Estimating adversarial transferability from feature-importance similarity in explainable intrusion detection systems
Machine Learning (ML)-based Intrusion Detection Systems (IDS) are critical for defending against cyber threats but remain vulnerable to adversarial attacks, posing risks to system reliability and security. This study investigates the transferability of adversarial attacks across XGBoost and LightGBM models in IDS and uses Explainable AI (XAI) techniques to identify features that influence model decisions. Experiments on the CICIDS-2017 and NSL-KDD datasets demonstrate cross-model adversarial transferability, with accuracy reductions of 8.75% and 10.59% for XGBoost and LightGBM, respectively. The XAI-informed analysis further shows that feature-importance patterns can be used to examine model vulnerability under adversarial perturbations. Under direct adversarial testing, XGBoost exhibited a 6.18% reduction in accuracy, illustrating the vulnerability associated with perturbations targeting highly ranked features. Building on prior research linking feature importance to adversarial transferability, this study operationalizes that relationship in the IDS domain through a heuristic formulation based on correlations between model-specific feature-importance vectors. The proposed formulation is intended as a practical approximation for assessing cross-model vulnerability rather than as a deterministic predictor.
Authors
- Duygu Çakır (ORCID: https://orcid.org/0000-0003-1600-3989)
- Marwa Abdulkareem
- Abdlelah Abdlatef
Institutions
- Bahçeşehir University (TR)
- Galatasaray University (TR)
Publication Details
- Journal
- International Journal of Information Security
- Published
- 2026-09-14
- DOI
- https://doi.org/10.1007/s10207-026-01333-y
- Primary Topic
- Adversarial Robustness in Machine Learning
- Type
- article
- Field-Weighted Citation Impact
- 0.00