Architecting Post-Hoc Explainable Artificial Intelligence Frameworks For Verifiable, Transparent, And Auditable Deep Learning Network Intrusion Controls

17 Jul

Authors: Aravind Chagantipati

Abstract: Although multi-layered neural architectures deliver exceptional precision in autonomous cyber threat identification, their complex internal mechanisms remain functionally opaque. This hidden operational layer compromises institutional trust, severely impacts the speed of post-incident forensic validation, and introduces regulatory compliance vulnerabilities under modern international data governance mandates. This study introduces an operational deployment strategy that embeds post-hoc Explainable AI (XAI) methodology—specifically leveraging Shapley Additive Explanations (SHAP) and Local Interpretable Model-agnostic Explanations (LIME)—directly onto high-performance network anomaly classifiers. Comprehensive experimental assessments utilizing the NSL-KDD, CICIDS, and UNSW-NB15 reference datasets reveal that while the SHAP framework establishes rigorous global structural stability, the LIME tool yields rapid, localized diagnostic clarity for isolated alerts.

DOI: http://doi.org/10.5281/zenodo.21412639