Explainable Artificial Intelligence for Cybersecurity: A Systematic Review of Trustworthy Intrusion Detection and Threat Analysis
Keywords:
artificial intelligence, cybersecurity, intrusion detection, machine learning, security analytics, threat detectionAbstract
Artificial intelligence (AI) and machine learning (ML) have become important technologies for detecting cyber threats, classifying malicious traffic, identifying anomalous behavior, and supporting security operations. However, many high-performing AI models operate as complex black boxes, making it difficult for security analysts to understand why a particular event has been classified as malicious. This lack of transparency can reduce trust, complicate incident investigation, and create difficulties in auditing automated security decisions. Explainable Artificial Intelligence (XAI) addresses this problem by providing human-understandable explanations of model predictions. This article presents a structured literature review of XAI techniques applied to cybersecurity, with particular emphasis on intrusion detection, malware classification, anomaly detection, and security analytics. The methodology organizes the literature according to model type, explanation mechanism, cybersecurity application, and operational requirement. The review indicates that SHAP, LIME, feature importance methods, attention-based explanations, rule-based explanations, and model-specific interpretation techniques can improve the interpretability of AI-supported security decisions. However, explanation quality, computational overhead, robustness against adversarial manipulation, and the difference between plausible and faithful explanations remain significant challenges. The study proposes a practical XAI-oriented cybersecurity framework integrating detection, explanation, analyst validation, and continuous monitoring. The findings suggest that explainability should be treated as an operational property of cybersecurity AI rather than merely as a visualization feature.