Skip navigation

Balancing explainability strength and privacy in counterfactual explanations for insider threat detection

Balancing explainability strength and privacy in counterfactual explanations for insider threat detection

Naila, Naila, Loukas, George ORCID logoORCID: https://orcid.org/0000-0003-3559-5182 and Panaousis, Manos ORCID logoORCID: https://orcid.org/0000-0001-7306-4062 (2026) Balancing explainability strength and privacy in counterfactual explanations for insider threat detection. In: 2026 IEEE Conference on Communications and Network Security (CNS). IEEE. (In Press)

[thumbnail of Author's Accepted Manuscript]
Preview
PDF (Author's Accepted Manuscript)
53988 NAILA_Balancing_Explainability_Strength_And_Privacy_(AAM)_2026.pdf - Accepted Version
Available under License Creative Commons Attribution.

Download (515kB) | Preview

Abstract

Explainable AI (XAI) methods, such as counterfactual explanations, help make model decisions more transparent and actionable. However, they can unintentionally reveal sensitive information, which is a critical concern in security settings such as insider threat detection, where both transparency and privacy are vital, particularly when explanations are shared with external analysts or decision-makers. We propose a privacy-aware counterfactual framework that integrates Differential Privacy (DP) to add only the minimum adjusted noise required to satisfy user-defined privacy caps, reducing information leakage while preserving explanation fidelity. Two task-specific metrics are introduced: XAIStrength, which measures how faithfully a counterfactual follows the model’s decision boundary, and XAILeakage, which quantifies privacy risk based on movement into sparse feature regions. Experiments on the CERT insider threat dataset show that initially generated counterfactuals were highly faithful for most users but frequently violated privacy requirements. After optimisation, leakage was reduced to meet strict, moderate, and lenient privacy caps (τ = 0.05/0.10/0.20) while maintaining practical fidelity. More than 60% of users retained Sopt ≥ 0.70 under strict privacy constraints, while over 60% maintained Sopt ≥ 0.85 under moderate privacy settings. Comparative evaluation against standard and privacy-aware baselines shows that the proposed framework achieves a stronger balance between explanation utility and disclosure risk. To the best of our knowledge, this is the first study to formally quantify and optimise the XAIStrength–XAILeakage trade-off in counterfactual explanations using statistically grounded risk measures and DP-calibrated optimisation.

Item Type: Conference Proceedings
Title of Proceedings: 2026 IEEE Conference on Communications and Network Security (CNS)
Uncontrolled Keywords: Explainable AI (XAI), counterfactual, XAIStrength, XAILeakage, optimisation, differential privacy
Subjects: Q Science > QA Mathematics > QA75 Electronic computers. Computer science
Faculty / School / Research Centre / Research Group: Faculty of Education, Health & Human Sciences > Institute for Lifecourse Development
Faculty of Education, Health & Human Sciences > Institute for Lifecourse Development > Centre for Chronic Illness and Ageing
Faculty of Engineering & Science
Faculty of Engineering & Science > School of Computing & Mathematical Sciences (CMS)
Related URLs:
Last Modified: 28 Jul 2026 09:53
URI: https://gala.gre.ac.uk/id/eprint/53988

Actions (login required)

View Item View Item

Downloads

Downloads per month over past year

View more statistics