label>3.2.1</label>
<title>Data Preparation</title>
<p>To ensure the dataset is adequately prepared for training and evaluating the deep learning model, several steps were undertaken. This included extracting a subset of network flows from the original data source, which contains both benign and attack flows. All the obtained network flows have been merged and stored in one comma-separated value (CSV) file, and then label mapping has been done to map each network flow to its exact attack type. All the categorical columns have been encoded. After that, the raw data was converted into a format that the model could use. The original 34 labels were simplified by grouping related classes and assigning new labels to reduce complexity. In two experiments, the attacks were mapped into eight attacks and one general label to classify network flows to attack or begin. This approach reduced the complexity of the classification task and made the process more manageable. Also, label encoding is used to transform categorical data into a numerical representation that deep learning models can understand. Based on the mapping procedure, each unique label is allocated a unique integer.</p>
<p>Due to the huge amount of data, twenty-one CSV files with 4,960,973 network flows are obtained from the original data and combined in one source to train and evaluate the deep learning models. The data set is divided into three parts: 70% for training, 10% for validation, and 20% for testing. Due to the use of imbalanced data, the stratification technique is used to guarantee that models are trained and assessed on subsets of data that accurately represent the overall distribution of classes.</p>
</sec>
<sec id="s3_2_2">
<label>3.2.2</label>
<title>Feature Engineering</title>
<p>In this work, the procedure of feature engineering includes feature selection and feature standardization. The feature selection step is done manually to select the same features that were obtained by the authors of CICIoT2023 without implementing any mathematical technique. Feature standardization is used for data scaling by changing the distribution of characteristics to a standard scale with a mean of 0 and a standard deviation of 1. This paper used the standard scaler method to guarantee that numerical features contribute equally to the model&#x2019;s learning process and reduce the influence of differing scales on the performance of the algorithms. The standard scaler transformation for a feature <inline-formula id="ieqn-1"><mml:math id="mml-ieqn-1"><mml:mrow><mml:mi mathvariant="bold-script">X</mml:mi></mml:mrow></mml:math></inline-formula> is defined in <xref ref-type="disp-formula" rid="eqn-1">Eq. (1)</xref>, where <bold><italic>Z</italic></bold> is the standardized value, <inline-formula id="ieqn-2"><mml:math id="mml-ieqn-2"><mml:mrow><mml:mi mathvariant="bold-script">X</mml:mi></mml:mrow></mml:math></inline-formula> is the original feature, <italic>&#x03BC;</italic> is the mean of the feature, and &#x03C3; is the standard deviation of the feature.
<disp-formula id="eqn-1"><label>(1)</label><mml:math id="mml-eqn-1" display="block"><mml:mi mathvariant="bold-italic">Z</mml:mi><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:mrow><mml:mi>&#x1D4B3;</mml:mi></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mi>&#x03BC;</mml:mi></mml:mrow><mml:mi>&#x03C3;</mml:mi></mml:mfrac></mml:math></disp-formula></p>
</sec>
<sec id="s3_2_3">
<label>3.2.3</label>
<title>Deep Learning Backbone Models</title>
<p>This paper employs various deep learning backbones in DDoS detection to provide a reliable and comprehensive approach for analyzing network traffic data. Extensive experiments were performed for the procedure of transfer learning using four different pre-trained deep learning models, which are BiLSTM [<xref ref-type="bibr" rid="ref-29">29</xref>], CNN [<xref ref-type="bibr" rid="ref-30">30</xref>], gated recurrent units (GRU) [<xref ref-type="bibr" rid="ref-31">31</xref>], and RNN [<xref ref-type="bibr" rid="ref-32">32</xref>]. Because each of these models has distinct architectural features, it is possible to thoroughly examine how well they can address the particular difficulties presented by this research. Utilizing different deep learning models validates the dataset network flows and their outcomes across multiple methodologies. As a result, organizations can improve the effectiveness and reliability of their DDoS detection systems, ultimately enhancing their defenses against cyber threats. These models are used in this paper due to their architectures which have unique capabilities that make them suitable for DDoS detection tasks compared to other deep learning and machine learning techniques. They can handle sequential data, learn hierarchical features, preserve memory and context, adapt to evolving patterns, and leverage ensemble learning. <xref ref-type="fig" rid="fig-3">Fig. 3</xref> shows a visual representation of the operational flow of these models at every stage, including both the training and testing phases. It details the entire process from the input of data to the ultimate decision-making.</p>
<fig id="fig-3">
<label>Figure 3</label>
<caption>
<title>Visual representation of neural network learning process</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_52599-fig-3.tif"/>
</fig>
</sec>
<sec id="s3_2_4">
<label>3.2.4</label>
<title>Feature Explanation</title>
<p>To explain the model prediction and determine the feature contribution, LIME is used. LIME provides an interpretable and accurate explanation of classifier predictions by learning a local interpretable model around the prediction [<xref ref-type="bibr" rid="ref-20">20</xref>]. LIME justifies supervised learning model predictions on a variety of data formats, including text and images. It computes essential characteristics around a given instance and creates 5000 feature vector normal distribution samples. This technique works by looking for target variables for a specific number of samples and assigning weights to each row based on how close it is to the original data label. Also, it determines the important features by using feature selection techniques such as lasso and principal component analysis (PCA). This technique has been successfully implemented in XAI for image, text, and tabular data. In this paper, the LIME method is applied for DDOS network flows, which represent tabular data to determine the contribution of each feature in predicting the correct attack type. We used a LIME-based XAI procedure to analyze the contribution of each feature in the traffic data. This helped us to understand how each feature influenced the final decision and to identify any biases or incorrect decisions in the predicted classes of network attacks. A thorough investigation has demonstrated that LIME is the most effective method for describing traffic data qualities and supporting any prediction generated by a supervised learning model, which has been also demonstrated in previous empirical studies [<xref ref-type="bibr" rid="ref-33">33</xref>].</p>
