Nascita, Alfredo (2024) Explaining and Improving DL Models for Network Traffic Analysis: Unveiling the Black Box via XAI. [Tesi di dottorato]

[thumbnail of Alfredo_Nascita_37_COMPLETO.pdf] Documento PDF
Alfredo_Nascita_37_COMPLETO.pdf
Visibile a [TBR] Amministratori dell'archivio

Download (9MB) | Richiedi una copia
[thumbnail of Alfredo_Nascita_37_PARZIALE.pdf] Documento PDF
Alfredo_Nascita_37_PARZIALE.pdf
Visibile a [TBR] Amministratori dell'archivio

Download (5MB) | Richiedi una copia
Tipologia del documento: Tesi di dottorato
Lingua: English
Titolo: Explaining and Improving DL Models for Network Traffic Analysis: Unveiling the Black Box via XAI
Autori:
Autore
Email
Nascita, Alfredo
alfredo.nascita@unina.it
Data: 11 Dicembre 2024
Numero di pagine: 180
Istituzione: Università degli Studi di Napoli Federico II
Dipartimento: Ingegneria Elettrica e delle Tecnologie dell'Informazione
Dottorato: Information technology and electrical engineering
Ciclo di dottorato: 37
Coordinatore del Corso di dottorato:
nome
email
Russo, Stefano
stefano.russo@unina.it
Tutor:
nome
email
Persico, Valerio
[non definito]
Data: 11 Dicembre 2024
Numero di pagine: 180
Parole chiave: Internet Traffic Analysis; XAI; Traffic Classification; Anomaly Detection; Attack Classification
Settori scientifico-disciplinari del MIUR: Area 09 - Ingegneria industriale e dell'informazione > ING-INF/05 - Sistemi di elaborazione delle informazioni
Informazioni aggiuntive: Ciclo di dottorato di appartenenza: 37
Depositato il: 29 Dic 2024 09:12
Ultima modifica: 12 Ago 2026 05:38
URI: https://www.fedoa.unina.it/id/eprint/16479

Abstract

The analysis of Internet traffic today presents new and complex challenges that make traditional approaches increasingly ineffective. Deep Learning (DL) approaches represent the most promising strategy, as they can handle the dynamic and heterogeneous nature of traffic. However, such approaches have limitations in transparency due to their "black-box" nature, which hinders adoption in real-world network environments. For these reasons, Explainable AI (XAI) has been introduced, aiming to shed light on DL models and enhance understanding of their decisions. This thesis focuses on the explainability of state-of-the-art approaches based on DL for Internet traffic analysis in various application contexts, such as traffic classification and cyber-attacks and anomaly detection. Specifically, several explainability aspects are analyzed to understand how DL models function and to guide their improvement from different perspectives. Initially, the role of inputs on model performance is studied, and a strategy is proposed to refine model complexity by selecting only the most important inputs. Subsequently, the reliability of the outputs produced by traffic classifiers is analyzed and improved. The analysis then shifts to locate knowledge in the core of models tied to specific concepts, such as class membership, enabling targeted knowledge manipulations and performance adjustments without additional fine-tuning. Finally, traffic classifiers trained with incremental approaches are analyzed to develop guidelines for training extensible traffic classifiers. The methodologies proposed aim to improve the integration of DL models in real-world contexts through in-depth explainability analyses. The solutions presented support a deeper understanding and improvement of network tools, making them more transparent, reliable, and suited for complex, evolving scenarios.

Downloads

Downloads per month over past year

Actions (login required)

Modifica documento Modifica documento