eX-NIDS: A Framework for Explainable Network Intrusion Detection Leveraging Large Language Models

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Houssel, Paul R. B., Layeghy, Siamak, Singh, Priyanka, Portmann, Marius
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866918195310362624
author Houssel, Paul R. B.
Layeghy, Siamak
Singh, Priyanka
Portmann, Marius
author_facet Houssel, Paul R. B.
Layeghy, Siamak
Singh, Priyanka
Portmann, Marius
contents This paper introduces eX-NIDS, a framework designed to enhance interpretability in flow-based Network Intrusion Detection Systems (NIDS) by leveraging Large Language Models (LLMs). In our proposed framework, flows labelled as malicious by NIDS are initially processed through a module called the Prompt Augmenter. This module extracts contextual information and Cyber Threat Intelligence (CTI)-related knowledge from these flows. This enriched, context-specific data is then integrated with an input prompt for an LLM, enabling it to generate detailed explanations and interpretations of why the flow was identified as malicious by NIDS. We compare the generated interpretations against a Basic-Prompt Explainer baseline, which does not incorporate any contextual information into the LLM's input prompt. Our framework is quantitatively evaluated using the Llama 3 and GPT-4 models, employing a novel evaluation method tailored for natural language explanations, focusing on their correctness and consistency. The results demonstrate that augmented LLMs can produce accurate and consistent explanations, serving as valuable complementary tools in NIDS to explain the classification of malicious flows. The use of augmented prompts enhances performance by over 20% compared to the Basic-Prompt Explainer.
format Preprint
id arxiv_https___arxiv_org_abs_2507_16241
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle eX-NIDS: A Framework for Explainable Network Intrusion Detection Leveraging Large Language Models
Houssel, Paul R. B.
Layeghy, Siamak
Singh, Priyanka
Portmann, Marius
Cryptography and Security
Artificial Intelligence
This paper introduces eX-NIDS, a framework designed to enhance interpretability in flow-based Network Intrusion Detection Systems (NIDS) by leveraging Large Language Models (LLMs). In our proposed framework, flows labelled as malicious by NIDS are initially processed through a module called the Prompt Augmenter. This module extracts contextual information and Cyber Threat Intelligence (CTI)-related knowledge from these flows. This enriched, context-specific data is then integrated with an input prompt for an LLM, enabling it to generate detailed explanations and interpretations of why the flow was identified as malicious by NIDS. We compare the generated interpretations against a Basic-Prompt Explainer baseline, which does not incorporate any contextual information into the LLM's input prompt. Our framework is quantitatively evaluated using the Llama 3 and GPT-4 models, employing a novel evaluation method tailored for natural language explanations, focusing on their correctness and consistency. The results demonstrate that augmented LLMs can produce accurate and consistent explanations, serving as valuable complementary tools in NIDS to explain the classification of malicious flows. The use of augmented prompts enhances performance by over 20% compared to the Basic-Prompt Explainer.
title eX-NIDS: A Framework for Explainable Network Intrusion Detection Leveraging Large Language Models
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2507.16241