</sec>
</sec>
</sec>
<sec id="s4">
<label>4</label>
<title>Experimental Results and Discussion</title>
<sec id="s4_1">
<label>4.1</label>
<title>Experimental Setup</title>
<p>The experiments were conducted on a professional cloud processing platform equipped with powerful GPUs and CPUs. Several Python and ML libraries were used for implementing the proposed DDoS classifier, e.g., TensorFlow and Keras. The specifications of the client machine used to initiate and control the experiments include Nvidia T4 Tensor Core GPU, Intel core i7 of 3.4 GHz, and RAM of 12 gigabytes (GB). The experiments were performed using identical hyperparameters under the same configuration. The models&#x2019; performance is assessed based on training time complexity and final prediction results. The binary classification experiment uses binary cross entropy as a loss function, and the sigmoid as an activation function for the output layer. Also, the Adam optimizer is used with a learning rate equal to 0.001. A batch size of 128 is used during five epochs, with an early stopping equal to 3. On the other hand, in the multiclassification tasks, categorical cross-entropy is used as a loss function, and SoftMax is applied with a batch size of 64 for ten epochs. <xref ref-type="table" rid="table-6">Table 6</xref> shows the hyperparameters utilized in each experiment.</p>
<table-wrap id="table-6">
<label>Table 6</label>
<caption>
<title>The list of hyper-parameters used in all training experiments</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th>Hyper-Parameter</th>
<th>Binary Classification</th>
<th>Multi Classification</th>
</tr>
</thead>
<tbody>
<tr>
<td>Loss function</td>
<td>Binary cross-entropy</td>
<td>Categorical cross-entropy</td>
</tr>
<tr>
<td>Activation function</td>
<td>Sigmoid</td>
<td>SoftMax</td>
</tr>
<tr>
<td>Optimizer</td>
<td>Adam</td>
<td>Adam</td>
</tr>
<tr>
<td>Epochs</td>
<td>5</td>
<td>10</td>
</tr>
<tr>
<td>Learning rate</td>
<td>0.001</td>
<td>0.001</td>
</tr>
<tr>
<td>Batch size</td>
<td>128</td>
<td>64</td>
</tr>
<tr>
<td>Early stopping</td>
<td>True</td>
<td>True</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>Four distinct standard metrics are used to evaluate the performance of deep learning models, which are accuracy, recall, precision, and F1-score. The metrics are calculated in terms of macro average and weighted average. The weighted averaging metrics tend to the majority class and affect the final decision in the prediction process; therefore, to ensure the validity of the performance results for the used models, we measured their performance using macro averaging, which is not affected by the majority class since it handles all the labels equally by distributing equal weights for each label.</p>
<p>This study focuses on the recall metric, a key metric in DDoS attack detection, to evaluate a model&#x2019;s ability to accurately identify all DDoS network flows, aiming to maximize true positives and minimize false negatives in network flow classification. High recall is essential in DDoS classification due to the significant cost and damage caused by false negatives. It is also important in this work because of the imbalanced class distribution in the dataset. The model often accurately identifies the majority class but fails to identify the infrequent minority class. However, recall is not affected by the imbalanced distribution since a high recall score ensures accurate classification.</p>
</sec>
<sec id="s4_2">
<label>4.2</label>
<title>Classification Results of DDoS Attacks</title>
<p>A thorough analysis of DDoS attacks is presented using various deep learning models. Three experiments are conducted based on the attack type. The first experiment is conducted to detect and classify the network flows based on their general nature, whether they are benign or attack flows. The second experiment presents more detailed results by classifying the detected attacks into eight types. The third experiment provided more details by classifying them into 34 different attack types. In the context of DDoS detection, true positive (TP) represents the correctly classified attacks, true negative (TN) represents the correctly classified non-attacks, false positive (FP) defines non-attacks incorrectly classified as attacks, and false negative (FN) defines attacks incorrectly detected as non-attacks. The primary target for this study is achieving a high recall since the recall represents the ratio of correctly classified DDoS attacks.</p>
<p>Recall estimates the proportion of positive samples identified by a model among all positive samples, aiming to capture as many attacks as possible while minimizing missed attacks. Optimizing for recall ensures the model effectively detects most DDoS attacks, even if it indicates tolerating some false positives that represent normal traffic inaccurately classified as attacks. However, four different deep learning models are used in each experiment, BiLSTM, GRU, RNN, and CNN. <xref ref-type="table" rid="table-7">Tables 7</xref>&#x2013;<xref ref-type="table" rid="table-9">9</xref> demonstrate the detailed results of the deep learning models in each experiment. In the binary classification experiment, the BiLSTM model outperformed all the other models with an accuracy of 99.40, precision of 99.44, recall of 99.39, and F1-score of 99.41 in the weighted averaging measurement. Regarding the macro-averaging, it achieved a precision of 91.50, a recall of 96.21, and an F1-score of 93.72.</p>
<table-wrap id="table-7">
<label>Table 7</label>
<caption>
<title>Summary of the binary classification results</title>
</caption>
<table frame="hsides">
<colgroup>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Model</th>
<th>Val Acc</th>
<th>Test Acc</th>
<th align="center" colspan="3">Weighted Average</th>
<th align="center" colspan="3">Macro Average</th>
</tr>
<tr>
<th/>
<th/>
<th/>
<th>P</th>
<th>R</th>
<th>F</th>
<th>P</th>
