Abstract
In the evolving cybersecurity landscape, Security Operation Centers (SOCs) play a pivotal role in protecting digital assets through real-time threat detection and response. Recently, the integration of Artificial Intelligence (AI) and Explainable AI (XAI) has bolstered SOC operations by enhancing the model transparency and interpretability. While these advancements have increased operational reliability, challenges remain. Specifically, insufficient XAI explanations to support analyst decision-making and the high explanation latency inherent in the generation process continue to hinder the practical deployment of XAI in real-world SOC environments. To address these challenges, we proposed a three-stage XAI framework based on TreeSHAP. Our method enhances interpretability through analyst-centric input construction, mitigates the Shapley value bias induced by multicollinearity by isolating feature contributions during iterative retraining on decorrelated data, and introduces a novel ranking scheme that balances consistency with practical influences. The experimental results demonstrate that the proposed method achieved the highest Intersection-over-Union (IoU) score. Specifically, by providing more sufficient and analyst-centric rationales for attack detection than the other XAI methods, the proposed approach significantly improves analyst acceptance. Notably, the proposed method exhibits an explanation latency that is 25 times lower than that of baseline techniques, such as KernelSHAP and LIME. These results confirm that our approach is both analyst-acceptable and operationally practical in real-world SOC environments.
Author supplied keywords
Cite
CITATION STYLE
Lee, H., Baek, U. J., Kwon, T., Lee, J., & Song, J. (2026). Practical and Analyst-Acceptable Explainable AI for Supporting Decision-Making in SOCs. IEEE Access, 14, 48934–48955. https://doi.org/10.1109/ACCESS.2026.3672924
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.