Trade-off Between Performance, Efficiency, and Explainability in AI-Based Intrusion Detection Systems: A Systematic Review of Models, XAI, and Research Challenges
Downloads
Artificial Intelligence (AI)-based Intrusion Detection Systems (IDS) have significantly enhanced the detection of cyber-attacks through the adoption of machine learning and deep learning techniques. However, achieving high detection results often comes at the expense of interpretability, computational efficiency, and generalization. This paper introduces a systematic review of AI-based IDS, focusing on the integration of deep learning algorithms with Explainable Artificial Intelligence (XAI) methods. The paper analyzes a varied range of techniques, including traditional machine learning, deep learning, and hybrid models, alongside commonly used XAI methods such as SHAP and LIME. Furthermore, the review studies widely used benchmark and real-world datasets, emphasize their limitations in representing modern cyber-attack scenarios. Evaluation metrics used in the literature are also critically analyzed, revealing a lack of comprehensive assessment frameworks that incorporate performance, efficiency, and explainability. The findings determine a clear trade-off between accuracy, interpretability, and computational complexity, with most high-performing models lacking intrinsic transparency and relying heavily on post-hoc explanation methods. Finally, this paper recognizes key research gaps, including a limited combination of XAI within model architectures, over-reliance on outdated datasets, and the absence of unified Intrusion Detection Systems frameworks. These insights deliver a foundation for developing next-generation Intrusion Detection Systems solutions that balance performance, explainability, and real-world applicability.
V. Z. Mohale and I. C. Obagbuwa, "A systematic review on the integration of explainable artificial intelligence in intrusion detection systems to enhancing transparency and interpretability in cybersecurity," Frontiers in Artificial Intelligence, vol. 8, p. 1526221, 2025.
M. I. J. Shekh Tareq Ali, Mahabub Alam Khan, Sheikh Md Kamrul Islam Rasel, Md Abdullah Al Nahid, Touhid Bhuiyan, "Enhancing Intrusion Detection Systems with AI: Examine the Integration of AI into Traditional IDS to Improve Detection Rates and Reduce False Positives," International Journal of Intelligent, vol. VOL. 12 NO. 22S (2024) no. 2147-6799, 2024. [Online]. Available: https://ijisae.org/index.php/IJISAE/article/view/7555?utm_source=chatgpt.com.
S. M. Yellepeddi, C. S. Ravi, V. K. R. Vangoor, and S. Chitta, "AI-powered intrusion detection systems: Real-world performance analysis," J AI-Assist Sci Discov, vol. 4, no. 1, pp. 279-289, 2024.
Y. Sanjalawe, S. Fraihat, S. Al-E’mari, and S. N. Makhadmeh, "A review of artificial intelligence-based intrusion detection in industrial internet of things," Discover Internet of Things, 2026.
M. Keshk, N. Koroniotis, N. Pham, N. Moustafa, B. Turnbull, and A. Y. Zomaya, "An explainable deep learning-enabled intrusion detection framework in IoT networks," Information Sciences, vol. 639, p. 119000, 2023.
Y. Djenouri, A. Belhadi, G. Srivastava, J. C.-W. Lin, and A. Yazidi, "Interpretable intrusion detection for the next generation of Internet of Things," Computer Communications, vol. 203, pp. 192-198, 2023.
M. Hasnain, N. Javaid, A. K. J. Saudagar, and N. Kumar, "An intelligent and explainable intrusion detection framework for Internet of Sensor Things using generalizable optimized active Machine Learning," Journal of Network and Computer Applications, p. 104358, 2025.
A. Kwubeghari and N. G. Ezeji, "Designing an Explainable Intrusion Detection System (X-Ids) Using Machine Learning: A Framework for Transparency and Trust," ABUAD Journal of Engineering Research and Development (AJERD), vol. 8, no. 2, pp. 319-328, 2025.
S. Neupane et al., "Explainable intrusion detection systems (X-IDS): a survey of current methods, challenges, and opportunities. arXiv," arXiv preprint arXiv:2207.06236, 2022.
J. Ables et al., "Eclectic rule extraction for explainability of deep neural network-based intrusion detection systems," arXiv preprint arXiv:2401.10207, 2024.