<th>R</th>
<th>F</th>
</tr>
</thead>
<tbody>
<tr>
<td>BiLSTM</td>
<td><bold>99.40</bold></td>
<td><bold>99.39</bold></td>
<td><bold>99.44</bold></td>
<td><bold>99.39</bold></td>
<td><bold>99.41</bold></td>
<td>91.50</td>
<td><bold>96.21</bold></td>
<td><bold>93.72</bold></td>
</tr>
<tr>
<td>GRU</td>
<td>99.37</td>
<td><bold>99.39</bold></td>
<td>99.42</td>
<td><bold>99.39</bold></td>
<td>99.40</td>
<td>91.91</td>
<td>95.56</td>
<td>93.66</td>
</tr>
<tr>
<td>RNN</td>
<td>99.33</td>
<td>99.35</td>
<td>99.36</td>
<td>99.35</td>
<td>99.35</td>
<td><bold>92.92</bold></td>
<td>93.04</td>
<td>92.98</td>
</tr>
<tr>
<td>CNN</td>
<td>99.35</td>
<td>99.35</td>
<td>99.39</td>
<td>99.35</td>
<td>99.36</td>
<td>91.19</td>
<td>95.49</td>
<td>93.23</td>
</tr>
</tbody>
</table>
</table-wrap><table-wrap id="table-8">
<label>Table 8</label>
<caption>
<title>Summary of multiclassification results (8-classes)</title>
</caption>
<table frame="hsides">
<colgroup>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Model</th>
<th>Val Acc</th>
<th>Test Acc</th>
<th align="center" colspan="3">Weighted Average</th>
<th align="center" colspan="3">Macro Average</th>
</tr>
<tr>
<th/>
<th/>
<th/>
<th>P</th>
<th>R</th>
<th>F</th>
<th>P</th>
<th>R</th>
<th>F</th>
</tr>
</thead>
<tbody>
<tr>
<td>BiLSTM</td>
<td><bold>99.03</bold></td>
<td><bold>99.04</bold></td>
<td><bold>99.07</bold></td>
<td><bold>99.04</bold></td>
<td><bold>98.97</bold></td>
<td>90.87</td>
<td><bold>66.79</bold></td>
<td><bold>69.62</bold></td>
</tr>
<tr>
<td>GRU</td>
<td>99.00</td>
<td><bold>98.98</bold></td>
<td>99.03</td>
<td>98.98</td>
<td>98.91</td>
<td><bold>92.53</bold></td>
<td>66.07</td>
<td>68.87</td>
</tr>
<tr>
<td>RNN</td>
<td>96.86</td>
<td>96.86</td>
<td>96.91</td>
<td>96.86</td>
<td>96.72</td>
<td>79.42</td>
<td>63.36</td>
<td>66.47</td>
</tr>
<tr>
<td>CNN</td>
<td>99.07</td>
<td>99.00</td>
<td>99.12</td>
<td>99.00</td>
<td>98.92</td>
<td>89.32</td>
<td>65.32</td>
<td>68.35</td>
</tr>
</tbody>
</table>
</table-wrap><table-wrap id="table-9">
<label>Table 9</label>
<caption>
<title>Summary of multiclassification results (34-classes)</title>
</caption>
<table frame="hsides">
<colgroup>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Model</th>
<th>Val Acc</th>
<th>Test Acc</th>
<th align="center" colspan="3">Weighted Average</th>
<th align="center" colspan="3">Macro Average</th>
</tr>
<tr>
<th/>
<th/>
<th/>
<th>P</th>
<th>R</th>
<th>F</th>
<th>P</th>
<th>R</th>
<th>F</th>
</tr>
</thead>
<tbody>
<tr>
<td>BiLSTM</td>
<td><bold>98.44</bold></td>
<td><bold>98.43</bold></td>
<td>98.35</td>
<td><bold>98.43</bold></td>
<td><bold>98.23</bold></td>
<td>71.18</td>
<td><bold>65.17</bold></td>
<td><bold>65.35</bold></td>
</tr>
<tr>
<td>GRU</td>
<td>96.95</td>
<td>98.13</td>
<td>98.10</td>
<td>98.13</td>
<td>97.94</td>
<td>71.88</td>
<td>64.68</td>
<td>64.73</td>
</tr>
<tr>
<td>RNN</td>
<td>94.64</td>
<td>95.98</td>
<td>96.04</td>
<td>95.98</td>
<td>95.75</td>
<td>68.95</td>
<td>60.90</td>
<td>61.11</td>
</tr>
<tr>
<td>CNN</td>
<td>98.32</td>
<td>97.87</td>
<td><bold>98.90</bold></td>
<td>97.87</td>
<td>98.17</td>
<td><bold>76.11</bold></td>
<td>64.28</td>
<td>64.41</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>In the second experiment, it achieved an accuracy of 99.04, a weighted precision of 99.07, a weighted recall of 99.04, a weighted F1-score of 98.97, a macro precision of 90.87, a macro recall of 66.79, and a macro F1-score of 69.62. Also, in the 34-class experiment, it got an accuracy of 98.43, a weighted precision of 98.35, a weighted recall of 98.43, a weighted F1-score of 98.23, a macro precision of 71.18, a macro recall of 65.17, and a macro F1-score of 65.35. The second and third experiments showed a decrease in macro recall due to the complexity of identifying the exact type of DDoS attack, as the model was burdened by the detailed attack type. This paper validated the findings obtained from the CICIoT2023 dataset by evaluating the models using a high-quality dataset collected from real-world scenarios. This dataset is particularly challenging as it serves as a testbed for assessing the algorithms&#x2019; capability to detect network attack flows. We used the CICDDoS2019 dataset to evaluate the selected models under identical settings, employing consistent hyperparameters for comparison.</p>
<p>The Bi-LSTM model exhibited exceptional performance, achieving an accuracy of 99.82. Additionally, it demonstrated a recall rate of 99.82, a precision score of 99.82, and an F1-score of 99.82. These results highlight the robustness and high quality of the model&#x2019;s performance across various metrics. <xref ref-type="table" rid="table-10">Table 10</xref> demonstrates the detailed results of the deep learning models. After validating the results, the models are compared based on their training time complexity. As shown in <xref ref-type="table" rid="table-11">Table 11</xref>, the CNN model outperforms the other models in detecting DDoS attacks, demonstrating superior efficiency with minimal training time.</p>
<table-wrap id="table-10">
<label>Table 10</label>
<caption>
<title>Summary of the classification results on CICDDOS2019</title>
</caption>
<table frame="hsides">
<colgroup>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Model</th>
<th>Val Acc</th>
<th>Test Acc</th>
<th align="center" colspan="3">Weighted Average</th>
<th align="center" colspan="3">Macro Average</th>
</tr>
<tr>
<th/>
<th/>
<th/>
<th>P</th>
<th>R</th>
<th>F</th>
<th>P</th>
<th>R</th>
<th>F</th>
</tr>
</thead>
<tbody>
<tr>
<td>BiLSTM</td>
<td><bold>99.77</bold></td>
<td><bold>99.82</bold></td>
<td><bold>99.82</bold></td>
<td><bold>99.82</bold></td>
<td><bold>99.82</bold></td>
<td><bold>99.65</bold></td>
<td><bold>99.84</bold></td>
<td><bold>99.74</bold></td>
</tr>
<tr>
<td>GRU</td>
<td>99.69</td>
<td>99.73</td>
<td>99.73</td>
<td>99.73</td>
<td>99.73</td>
<td>99.49</td>
<td>99.73</td>
<td>99.61</td>
</tr>
<tr>
<td>RNN</td>
<td>99.70</td>
<td>99.77</td>
<td>99.77</td>
<td>99.77</td>
<td>99.77</td>
<td>99.56</td>
<td>99.77</td>
<td>99.67</td>
</tr>
<tr>
<td>CNN</td>
<td>99.72</td>
<td>99.71</td>
<td>99.71</td>
<td>99.71</td>
<td>99.71</td>
<td>99.43</td>
<td>99.74</td>
<td>99.58</td>
</tr>
</tbody>
</table>
</table-wrap><table-wrap id="table-11">
<label>Table 11</label>
<caption>
<title>A summary of training time complexity</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th>Experiment</th>
<th>Model</th>
<th>Step</th>
<th>Epoch</th>
<th>Training time (minutes)</th>
</tr>
</thead>
