面向工业网络安全的可解释人工智能:方法、操作集成与研究挑战综述
Explainable Artificial Intelligence for Industrial Cybersecurity: A Review of Methods, Operational Integration, and Research Challenges
- German University in Cairo(开罗德国大学)
- University of Toronto(多伦多大学)
- University of Illinois Urbana-Champaign(伊利诺伊大学厄巴纳-香槟分校)
- Siemens Canada(西门子加拿大)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
本文综述工业网络安全领域的XAI技术,分析其方法适用性、工业系统特殊要求及相关挑战,为开发可信的XAI赋能工业网络安全解决方案指明研究方向。
AI中文摘要:
工业基础设施的日益数字化以及信息技术(IT)与运营技术(OT)的融合,扩大了工业系统的网络攻击面。为应对日益复杂的网络威胁,人工智能(AI)和机器学习(ML)技术越来越多地部署在工业网络安全运营中,尤其是安全运营中心(SOC)。这些方法虽能改进异常检测、威胁分析和自动响应,但其不透明的决策过程给运营信任、合规性和事件响应带来了挑战。可解释人工智能(XAI)作为一种有前景的范式应运而生,旨在提升AI驱动的网络安全系统及决策的透明度与可解释性。本文对工业网络安全领域的XAI技术进行了全面综述,重点关注工业SOC环境和运营安全工作流程。我们分析了AI在工业SOC工作流程中的作用、工业环境中利用的运营数据类型,以及基于AI的威胁检测的优势与局限性。随后综述了主要的XAI方法家族,包括特征归因方法、代理模型、基于规则的解释和可视化技术,并分析了它们在工业用例中的适用性。我们进一步探讨了工业系统与传统IT环境不同的运营、监管和安全要求。研究了关键挑战,包括带标签数据集有限、模型可靠性、可解释性-性能权衡,以及XAI工具与SOC工作流程的集成。最后,我们确定了开放的研究方向和机遇,以开发适用于工业环境的可信、可操作且面向特定领域的XAI赋能网络安全解决方案。
英文摘要:
The increasing digitalization of industrial infrastructure and the convergence of information technology (IT) and operational technology (OT) have expanded the cyberattack surface of industrial systems. To address the growing complexity of cyber threats, artificial intelligence (AI) and machine learning (ML) techniques are increasingly deployed within industrial cybersecurity operations, particularly in Security Operations Centers (SOCs). While these approaches improve anomaly detection, threat analysis, and automated response, their opaque decision-making presents challenges for operational trust, regulatory compliance, and incident response. EXplainable Artificial Intelligence (XAI) has emerged as a promising paradigm to improve the transparency and interpretability of AI-driven cybersecurity systems and decisions. This paper provides a comprehensive review of XAI techniques in industrial cybersecurity, focusing on industrial SOC environments and operational security workflows. We examine the role of AI in industrial SOC workflows, the types of operational data leveraged in industrial environments, and the benefits and limitations of AI-based threat detection. We then review major families of XAI approaches, including feature attribution methods, surrogate models, rule-based explanations, and visualization techniques, and analyze their applicability to industrial use cases. We further discuss the operational, regulatory, and safety requirements that distinguish industrial systems from traditional IT environments. Key challenges are examined, including limited labeled datasets, model reliability, explainability-performance tradeoffs, and the integration of XAI tools into SOC workflows. Finally, we identify open research directions and opportunities for developing trustworthy, operationally viable, and domain-specific XAI-enabled cybersecurity solutions for industrial environments.