D. J. K. Nkashama et al., "Deep learning for network anomaly detection under data contamination: evaluating robustness and mitigating performance degradation," in European Symposium on Research in Computer Security, 2024: Springer, pp. 68-87.
N. Khan, K. Ahmad, A. A. Tamimi, M. M. Alani, A. Bermak, and I. Khalil, "Explainable AI-based intrusion detection system for industry 5.0: an overview of the literature, associated challenges, the existing solutions, and potential research directions," arXiv preprint arXiv:2408.03335, 2024.
H. Manthena, S. Shajarian, J. Kimmell, M. Abdelsalam, S. Khorsandroo, and M. Gupta, "Explainable artificial intelligence (XAI) for malware analysis: A survey of techniques, applications, and open challenges," IEEE Access, 2025.
M. A. Yagiz, P. MohajerAnsari, M. D. Pesé, and P. Goktas, "Transforming in-vehicle network intrusion detection: VAE-based knowledge distillation meets explainable AI," in Proceedings of the Sixth Workshop on CPS&IoT Security and Privacy, 2024, pp. 93-103.
M. Adil, M. A. Jan, S. B. Hakim, H. H. Song, and Z. Jin, "xIDS-EnsembleGuard: An Explainable Ensemble Learning-based Intrusion Detection System," in 2024 IEEE 23rd International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), 2024: IEEE, pp. 93-100.
Z. Xu et al., "Deep learning-based intrusion detection systems: A survey," arXiv preprint arXiv:2504.07839, 2025.
M. M. J. Ayan et al., "Human-Centered Explainable AI for Security Enhancement: A Deep Intrusion Detection Framework," arXiv preprint arXiv:2602.13271, 2026.
W. Shao, "Interpretable Ensemble Learning for Network Traffic Anomaly Detection: A SHAP-based Explainable AI Framework for Embedded Systems Security," arXiv preprint arXiv:2603.28654, 2026.
Z. Li, W. Fang, C. Zhu, G. Song, and W. Zhang, "Toward deep learning-based intrusion detection system: A survey," in Proceedings of the 2024 6th International Conference on Big Data Engineering, 2024, pp. 25-32.
Z. Zamanzadeh Darban, G. I. Webb, S. Pan, C. Aggarwal, and M. Salehi, "Deep learning for time series anomaly detection: A survey," ACM Computing Surveys, vol. 57, no. 1, pp. 1-42, 2024.
S. Patil et al., "Explainable artificial intelligence for intrusion detection system," Electronics, vol. 11, no. 19, p. 3079, 2022.
O. Arreche, T. R. Guntur, J. W. Roberts, and M. Abdallah, "E-XAI: Evaluating black-box explainable AI frameworks for network intrusion detection," IEEE Access, vol. 12, pp. 23954-23988, 2024.
E. C. P. Neto, S. Iqbal, S. Buffett, M. Sultana, and A. Taylor, "Deep learning for intrusion detection in emerging technologies: a comprehensive survey and new perspectives," Artificial Intelligence Review, vol. 58, no. 11, p. 340, 2025.
O. Arreche and M. Abdallah, "A comparative analysis of DNN-based white-box explainable AI methods in network security," EURASIP Journal on Information Security, vol. 2025, no. 1, p. 16, 2025.
K. P. Sharma et al., "Interpretable intrusion detection for IoT environments using a self-attention-based explainable AI framework," Scientific Reports, vol. 15, no. 1, p. 39937, 2025.
T. B. Ogunseyi, G. Thiyagarajan, H. He, V. Bist, and Z. Du, "Performance Analysis of Explainable Deep Learning-Based Intrusion Detection Systems for IoT Networks: A Systematic Review," Sensors, vol. 26, no. 2, p. 363, 2026.
S. ISHTIAQ, F. U. REHMAN, S. SALEEM, and A. YAAR, "DEEP LEARNING FOR INTRUSION DETECTION SYSTEMS," Contemporary Journal of Social Science Review, vol. 3, no. 4, pp. 665-675, 2025.