<tbody>
<tr>
<td rowspan="4">2-classes</td>
<td>BiLSTM</td>
<td>6 ms</td>
<td>174 s</td>
<td>14.5</td>
</tr>
<tr>
<td>GRU</td>
<td>5 ms</td>
<td>135 s</td>
<td>11.25</td>
</tr>
<tr>
<td><bold>RNN</bold></td>
<td><bold>3 ms</bold></td>
<td><bold>96 s</bold></td>
<td><bold>8</bold></td>
</tr>
<tr>
<td>CNN</td>
<td>8 ms</td>
<td>229 s</td>
<td>19</td>
</tr>
<tr>
<td rowspan="4">8-classes</td>
<td>BiLSTM</td>
<td>12 ms</td>
<td>655 s</td>
<td>109</td>
</tr>
<tr>
<td>GRU</td>
<td>7 ms</td>
<td>374</td>
<td>62</td>
</tr>
<tr>
<td>RNN</td>
<td>5 ms</td>
<td>269 s</td>
<td>44.8</td>
</tr>
<tr>
<td><bold>CNN</bold></td>
<td><bold>4 ms</bold></td>
<td><bold>225 s</bold></td>
<td><bold>26.25</bold></td>
</tr>
<tr>
<td rowspan="4">34-classes</td>
<td>BiLSTM</td>
<td>9 ms</td>
<td>530 s</td>
<td>80.3</td>
</tr>
<tr>
<td>GRU</td>
<td>7 ms</td>
<td>414 s</td>
<td>69</td>
</tr>
<tr>
<td>RNN</td>
<td>6 ms</td>
<td>321 s</td>
<td>53</td>
</tr>
<tr>
<td><bold>CNN</bold></td>
<td><bold>8 ms</bold></td>
<td><bold>229 s</bold></td>
<td><bold>19</bold></td>
</tr>
<tr>
<td rowspan="4">CICDDoS2019</td>
<td>BiLSTM</td>
<td>7 ms</td>
<td>17 s</td>
<td>1.41</td>
</tr>
<tr>
<td>GRU</td>
<td>6 ms</td>
<td>15 s</td>
<td>1.25</td>
</tr>
<tr>
<td>RNN</td>
<td>5 ms</td>
<td>12 s</td>
<td>1</td>
</tr>
<tr>
<td><bold>CNN</bold></td>
<td><bold>4 ms</bold></td>
<td><bold>10 s</bold></td>
<td>&#x003C;<bold>1</bold></td>
</tr>
</tbody>
</table>
</table-wrap>
<p>BiLSTM and GRU models need additional training time because of their complex architectures and increased processing demands. As the number of classes increases, there will be more training time for all models. Nevertheless, the importance differs per model. For example, with the BiLSTM model, training time increases dramatically as the number of classes increases, but the CNN model has rather steady training times across varied class distributions.</p>
<p>Training time varied throughout the experiments, with RNN taking the least time in the 2-classes experiment, followed by GRU and BiLSTM, and CNN taking the longest. However, the model architecture plays a significant role in determining training time complexity. Variations in model parameter values, such as step size and epoch, can also influence training time complexity. This demonstrates the tradeoff between high performance and accurate results, which necessitates an extensive amount of time for training the model. However, the results indicate that incorporating explainable AI techniques into network security systems allows organizations to understand complex decisions made by AI models, improving the transparency and reliability of automated defense mechanisms. This builds trust in AI-powered security solutions. Understanding how AI models differentiate between normal network traffic and malicious attacks enables proactive response strategies, reducing DDoS attacks and downtime. This reduces the risk of misidentifying events as attacks and unauthorized resource usage. It also enhances the system&#x2019;s ability to detect insider threats and abnormal activities.</p>
</sec>
<sec id="s4_3">
<label>4.3</label>
<title>The Impact of Feature Explanation on DDoS Detection</title>
<p>The LIME-based XAI technique is employed to explain the contribution of each feature in the decision-making process during the prediction phase. The XAI technique utilizes tabular data through four steps: generating perturbed instances, predicting using a black-box model, fitting an interpretable model, and explaining the prediction. In the first step, it produces perturbed instances from the original data, randomly perturbing certain attributes while maintaining others constant. Then, the black-box model is used to predict labels for perturbed instances, allowing for a better understanding of how changes in feature values affect the model&#x2019;s predictions. Then, an interpretable model, in our case linear regression, is applied to the altered instances and their accompanying predictions, serving as a surrogate of the black-box model&#x2019;s behavior at the closest distance to the original data. LIME does not directly deal with optimization but focuses on finding an interpretable model that best explains the model&#x2019;s predictions in the local neighborhood of a data point. It uses a sampling-based approach to generate perturbed instances of input data, reducing the likelihood of getting stuck at local optima.</p>
<p>Finally, the XAI model examines interpretable model coefficients or decision rules, providing explanations for the most important elements driving model prediction in a given instance. The outcome of this process is evaluating the contribution of each feature by assigning weights for each feature to determine the power of its effect on the prediction result and determine whether this effect is negative or positive. <xref ref-type="fig" rid="fig-4">Fig. 4</xref> shows six instances from the binary classification task, with 0 indicating benign network flow and 1 indicating an attack. In the first three instances, features such as information assurance technical (IAT), Max, Total Size, DNS, and Rate have a positive effect by helping the model correctly classify the instance into its correct class label. On the other hand, features such as header length have a positive impact on the left three instances while harming the right three instances.</p>
<fig id="fig-4">
<label>Figure 4</label>
<caption>
<title>The feature explanation for six instances in the binary classification task</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_52599-fig-4.tif"/>
</fig>
<p>The contribution of features varies based on their value, target class label, and situation. <xref ref-type="fig" rid="fig-5">Fig. 5</xref> shows the feature explanations for the 8-class task with one instance per class. The 0 refers to Benign, 1 refers to Brute-Force, 2 indicates DDoS, 3 refers to DoS, 4 represents Mirai, 5 refers to Recon, 6 indicates Spoofing, and 7 refers to Web. As can be observed from the figure, the prediction probabilities for 1 and 7 are 82% and 85%, respectively, indicating the model&#x2019;s confusion in class label prediction. The vast majority of the features have a positive impact on the final result, which reflects how the model accurately classifies network flows into their specific attack type. However, some features have a negative impact, such as the HTTP feature.</p>
<fig id="fig-5">
<label>Figure 5</label>
<caption>
