Explainable Machine Learning or AI Using AssociationRule Mining

Authors

  • Sikha S. Bagui1* University of West Florida image/svg+xml
  • Emily Summers Department of Computer Science, University of West Florida, Pensacola, Florida, USA
  • Dustin Mink Department of Cybersecurity and Information Technology, University of West Florida, Pensacola, Florida, USA
  • Subhash Bagui Department of Mathematics and Statistics, University of West Florida, Pensacola, Florida, USA

Abstract

In this paper feature selection is performed using Association Rule Mining (ARM), a widely used data mining technique. Association Rule Mining is used as a preprocessing step before machine learning algorithms are applied. Association Rule Mining allows us to not only select the features, but also select the feature values, thus creating a useful feature-value subset that can be used as input for machine learning algorithms. To date, many works have been done on feature selection prior to running machine learning algorithms, but work has not been done on selecting the useful value or range/subset of the feature to be used for better and more efficient machine learning classification. Selecting the useful part of the feature would help in better explaining the machine learning results. This research is conducted using a newly created Cybersecurity dataset, UWF-ZeekData22, labeled as per the MITRE Adversarial Tactics, Techniques, and Common Knowledge (MITRE ATT&CK) framework. Due to the volume of network data, the Hadoop Distributed File System (HDFS) and Apache Spark were used. The results determined the feature range/value/subset that would be useful in the classification of attack tactics in each machine learning classifier, Decision Trees (DT), Support Vector Machines (SVM), Naïve Bayes (NB), and Random Forest (RF), as well as in all classifiers as a whole, confirming that Association Rule Mining can be useful for explainable machine learning/artificial intelligence and showing inter-feature-value relationships. One of the documented drawbacks of ARM, the generation of too many rules, turned out to be an advantage in this research to help classify rare attacks. That is, in addition to ARM feature-subsets being used for regular explainable AI, ARM’s feature-subsets can also be used in explaining rare attacks.

References

[1] Ali, S., Abuhmed, T., El-Sappagh, S., Muhammad, K., Alonso-Moral, J. M., Confalonieri, R., Guidotti, R., Del Ser, J., Díaz-Rodríguez, N., & Herrera, F. (2023). Explainable Artificial Intelligence (XAI): What we know and what remains. Information Fusion, 99, 101805.

[2] Agrawal, R., Imielinski, T., & Swami, A. (1993). Mining association rules between sets of items in large databases. Proceedings of the 1993 ACM SIGMOD International Conference on Management of Data (pp. 207–216). ACM Press.

[3] Han, J., Pei, J., & Kamber, M. (2012). Data Mining: Concepts and Techniques (3rd ed.). Elsevier.

[4] Aggarwal, C. C., Bhuiyan, M. A., & Al Hasan, M. (2014). Frequent pattern mining algorithms: A survey. In C. C. Aggarwal & J. Han (Eds.), Frequent Pattern Mining (pp. 19–64). Springer.

[5] Bagui, S., Just, J., & Bagui, S. (2009). Deriving strong association mining rules using a dependency criteria, the lift measure. International Journal of Data Analysis Techniques and Strategies, 1(3), 297–312.

[6] Lou, P., Lu, G., Jiang, X., Xiao, Z., Hu, J., & Yan, J. (2020). Cyber intrusion detection through association rule mining on multi-source logs. Applied Intelligence, 51(6), 4043–4057.

[7] Cai, J., Luo, J., Wang, S., & Yang, S. (2017). Feature selection in machine learning: A new perspective. Neurocomputing, 300, 70–79.

[8] Rajeswari, K. (2015). Feature selection by mining optimized association rules based on Apriori algorithm. International Journal of Computer Applications, 119(20), 30–34.

[9] Pudjihartono, N., Fadason, T., Kempa-Liehr, A. W., & O’Sullivan, J. M. (2022). A review of feature selection methods for machine learning-based disease risk prediction. Frontiers in Bioinformatics, 2, 927312.

[10] Xue, Y., Tang, Y., Xu, X., Liang, J., & Neri, F. (2020). Multi-objective feature selection with missing data in classification. arXiv preprint, arXiv:2002.06842.

[11] Özdemir, Ö., & Yıldız, O. T. (2022). A comprehensive review of feature selection and feature selection stability. Gazi University Journal of Science, 36(4), 1412–1446.

[12] Bagui, S. S., Mink, D., Bagui, S. C., Ghosh, T., Plenkers, R., McElroy, T., Dulaney, S., & Shabanali, S. (2023). Introducing UWF-ZeekData22: A comprehensive network traffic dataset based on the MITRE ATT&CK framework. Data, 8(1), 18. https://doi.org/10.3390/data8010018

[13] UWF Datasets. Retrieved from https://datasets.uwf.edu/

[14] What Is the MITRE ATT&CK Framework? | Get the 101 Guide. (2024). Trellix. Retrieved from https://www.trellix.com/en-us/security-awareness/cybersecurity/what-is-mitre-attack-framework.html

[15] Zeek Documentation. Retrieved from https://docs.zeek.org/en/master/logs/conn.html

[16] Bagui, S., & Spratlin, S. (2018). A review of data mining algorithms on Hadoop’s MapReduce. International Journal of Data Science, 3(2), 146–169.

