Exploring the intersection of machine learning and explainable artificial intelligence: An analysis and validation of ML models through XAI for intrusion detection

Citation

Rahman, M., Navid, R. K., Bhuyain, M. M. H., Hasan, F. F., & Nup, N. A. (2025). Exploring the intersection of machine learning and explainable artificial intelligence: An analysis and validation of ml models through xai for intrusion detection. In N. Siddique, M. S. Arefin, S. R. Haider Noori, & M. S. Kaiser, Intelligent Networks and Systems (1st ed., pp. 222–242). Chapman and Hall/CRC. https://doi.org/10.1201/9781032659770-17

Abstract

The use of machine learning models has greatly enhanced the capability to recognize patterns and draw conclusions. However, due to their black-box nature, it can be difficult to comprehend the factors that affect their decisions. XAI methods offer transparency into these models and aid in enhancing comprehension, examination and trust in their outcomes. In this chapter, we present a study on the use of machine learning(ML) models for intrusion detection in Windows 10 Operating systems using the ToN-IoT dataset. We investigate the performance of different ML models including tree-based models such as Decision Tree(DT), Random Forest(RF), Logistic Regression(LR) and K-Nearest Neighbors(KNN) in detecting these attacks. Furthermore, for the first time we use Explainable Artificial Intelligence(XAI) techniques to understand how the attacks influence the processes in Windows 10 systems and how they can be identified and prevented. Our study highlights the importance of using XAI techniques to make ML models more interpretable and trustworthy in high-stakes applications such as intrusion detection. We believe that this work can contribute to the development of more robust and secure operating systems. © 2026 selection and editorial matter, Nazmul Siddique, Mohammad Shamsul Arefin, Sheak Rashed Haider Noori, and M Shamim Kaiser; individual chapters, the contributors.

Description

Type

Book Chapter