<title>The feature explanation for eight instances in the multiclassification task</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_52599-fig-5.tif"/>
</fig>
</sec>
</sec>
<sec id="s5">
<label>5</label>
<title>Conclusion</title>
<p>This paper presents an efficient approach for automatically detecting DDoS attacks in IoT environments. The proposed model investigates and combines various deep learning algorithms and uses XAI to interpret the model predictions. Three different experiments were conducted with varying levels of attack-type complexity to test the system. In all experiments, BiLSTM outperformed the other models, with recalls of 99.39%, 66.79%, and 65.17%, respectively. On the other hand, the CNN model outperformed the other models in detecting DDoS attacks, demonstrating superior efficiency with minimal training time. The CNN model is highly parallelizable, which means it can efficiently perform parallel computations on the used GPU. This model reduces parameters through parameter sharing, resulting in faster and more stable training. This demonstrates the tradeoff between high performance and accurate results, which necessitates an extensive amount of time for training the model. The primary limitation of this study lies in the benchmarking dataset, which is quite large. This posed challenges in extracting and interpreting the entire traffic data thoroughly, potentially impacting the model&#x2019;s generalization ability. Although the evaluation was performed on another recent DDoS dataset, further processing could be applied to filter the traffic DDoS categories, thereby enhancing the quality of learnable features. Many future directions may include developing a federated learning framework for detecting IoT network attacks and creating reliable datasets to improve the accuracy of deep learning models for detecting DDoS attacks.</p>
</sec>
</body>
<back>
<ack>
<p>The authors would like to thank the anonymous reviewers for their constructive feedback and insightful comments, which helped us in improving the quality of the manuscript.</p>
</ack>
<sec><title>Funding Statement</title>
<p>The authors received no specific funding for this study.</p>
</sec>
<sec><title>Author Contributions</title>
<p>Conceptualization, Ahmad Alzu&#x2019;bi, Amjad Albashayreh, and Abdelrahman Abuarqoub; methodology, Ahmad Alzu&#x2019;bi, Amjad Albashayreh, Abdelrahman Abuarqoub, and Mai A. M. Alfawair; formal analysis, Ahmad Alzu&#x2019;bi, and Amjad Albashayreh; investigation, Abdelrahman Abuarqoub, and Mai A. M. Alfawair; data curation, Amjad Albashayreh; writing&#x2014;original draft preparation, Ahmad Alzu&#x2019;bi, and Amjad Albashayreh; writing&#x2014;review and editing, Abdelrahman Abuarqoub, and Mai A. M. Alfawair; visualization, Ahmad Alzu&#x2019;bi, and Amjad Albashayreh; supervision, Ahmad Alzu&#x2019;bi; project administration, Abdelrahman Abuarqoub, and Mai A. M. Alfawair; correspondence author, Ahmad Alzu&#x2019;bi. All authors reviewed the results and approved the final version of the manuscript.</p>
</sec>
<sec sec-type="data-availability"><title>Availability of Data and Materials</title>
<p>The CICIoT2023 dataset is publicly available on <ext-link ext-link-type="uri" xlink:href="https://www.unb.ca/cic/datasets/iotdataset-2023.html">https://www.unb.ca/cic/datasets/iotdataset-2023.html</ext-link>, accessed on 8 April 2024. The CICDDoS2019 dataset is publicly available on <ext-link ext-link-type="uri" xlink:href="https://www.unb.ca/cic/datasets/ddos-2019.html">https://www.unb.ca/cic/datasets/ddos-2019.html</ext-link>, accessed on 5 May 2024.</p>
</sec>
<sec><title>Ethics Approval</title>
<p>Not applicable.</p>
</sec>
<sec sec-type="COI-statement"><title>Conflicts of Interest</title>
<p>The authors declare that they have no conflicts of interest to report regarding the present study.</p>
</sec>
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>T.</given-names> <surname>Alam</surname></string-name></person-group>, &#x201C;<article-title>A reliable communication framework and its use in Internet of Things (IoT)</article-title>,&#x201D; vol. <volume>10</volume>, pp. <fpage>450</fpage>&#x2013;<lpage>456</lpage>, <year>2018</year>. doi: <pub-id pub-id-type="doi">10.36227/techrxiv.12657158.v1</pub-id>.</mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Z. A.</given-names> <surname>El Houda</surname></string-name>, <string-name><given-names>B.</given-names> <surname>Brik</surname></string-name>, and <string-name><given-names>S. -M.</given-names> <surname>Senouci</surname></string-name></person-group>, &#x201C;<article-title>A novel IoT-based explainable deep learning framework for intrusion detection systems</article-title>,&#x201D; <source>IEEE Internet Things Mag.</source>, vol. <volume>5</volume>, no. <issue>2</issue>, pp. <fpage>20</fpage>&#x2013;<lpage>23</lpage>, <year>Jun. 2022</year>. doi: <pub-id pub-id-type="doi">10.1109/IOTM.005.2200028</pub-id>.</mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Abbas</surname></string-name> <etal>et al.</etal></person-group>, &#x201C;<article-title>A novel federated edge learning approach for detecting cyberattacks in IoT infrastructures</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>11</volume>, pp. <fpage>112189</fpage>&#x2013;<lpage>112198</lpage>, <year>2023</year>.</mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Langiu</surname></string-name>, <string-name><given-names>C. A.</given-names> <surname>Boano</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Schu&#x00DF;</surname></string-name>, and <string-name><given-names>K.</given-names> <surname>R&#x00F6;mer</surname></string-name></person-group>, &#x201C;<article-title>UpKit: An open-source, portable, and lightweight update framework for constrained IoT devices</article-title>,&#x201D; in <conf-name>2019 IEEE 39th Int. Conf. Distrib. Comput. Syst. (ICDCS)</conf-name>, <publisher-loc>Dallas, TX, USA</publisher-loc>, <year>2019</year>, pp. <fpage>2101</fpage>&#x2013;<lpage>2112</lpage>.</mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>D.</given-names> <surname>Canavese</surname></string-name>, <string-name><given-names>L.</given-names> <surname>Mannella</surname></string-name>, <string-name><given-names>L.</given-names> <surname>Regano</surname></string-name>, and <string-name><given-names>C.