During the last few years, the term Mechanistic Interpretability, a specific area, under the umbrella of explainable artificial intelligence (XAI), has been introduced, to explain the decisions made by complex machine learning (ML) models in critical systems like UAV intrusion detection systems (UAVIDS). In this paper, we apply best-practices for data pre-processing and examine a wide range of tree-ensembles, deep neural networks, hybrid stacking models and the latest ensemble neural networks to detect intrusions in UAV, with stratified 10-fold cross validation. With our top-performing model, XGBoost, we proceed to Shapley Additive explanations (SHAP), to analyze the global and local feature importances and understand which features, each attack targets, to mimic normal traffic and where the misclassifications occur. Furthermore a distribution analysis follows, by visually comparing violin plots and the curves of kernel density estimations. With the Westfall-Young permutation test for multiple comparisons, the Bandwidth optimization of the KDEs and the selection of Jensen-Shannon Distance for the test, we discover the true causes of false predictions, observed in Wormhole and Blackhole attacks in UAVIDS-2025. The findings provide robust, reliable and explainable models for UAV intrusion detection, along with statistical insights, which capture and clarify the masked nature of the attacks, regarding the challenge of Density Support Intersection, between these attacks, in this dataset.
翻译:近年来,机械可解释性作为可解释人工智能(XAI)领域的一个特定分支被引入,用于解释关键系统(如无人机入侵检测系统UAVIDS)中复杂机器学习(ML)模型所做出的决策。本文应用数据预处理的最佳实践,考察了广泛的树集成模型、深度神经网络、混合堆叠模型以及最新集成神经网络,通过分层10折交叉验证对无人机入侵进行检测。针对性能最优的XGBoost模型,我们采用沙普利加性解释(SHAP)分析全局与局部特征重要性,明确每个攻击所针对的特征、模拟正常流量的方式以及误分类发生的位置。此外,通过可视化比较小提琴图与核密度估计曲线,我们进行了分布分析。借助Westfall-Young置换检验进行多重比较,结合核密度估计的带宽优化,并选用詹森-香农距离作为检验指标,我们揭示了UAVIDS-2025数据集中虫洞攻击与黑洞攻击产生误预测的真实成因。研究结果不仅为无人机入侵检测提供了稳健、可靠且可解释的模型,还通过统计洞察捕捉并阐明了这些攻击在数据集中因密度支撑交集问题而呈现的伪装特性。