Governance-Aware Explainable AI for Cybersecurity Threat Detection and Risk-Based Response
Abstract
Artificial intelligence is increasingly used in cybersecurity operations for intrusion detection, anomaly discovery, malware analysis, and alert triage. However, many AI-based security systems remain weakly interpretable and disconnected from governance and risk-management practices used by security teams. This paper proposes a governance-aware explainable AI framework that transforms model outputs into analyst-readable evidence packages for threat detection and risk-based response. The framework integrates machine-learning detection, SHAP-based feature attribution, MITRE ATT&CK-oriented behavioral hypothesis mapping, contextual risk scoring, and analyst feedback. A reproducible leakage-aware validation was conducted on a public CICIDS2017-derived sample. The upstream file contained 56,661 labeled flows; 12,598 exact duplicate feature/label rows were removed before splitting, leaving 44,063 records. A group-aware held-out split produced zero exact feature-vector overlap between training and test partitions. In the binary benign-versus-attack task, sigmoid-calibrated Random Forest achieved 0.993 accuracy, 0.993 balanced accuracy, 0.995 precision, 0.990 recall, 0.993 F1-score, 0.9992 ROC-AUC, 0.9990 PR-AUC, and 0.0059 Brier score. Original-label outcomes are reported to avoid hiding rare-class behavior. The reported run used mean absolute SHAP values for global attribution and representative local SHAP examples covering true-positive, false-positive, false-negative, and true-negative cases. The risk-response layer is evaluated as an illustrative governance mechanism because the public CSV does not contain organization-specific asset criticality. Results are interpreted as leakage-aware public-sample validation, not as a full official CICIDS2017 benchmark. The framework supports transparent, reproducible, and risk-aware AI adoption in security operations centers while preserving human analyst judgment.
Keywords
References
- Arreche, O., Guntur, T., & Abdallah, M. (2024a). Xai-ids: Toward proposing an explainable artificial intelligence framework for enhancing network intrusion detection systems. Applied Sciences, 14(10), Article 4170. https://doi.org/10.3390/App14104170
- Arreche, O., Guntur, T. R., Roberts, J. W., & Abdallah, M.(2024b). E-xai: Evaluating black-box explainable ai frameworks for network intrusion detection. IEEE Access, 12, 23954–23988. https://doi.org/10.1109/ACCESS.2024.3365140
- Barredo Arrieta, A., Díaz-Rodríguez, N., Del Ser, J., Bennetot, A., Tabik, S., Barbado, A., García, S., Gil-López, S., Molina, D., Benjamins, R., Chatila, R., & Herrera, F. (2020). Explainable artificial intelligence (XAI): Concepts, taxonomies, opportunities and challenges toward responsible AI. Information Fusion, 58, 82–115. https://doi.org/10.1016/j.inffus.2019.12.012
- Biggio, B., & Roli, F.(2018). Wild patterns: Ten years after the rise of adversarial machine learning. Pattern Recognition, 84, 317–331. https://doi.org/10.1016/j.patcog.2018.07.023
- Buczak, A. L., & Guven, E. (2016). A survey of data mining and machine learning methods for cyber security intrusion detection. IEEE Communications Surveys & Tutorials,18(2),1153–1176. https://doi.org/10.1109/COMST.2015.2494502
- Doshi-Velez, F., & Kim, B. (2017). Towards a rigorous science of interpretable machine learning. arXiv: 1702.08608.
- Engelen, G., Rimmer, V., & Joosen, W. (2021). Troubleshooting an intrusion detection dataset: The CICIDS 2017 case study. 2021 IEEE Security and Privacy Workshops (SPW), 7–12. https://doi.org/10.1109/SPW53761.2021.00009
- Ferrag, M. A., Maglaras, L., Moschoyiannis, S., & Janicke, H. (2020). Deep learning for cyber security intrusion detection: Approaches, datasets, and comparative study. Journal of Information Security and Applications, 50, Article 102419. https://doi.org/10.1016/j.jisa.2019.102419
Details
Primary Language
English
Subjects
Software and Application Security
Journal Section
Research Article
Authors
Ercan Erkalkan
*
0000-0001-9259-7112
Türkiye
Publication Date
September 17, 2026
Submission Date
May 11, 2026
Acceptance Date
July 31, 2026
Published in Issue
Year 2026 Volume: 3 Number: 1