Interpreting Unsupervised Anomaly Detection in Security via Rule Extraction
Ruoyu Li, Qing Li, Yu Zhang, Dan Zhao, Yong Jiang, Yong Yang
Abstract
Many security applications require unsupervised anomaly detection, as malicious data are extremely rare and often only unlabeled normal data are available for training (i.e., zero-positive). However, security operators are concerned about the high stakes of trusting black-box models due to their lack of interpretability. In this paper, we propose a post-hoc method to globally explain a black-box unsupervised anomaly detection model via rule extraction. First, we propose the concept of distribution decomposition rules that decompose the complex distribution of normal data into multiple compositional distributions. To find such rules, we design an unsupervised Interior Clustering Tree that incorporates the model prediction into the splitting criteria. Then, we propose the Compositional Boundary Exploration (CBE) algorithm to obtain the boundary inference rules that estimate the decision boundary of the original model on each compositional distribution. By merging these two types of rules into a rule set, we can present the inferential process of the unsupervised black-box model in a human-understandable way, and build a surrogate rule-based model for online deployment at the same time. We conduct comprehensive experiments on the explanation of four distinct unsupervised anomaly detection models on various real-world datasets. The evaluation shows that our method outperforms existing methods in terms of diverse metrics including fidelity, correctness and robustness.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- Dissect Black Box: Interpreting for Rule-Based Explanations in Unsupervised Anomaly DetectionYu Zhang, Ruoyu Li, Nengwu Wu, Qing Li et al.NeurIPS 2024 · 7 citations
- Helios: Learning and Adaptation of Matching Rules for Continual In-Network Malicious Traffic DetectionZhenning Shi, Dan Zhao, Yijia Zhu, Guorui Xie et al.WWW 2025 · 6 citations
- An Evidence-Based Post-Hoc Adjustment Framework for Anomaly Detection Under Data ContaminationSukanya Patra, Souhaib Ben TaiebNeurIPS 2025 · 4 citations
Builds on14
- DeepLog: Anomaly Detection and Diagnosis from System Logs through Deep LearningMin Du, Feifei Li, Guineng Zheng, Vivek SrikumarCCS 2017 · 1,823 citations
- Kitsune: An Ensemble of Autoencoders for Online Network Intrusion DetectionYisroel Mirsky, Tomer Doitshman, Yuval Elovici, Asaf ShabtaiNDSS 2018 · 945 citations
- LEMNA: Explaining Deep Learning based Security ApplicationsWenbo Guo, Dongliang Mu, Jun Xu, Purui Su et al.CCS 2018 · 336 citations
- CADE: Detecting and Explaining Concept Drift Samples for Security ApplicationsLimin Yang, Wenbo Guo, Qingying Hao, Arridhana Ciptadi et al.USENIX Security 2021 · 241 citations
- Explainable Deep One-Class ClassificationPhilipp Liznerski, Lukas Ruff, Robert A. Vandermeulen, Billy Joe Franks et al.ICLR 2021 · 240 citations
Related papers
- DeepAID: Interpreting and Improving Deep Learning-based Anomaly Detection in Security ApplicationsDongqi Han, Zhiliang Wang, Wenqi Chen, Ying Zhong et al.CCS 2021 · 108 citations
- Rules Refine the Riddle: Global Explanation for Deep Learning-Based Anomaly Detection in Security ApplicationsDongqi Han, Zhiliang Wang, Ruitao Feng, Minghui Jin et al.CCS 2024 · 3 citations
- Concept-based Explanations for Out-of-Distribution DetectorsJihye Choi, Jayaram Raghuram, Ryan Feng, Jiefeng Chen et al.ICML 2023 · 18 citations
- Beyond Outlier Detection: Outlier Interpretation by Attention-Guided Triplet Deviation NetworkHongzuo Xu, Yijie Wang, Songlei Jian, Zhenyu Huang et al.WWW 2021 · 40 citations
- Evidential Reasoning for Video Anomaly DetectionChe Sun, Yunde Jia, Yuwei WuACM MM 2022 · 23 citations