</given-names> <surname>Basile</surname></string-name></person-group>, &#x201C;<article-title>Security at the edge for resource-limited IoT devices</article-title>,&#x201D; <source>Sensors</source>, vol. <volume>24</volume>, no. <issue>2</issue>, <year>2024</year>, Art. no. 590. doi: <pub-id pub-id-type="doi">10.3390/s24020590</pub-id>; <pub-id pub-id-type="pmid">38257680</pub-id></mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Tabassum</surname></string-name> and <string-name><given-names>W.</given-names> <surname>Lebda</surname></string-name></person-group>, &#x201C;<article-title>Security framework for IoT devices against cyber-attacks</article-title>,&#x201D; <comment>arXiv preprint arXiv:1912.01712</comment>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-7"><label>[7]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Alzu&#x2019;bi</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Alomar</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Alkhaza&#x2019;leh</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Abuarqoub</surname></string-name>, and <string-name><given-names>M.</given-names> <surname>Hammoudeh</surname></string-name></person-group>, &#x201C;<article-title>A review of privacy and security of edge computing in smart healthcare systems: Issues, challenges, and research directions</article-title>,&#x201D; <source>Tsinghua Sci. Technol.</source>, vol. <volume>29</volume>, no. <issue>4</issue>, pp. <fpage>1152</fpage>&#x2013;<lpage>1180</lpage>, <year>Aug. 2024</year>. doi: <pub-id pub-id-type="doi">10.26599/TST.2023.9010080</pub-id>.</mixed-citation></ref>
<ref id="ref-8"><label>[8]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>T. -L.</given-names> <surname>Nguyen</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Kao</surname></string-name>, <string-name><given-names>T. -T.</given-names> <surname>Nguyen</surname></string-name>, <string-name><given-names>M. -F.</given-names> <surname>Horng</surname></string-name>, and <string-name><given-names>C. -S.</given-names> <surname>Shieh</surname></string-name></person-group>, &#x201C;<article-title>Unknown DDoS attack detection with fuzzy C-means clustering and spatial location constraint prototype loss</article-title>,&#x201D; <source>Comput. Mater. Contin.</source>, vol. <volume>78</volume>, pp. <fpage>1</fpage>&#x2013;<lpage>10</lpage>, <year>2024</year>. doi: <pub-id pub-id-type="doi">10.32604/cmc.2024.047387</pub-id>.</mixed-citation></ref>
<ref id="ref-9"><label>[9]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>R.</given-names> <surname>Vishwakarma</surname></string-name> and <string-name><given-names>A. K.</given-names> <surname>Jain</surname></string-name></person-group>, &#x201C;<article-title>A survey of DDoS attacking techniques and defence mechanisms in the IoT network</article-title>,&#x201D; <source>Telecommun. Syst.</source>, vol. <volume>73</volume>, no. <issue>1</issue>, pp. <fpage>3</fpage>&#x2013;<lpage>25</lpage>, <year>2019</year>. doi: <pub-id pub-id-type="doi">10.1007/s11235-019-00599-z</pub-id>.</mixed-citation></ref>
<ref id="ref-10"><label>[10]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S. K.</given-names> <surname>Jagatheesaperumal</surname></string-name>, <string-name><given-names>Q. -V.</given-names> <surname>Pham</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Ruby</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Yang</surname></string-name>, <string-name><given-names>C.</given-names> <surname>Xu</surname></string-name> and <string-name><given-names>Z.</given-names> <surname>Zhang</surname></string-name></person-group>, &#x201C;<article-title>Explainable AI over the Internet of Things (IoT): Overview, state-of-the-art and future directions</article-title>,&#x201D; <source>IEEE Open J. Commun. Soc.</source>, vol. <volume>3</volume>, pp. <fpage>2106</fpage>&#x2013;<lpage>2136</lpage>, <year>2022</year>. doi: <pub-id pub-id-type="doi">10.1109/OJCOMS.2022.3215676</pub-id>.</mixed-citation></ref>
<ref id="ref-11"><label>[11]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>E. C. P.</given-names> <surname>Neto</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Dadkhah</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Ferreira</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Zohourian</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Lu</surname></string-name> and <string-name><given-names>A. A.</given-names> <surname>Ghorbani</surname></string-name></person-group>, &#x201C;<article-title>CICIoT2023: A real-time dataset and benchmark for large-scale attacks in IoT environment</article-title>,&#x201D; <source>Sensors</source>, vol. <volume>23</volume>, no. <issue>13</issue>, <year>2023</year>, Art. no. 5941. doi: <pub-id pub-id-type="doi">10.3390/s23135941</pub-id>; <pub-id pub-id-type="pmid">37447792</pub-id></mixed-citation></ref>
<ref id="ref-12"><label>[12]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>N.</given-names> <surname>Sharmin</surname></string-name> and <string-name><given-names>C.</given-names> <surname>Kiekintveld</surname></string-name></person-group>, &#x201C;<article-title>Enhancing IoT device security: Predicting and analyzing reconnaissance attacks using flags and time-based attributes</article-title>,&#x201D; in <conf-name>2023 10th Int. Conf. Internet of Things: Syst., Manage. Secur. (IOTSMS)</conf-name>, <publisher-loc>San Antonio, TX, USA</publisher-loc>, <publisher-name>IEEE</publisher-name>, <year>2023</year>, pp. <fpage>23</fpage>&#x2013;<lpage>30</lpage>.</mixed-citation></ref>
<ref id="ref-13"><label>[13]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Z.</given-names> <surname>Wang</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Chen</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Yang</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Luo</surname></string-name>, <string-name><given-names>D.</given-names> <surname>Li</surname></string-name> and <string-name><given-names>J.</given-names> <surname>Wang</surname></string-name></person-group>, &#x201C;<article-title>A lightweight intrusion detection method for IoT based on deep learning and dynamic quantization</article-title>,&#x201D; <source>PeerJ Comput. Sci.</source>, vol. <volume>9</volume>, <year>2023</year>, <publisher-name>Art. no. e1569</publisher-name>.</mixed-citation></ref>
<ref id="ref-14"><label>[14]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M. M.</given-names> <surname>Khan</surname></string-name> and <string-name><given-names>M.</given-names> <surname>Alkhathami</surname></string-name></person-group>, &#x201C;<article-title>Anomaly detection in IoT-based healthcare: Machine learning for enhanced security</article-title>,&#x201D; <source>Sci. Rep.</source>, vol. <volume>14</volume>, no. <issue>1</issue>, <year>2024</year>, <publisher-name>Art. no. 5872</publisher-name>.</mixed-citation></ref>