N. Kalimuthu, "Explainable AI (XAI) for Enhanced Cyber Threat Intelligence: Building Interpretable Intrusion Detection Systems," IJSAT-International Journal on Science and Technology, vol. 16, no. 4, 2025.
M. Siganos et al., "Explainable AI-based intrusion detection in the internet of things," in Proceedings of the 18th International Conference on Availability, Reliability, and Security, 2023, pp. 1-10.
M. B. M. Shtayat, M. K. Hasan, R. Sulaiman, S. Islam, and A. U. R. Khan, "An explainable ensemble deep learning approach for intrusion detection in industrial internet of things," IEEE Access, vol. 11, pp. 115047-115061, 2023.
O. Arreche, T. Guntur, and M. Abdallah, "Xai-ids: Toward proposing an explainable artificial intelligence framework for enhancing network intrusion detection systems," Applied Sciences, vol. 14, no. 10, p. 4170, 2024.
A. I. Udofot, O. M. Oluseyi, and E. Bassey, "Explainable AI for cyber security. Improving transparency and trust in intrusion detection systems," International Journal of Advances in Engineering and Management, vol. 6, no. 12, pp. 229-240, 2024.
D. Gaspar, P. Silva, and C. Silva, "Explainable AI for intrusion detection systems: LIME and SHAP applicability on multi-layer perceptron," IEEE Access, vol. 12, pp. 30164-30175, 2024.
Z. Abou El Houda, B. Brik, and L. Khoukhi, "Why should I trust your IDs?”: An explainable deep learning framework for intrusion detection systems in Internet of Things networks," IEEE Open Journal of the Communications Society, vol. 3, pp. 1164-1176, 2022.
Z. C. Lipton, "The Mythos of Model Interpretability," Communications of the ACM, vol. Vol. 61, No. 10, pp. 36-43, Oct 1 2018, doi: 10.1145/3233231.
P. Zschech, S. Weinzierl, and M. Kraus, "Inherently Interpretable Machine Learning: A Contrasting Paradigm to Post-hoc Explainable AI: P. Zschech et al," Business & Information Systems Engineering, pp. 1-19, 2025.
T. Laugel, M.-J. Lesot, C. Marsala, X. Renard, and M. Detyniecki, "The dangers of post-hoc interpretability: Unjustified counterfactual explanations," arXiv preprint arXiv:1907.09294, 2019.
I. Lage et al., "An evaluation of the human-interpretability of explanation," arXiv preprint arXiv:1902.00006, 2019.
T. Qamar and N. Z. Bawany, "Understanding the black-box: towards interpretable and reliable deep learning models," PeerJ Computer Science, vol. 9, p. e1629, 2023.
R. Hassan, N. Nguyen, S. R. Finserås, L. Adde, I. Strümke, and R. Støen, "Unlocking the black box: Enhancing human-AI collaboration in high-stakes healthcare scenarios through explainable AI," Technological Forecasting and Social Change, vol. 219, p. 124265, 2025.
L. Gao and L. Guan, "Interpretability of machine learning: Recent advances and prospects," IEEE MultiMedia, vol. 30, no. 4, pp. 105-118, 2023.
J. C. Bjerring, J. Mainz, and L. Munch, "Deep learning models and the limits of explainable artificial intelligence," Asian Journal of Philosophy, vol. 4, no. 1, p. 22, 2025.
H. Liu and B. Lang, "Machine learning and deep learning methods for intrusion detection systems: A survey," Applied Sciences, vol. 9, no. 20, p. 4396, 2019.
A. Devarakonda, N. Sharma, P. Saha, and S. Ramya, "Network intrusion detection: A comparative study of four classifiers using the NSL-KDD and KDD’99 datasets," in Journal of Physics: Conference Series, 2022, vol. 2161, no. 1: IOP Publishing, p. 012043.
H. M. R. U. Rehman et al., "A systematic literature study of machine learning techniques based intrusion detection: datasets, models, challenges, and future directions," Journal of Big Data, vol. 12, no. 1, p. 264, 2025.
S. A. AL-Shami and M. F. Abdullah, "Deep Learning for DDoS Detection: A Systematic Review of Explainability and Adversarial Robustness."
