Balancing explainability strength and privacy in counterfactual explanations for insider threat detection
Naila, Naila, Loukas, George ORCID: https://orcid.org/0000-0003-3559-5182 and Panaousis, Manos
ORCID: https://orcid.org/0000-0001-7306-4062
(2026)
Balancing explainability strength and privacy in counterfactual explanations for insider threat detection.
In: 2026 IEEE Conference on Communications and Network Security (CNS).
IEEE.
(In Press)
Preview |
PDF (Author's Accepted Manuscript)
53988 NAILA_Balancing_Explainability_Strength_And_Privacy_(AAM)_2026.pdf - Accepted Version Available under License Creative Commons Attribution. Download (515kB) | Preview |
Abstract
Explainable AI (XAI) methods, such as counterfactual explanations, help make model decisions more transparent and actionable. However, they can unintentionally reveal sensitive information, which is a critical concern in security settings such as insider threat detection, where both transparency and privacy are vital, particularly when explanations are shared with external analysts or decision-makers. We propose a privacy-aware counterfactual framework that integrates Differential Privacy (DP) to add only the minimum adjusted noise required to satisfy user-defined privacy caps, reducing information leakage while preserving explanation fidelity. Two task-specific metrics are introduced: XAIStrength, which measures how faithfully a counterfactual follows the model’s decision boundary, and XAILeakage, which quantifies privacy risk based on movement into sparse feature regions. Experiments on the CERT insider threat dataset show that initially generated counterfactuals were highly faithful for most users but frequently violated privacy requirements. After optimisation, leakage was reduced to meet strict, moderate, and lenient privacy caps (τ = 0.05/0.10/0.20) while maintaining practical fidelity. More than 60% of users retained Sopt ≥ 0.70 under strict privacy constraints, while over 60% maintained Sopt ≥ 0.85 under moderate privacy settings. Comparative evaluation against standard and privacy-aware baselines shows that the proposed framework achieves a stronger balance between explanation utility and disclosure risk. To the best of our knowledge, this is the first study to formally quantify and optimise the XAIStrength–XAILeakage trade-off in counterfactual explanations using statistically grounded risk measures and DP-calibrated optimisation.
| Item Type: | Conference Proceedings |
|---|---|
| Title of Proceedings: | 2026 IEEE Conference on Communications and Network Security (CNS) |
| Uncontrolled Keywords: | Explainable AI (XAI), counterfactual, XAIStrength, XAILeakage, optimisation, differential privacy |
| Subjects: | Q Science > QA Mathematics > QA75 Electronic computers. Computer science |
| Faculty / School / Research Centre / Research Group: | Faculty of Education, Health & Human Sciences > Institute for Lifecourse Development Faculty of Education, Health & Human Sciences > Institute for Lifecourse Development > Centre for Chronic Illness and Ageing Faculty of Engineering & Science Faculty of Engineering & Science > School of Computing & Mathematical Sciences (CMS) |
| Related URLs: | |
| Last Modified: | 28 Jul 2026 09:53 |
| URI: | https://gala.gre.ac.uk/id/eprint/53988 |
Actions (login required)
![]() |
View Item |
Downloads
Downloads per month over past year
Tools
Tools