<ref id="ref-15"><label>[15]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Yaras</surname></string-name> and <string-name><given-names>M.</given-names> <surname>Dener</surname></string-name></person-group>, &#x201C;<article-title>IoT-based intrusion detection system using new hybrid deep learning algorithm</article-title>,&#x201D; <source>Electronics</source>, vol. <volume>13</volume>, no. <issue>6</issue>, <year>2024</year>, <comment>Art. no. 1053</comment>.</mixed-citation></ref>
<ref id="ref-16"><label>[16]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>N.</given-names> <surname>Moustafa</surname></string-name></person-group>, &#x201C;<article-title>A new distributed architecture for evaluating AI-based security systems at the edge: Network TON_IoT datasets</article-title>,&#x201D; <source>Sustain. Cities Soc.</source>, vol. <volume>72</volume>, <year>2021</year>, Art. no. 102994. doi: <pub-id pub-id-type="doi">10.1016/j.scs.2021.102994</pub-id>.</mixed-citation></ref>
<ref id="ref-17"><label>[17]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>E. O.</given-names> <surname>Gyamfi</surname></string-name> <etal>et al.</etal></person-group>, &#x201C;<article-title>A model-agnostic XAI approach for developing low-cost IoT intrusion detection dataset</article-title>,&#x201D; <source>J. Inform. Secur. Cyber. Res.</source>, vol. <volume>6</volume>, no. <issue>2</issue>, pp. <fpage>74</fpage>&#x2013;<lpage>88</lpage>, <year>2023</year>. doi: <pub-id pub-id-type="doi">10.26735/LPAO2070</pub-id>.</mixed-citation></ref>
<ref id="ref-18"><label>[18]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M. K.</given-names> <surname>Hasan</surname></string-name> <etal>et al.</etal></person-group>, &#x201C;<article-title>An explainable ensemble deep learning approach for intrusion detection in industrial Internet of Things</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>11</volume>, pp. <fpage>115047</fpage>&#x2013;<lpage>115061</lpage>, <year>2023</year>.</mixed-citation></ref>
<ref id="ref-19"><label>[19]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Bashaiwth</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Binsalleeh</surname></string-name>, and <string-name><given-names>B.</given-names> <surname>AsSadhan</surname></string-name></person-group>, &#x201C;<article-title>An explanation of the LSTM model used for DDoS attacks classification</article-title>,&#x201D; <source>Appl. Sci.</source>, vol. <volume>13</volume>, no. <issue>15</issue>, <year>2023</year>, <comment>Art. no. 8820</comment>.</mixed-citation></ref>
<ref id="ref-20"><label>[20]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>M. T.</given-names> <surname>Ribeiro</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Singh</surname></string-name>, and <string-name><given-names>C.</given-names> <surname>Guestrin</surname></string-name></person-group>, &#x201C;<article-title>Why should I trust you? Explaining the predictions of any classifier</article-title>,&#x201D; in <conf-name>Proc. 22nd ACM SIGKDD Int. Conf. Knowl. Dis. Data Min.</conf-name>, <publisher-loc>San Diego, CA, USA</publisher-loc>, <year>2016</year>, pp. <fpage>1135</fpage>&#x2013;<lpage>1144</lpage>.</mixed-citation></ref>
<ref id="ref-21"><label>[21]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>F.</given-names> <surname>Hassan</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Yu</surname></string-name>, <string-name><given-names>Z. S.</given-names> <surname>Syed</surname></string-name>, <string-name><given-names>A. H.</given-names> <surname>Magsi</surname></string-name>, and <string-name><given-names>N.</given-names> <surname>Ahmed</surname></string-name></person-group>, &#x201C;<article-title>Developing transparent IDS for VANETs using LIME and SHAP: An empirical study</article-title>,&#x201D; <source>Comput. Mater. Contin.</source>, vol. <volume>77</volume>, no. <issue>3</issue>, pp. <fpage>3185</fpage>&#x2013;<lpage>3208</lpage>, <year>2023</year>. doi: <pub-id pub-id-type="doi">10.32604/cmc.2023.044650</pub-id>.</mixed-citation></ref>
<ref id="ref-22"><label>[22]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><given-names>Y.</given-names> <surname>Wei</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Jang-Jaccard</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Singh</surname></string-name>, <string-name><given-names>F.</given-names> <surname>Sabrina</surname></string-name>, and <string-name><given-names>S.</given-names> <surname>Camtepe</surname></string-name></person-group>, &#x201C;<article-title>Classification and explanation of distributed Denial-of-Service (DDoS) attack detection using machine learning and shapley additive explanation (SHAP) methods</article-title>,&#x201D; <comment>arXiv preprint arXiv:2306.17190</comment>, <year>2023</year>.</mixed-citation></ref>
<ref id="ref-23"><label>[23]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Tabassum</surname></string-name>, <string-name><given-names>N.</given-names> <surname>Parvin</surname></string-name>, <string-name><given-names>N.</given-names> <surname>Hossain</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Tasnim</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Rahman</surname></string-name> and <string-name><given-names>M. I.</given-names> <surname>Hossain</surname></string-name></person-group>, &#x201C;<article-title>IoT network attack detection using XAI and reliability analysis</article-title>,&#x201D; in <conf-name>2022 25th Int. Conf. Comput. Inform. Technol. (ICCIT)</conf-name>, <publisher-name>Cox&#x2019;s Bazar</publisher-name>, <publisher-loc>Bangladesh</publisher-loc>, <year>2022</year>, pp. <fpage>176</fpage>&#x2013;<lpage>181</lpage>.</mixed-citation></ref>
<ref id="ref-24"><label>[24]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>L.</given-names> <surname>Antwarg</surname></string-name>, <string-name><given-names>R. M.</given-names> <surname>Miller</surname></string-name>, <string-name><given-names>B.</given-names> <surname>Shapira</surname></string-name>, and <string-name><given-names>L.</given-names> <surname>Rokach</surname></string-name></person-group>, &#x201C;<article-title>Explaining anomalies detected by autoencoders using shapley additive explanations</article-title>,&#x201D; <source>Expert Syst. Appl.</source>, vol. <volume>186</volume>, <year>2021</year>, <comment>Art. no. 115736</comment>.</mixed-citation></ref>