[17] Apache Hadoop. Retrieved from https://hadoop.apache.org/

[18] Apache Spark (2025). Spark 4.0.0 Configuration. Retrieved from https://spark.apache.org/

[19] Kotsiantis, S., & Kanellopoulos, D. (2006). Association rules mining: A recent overview. GESTS International Transactions on Computer Science and Engineering, 32, 71–82.

[20] Abu, M. S., Rahayu, S., Yusof, R., & Ariffin, A. (2020). Attribution of cyberattack using association rule mining. IJACSA, 11(2).

[21] Mironeanu, C., Archip, A., & Atomei, G. (2021). Application of association rule mining in preventing cyberattacks. Bulletin of the Polytechnic Institute of IAȘI, 67(4), 25–41.

[22] Guyon, I., Weston, J., Barnhill, S., et al. (2002). Gene selection for cancer classification using support vector machines. Machine Learning, 46, 389–422.

[23] Kursa, M. B., & Rudnicki, W. R. (2010). Feature selection with the Boruta package. Journal of Statistical Software, 36(11). doi: 10.18637/jss.v036.i11

[24] Raman, B., & Ioerger, T. R. (2002). Instance-based filter for feature selection. Journal of Machine Learning Research, 1(3), 1-23.

[25] Chen, R.-C., Dewi, D., Huang, S.-W., & Caraka, R. E. (2020). Selecting critical features for data classification based on machine learning methods. Journal of Big Data, 7, 52.

[26] Rostami, M., & Oussalah, M. (2022). Explainable COVID-19 diagnosis using feature selection and random forest. Informatics in Medicine Unlocked, 30, 100941. https://doi.org/10.1016/j.imu.2022.100941

[27] Hussain, A., & Hussain, A. (2025). Transparency and accountability: unpacking the real problems of explainable AI. AI & Soc. https://doi.org/10.1007/s00146-025-02302-0

[28] Bassan, S., Amir, G., & Katz, G. (2024). Local vs. global interpretability: A computational complexity perspective. Proceedings of the 41st International Conference on Machine Learning (ICML 2024) (Vol. 235).

[29] Saarela, M., & Podgorelec, V. (2024). Recent applications of Explainable AI (XAI): A systematic literature review. Applied Sciences, 14(19), 8884. https://doi.org/10.3390/app14198884

[30] Ponce-Bobadilla, A. V., Schmitt, V., Maier, C., Mensing, S., & Stodtmann, S. (2024). Practical guide to SHAP analysis. Clinical and Translational Science, 17(11), e70056.

[31] Hamilton, R. I., & Papadopoulos, P. N. (2024). Using SHAP values to understand transient stability limits. IEEE Transactions on Power Systems, 39(1), 1384–1397.

[32] Nohara, Y., Matsumoto, K., Soejima, H., & Nakashima, N. (2022). Explanation of machine learning models using SHAP. Computer Methods and Programs in Biomedicine, 214, 106584.

[33] Alodibat, S., Ahmad, A., & Azzeh, M. (2023). Explainable ML-based cybersecurity detection using LIME. Proceedings of IEEE JEEIT (pp. 235–242).

[34] Hermosilla, P., Berríos, S., & Allende-Cid, H. (2025). SHAP vs LIME for intrusion detection. Applied Sciences, 15, 7329.

[35] Bagui, S., Just, J., Bagui, S., & Hemasinha, R. (2010). Cosine-type measure for strong association rules. IJKEDM, 1(1), 69–83.

[36] Miller, E., Mink, D., Spellings, P., Bagui, S. S., & Bagui, S. C. (2025). Classifying cyber ranges. Encyclopedia, 5, 162.

[37] MITRE ATT&CK. Reconnaissance Tactic (TA0043). Retrieved from https://attack.mitre.org/tactics/TA0043/

[38] MITRE ATT&CK. Discovery Tactic (TA0007). Retrieved from https://attack.mitre.org/tactics/TA0007/

[39] MITRE ATT&CK. Credential Access Tactic (TA0006). Retrieved from https://attack.mitre.org/tactics/TA0006/

[40] MITRE ATT&CK. Privilege Escalation Tactic (TA0004). Retrieved from https://attack.mitre.org/tactics/TA0004/

[41] Bagui, S., Mink, D., Bagui, S., Ghosh, T., McElroy, T., Paredes, E., Khasnavis, N., & Plenkers, R. (2022). Detecting reconnaissance and discovery tactics in Zeek logs. Sensors, 22, 7999.

[42] Breiman, L. (2001). Random forests. Machine Learning, 45(1).

[43] Tan, P.-N., Steinbach, M., & Kumar, V. (2006). Introduction to Data Mining. Addison Wesley.

[44] Scikit-learn. Accuracy Score Documentation. Retrieved from https://scikit-learn.org/

[45] Powers, D. M. W. (2011). Evaluation: From precision, recall and F-Measure. Journal of Machine Learning Technologies, 2(1), 37–63.

Downloads

Published

2026-06-29

Issue

Section

Article