<ref id="ref-25"><label>[25]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>T.</given-names> <surname>Senevirathna</surname></string-name>, <string-name><given-names>B.</given-names> <surname>Siniarski</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Liyanage</surname></string-name>, and <string-name><given-names>S.</given-names> <surname>Wang</surname></string-name></person-group>, &#x201C;<article-title>Deceiving post-hoc explainable AI (XAI) methods in network intrusion detection</article-title>,&#x201D; in <conf-name>2024 IEEE 21st Consum. Commun. Netw. Conf. (CCNC)</conf-name>, <publisher-loc>Las Vegas, NV, USA</publisher-loc>, <publisher-name>IEEE</publisher-name>, <year>2024</year>, pp. <fpage>107</fpage>&#x2013;<lpage>112</lpage>.</mixed-citation></ref>
<ref id="ref-26"><label>[26]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>O.</given-names> <surname>Arreche</surname></string-name>, <string-name><given-names>T. R.</given-names> <surname>Guntur</surname></string-name>, <string-name><given-names>J. W.</given-names> <surname>Roberts</surname></string-name>, and <string-name><given-names>M.</given-names> <surname>Abdallah</surname></string-name></person-group>, &#x201C;<article-title>E-XAI: Evaluating black-box explainable AI frameworks for network intrusion detection</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>12</volume>, pp. <fpage>23954</fpage>&#x2013;<lpage>23988</lpage>, <year>2024</year>. doi: <pub-id pub-id-type="doi">10.1109/ACCESS.2024.3365140</pub-id>.</mixed-citation></ref>
<ref id="ref-27"><label>[27]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>U.</given-names> <surname>Do</surname></string-name>, <string-name><given-names>L.</given-names> <surname>Lahesoo</surname></string-name>, <string-name><given-names>R. M.</given-names> <surname>Carnier</surname></string-name>, and <string-name><given-names>K.</given-names> <surname>Fukuda</surname></string-name></person-group>, &#x201C;<article-title>Evaluation of XAI algorithms in IoT traffic anomaly detection</article-title>,&#x201D; in <conf-name>2024 Int. Conf. Artif. Intell. Inform. Commun. (ICAIIC)</conf-name>, <publisher-loc>Osaka, Japan</publisher-loc>, <publisher-name>IEEE</publisher-name>, <year>2024</year>, pp. <fpage>669</fpage>&#x2013;<lpage>674</lpage>.</mixed-citation></ref>
<ref id="ref-28"><label>[28]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>I.</given-names> <surname>Sharafaldin</surname></string-name>, <string-name><given-names>A. H.</given-names> <surname>Lashkari</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Hakak</surname></string-name>, and <string-name><given-names>A. A.</given-names> <surname>Ghorbani</surname></string-name></person-group>, &#x201C;<article-title>Developing realistic distributed denial of service (DDoS) attack dataset and taxonomy</article-title>,&#x201D; in <conf-name>2019 Int. Carnahan Conf. Secur. Technol. (ICCST)</conf-name>, <publisher-loc>Chennai, India</publisher-loc>, <publisher-name>IEEE</publisher-name>, <year>Oct. 2019</year>, pp. <fpage>1</fpage>&#x2013;<lpage>8</lpage>.</mixed-citation></ref>
<ref id="ref-29"><label>[29]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>M&#x00E9;ndez</surname></string-name>, <string-name><given-names>M. G.</given-names> <surname>Merayo</surname></string-name>, and <string-name><given-names>M.</given-names> <surname>N&#x00FA;&#x00F1;ez</surname></string-name></person-group>, &#x201C;<article-title>Long-term traffic flow forecasting using a hybrid CNN-BiLSTM model</article-title>,&#x201D; <source>Eng. Appl. Artif. Intell.</source>, vol. <volume>121</volume>, <year>2023</year>, <comment>Art. no. 106041</comment>.</mixed-citation></ref>
<ref id="ref-30"><label>[30]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>L.</given-names> <surname>Mohammadpour</surname></string-name>, <string-name><given-names>T. C.</given-names> <surname>Ling</surname></string-name>, <string-name><given-names>C. S.</given-names> <surname>Liew</surname></string-name>, and <string-name><given-names>A.</given-names> <surname>Aryanfar</surname></string-name></person-group>, &#x201C;<article-title>A survey of CNN-based network intrusion detection</article-title>,&#x201D; <source>Appl. Sci.</source>, vol. <volume>12</volume>, no. <issue>16</issue>, <year>2022</year>, <comment>Art. no. 8162</comment>.</mixed-citation></ref>
<ref id="ref-31"><label>[31]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M. V. O.</given-names> <surname>Assis</surname></string-name>, <string-name><given-names>L. F.</given-names> <surname>Carvalho</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Lloret</surname></string-name>, and <string-name><given-names>M. L.</given-names> <surname>Proen&#x00E7;a</surname> <suffix>Jr</suffix></string-name></person-group>, &#x201C;<article-title>A GRU deep learning system against attacks in software defined networks</article-title>,&#x201D; <source>J. Netw. Comput. Appl.</source>, vol. <volume>177</volume>, <year>2021</year>, <comment>Art. no. 102942</comment>.</mixed-citation></ref>
<ref id="ref-32"><label>[32]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>K.</given-names> <surname>Kim</surname></string-name>, <string-name><given-names>J. -H.</given-names> <surname>Lee</surname></string-name>, <string-name><given-names>H. -K.</given-names> <surname>Lim</surname></string-name>, <string-name><given-names>S. W.</given-names> <surname>Oh</surname></string-name>, and <string-name><given-names>Y. -H.</given-names> <surname>Han</surname></string-name></person-group>, &#x201C;<article-title>Deep RNN-based network traffic classification scheme in edge computing system</article-title>,&#x201D; <source>Comput. Sci. Inf. Syst.</source>, vol. <volume>19</volume>, no. <issue>1</issue>, pp. <fpage>165</fpage>&#x2013;<lpage>184</lpage>, <year>2022</year>. doi: <pub-id pub-id-type="doi">10.2298/CSIS200424038K</pub-id>.</mixed-citation></ref>
<ref id="ref-33"><label>[33]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><given-names>P.</given-names> <surname>Gohel</surname></string-name>, <string-name><given-names>P.</given-names> <surname>Singh</surname></string-name>, and <string-name><given-names>M.</given-names> <surname>Mohanty</surname></string-name></person-group>, &#x201C;<article-title>Explainable AI: Current status and future directions</article-title>,&#x201D; <comment>arXiv preprint arXiv:2107.07045</comment>, <year>2021</year>.</mixed-citation></ref>
</ref-list>
</back></article>