Source-linked AI summary

Explainable Artificial Intelligence Applications in Cyber Security: State-of-the-Art in Research

Zhibo Zhang, Hussam Al Hamadi, Ernesto Damiani, Chan Yeob Yeun, Fatma Taher

arXiv:2208.14937v1cs.CR

TL;DR

Black-box AI models limit transparency in cybersecurity decisions, while existing surveys had not focused on XAI applications in cybersecurity. This paper surveys the field’s methods, taxonomies, tools, datasets, and application scenarios, concluding that XAI supports more transparent security decisions while evaluation and dataset coverage remain challenges.

  • Problem

    Black-box AI models make cybersecurity decisions difficult to explain, despite transparency being important for trust, regulation, justice, and risk mitigation.

  • Method

    The paper conducts a comprehensive survey of state-of-the-art XAI cybersecurity research, synthesizing model taxonomies, tools, frameworks, datasets, and application scenarios.

  • Results

    The survey organizes XAI cybersecurity research across principles, taxonomies, tools, datasets, and application scenarios, including systems for defending against diverse cyber threats.

  • Takeaways & Limitations

    XAI offers a framework for making cybersecurity decisions more explainable and transparent, supporting user trust and the analysis of security decisions.

  • Takeaways & Limitations

    Public cybersecurity datasets often lack recent attack categories, potentially reducing their usefulness for training XAI-based defensive mechanisms.

Abstract

from arXiv · show

This survey presents a comprehensive review of current literature on Explainable Artificial Intelligence (XAI) methods for cyber security applications. Due to the rapid development of Internet-connected systems and Artificial Intelligence in recent years, Artificial Intelligence including Machine Learning (ML) and Deep Learning (DL) has been widely utilized in the fields of cyber security including intrusion detection, malware detection, and spam filtering. However, although Artificial Intelligence-based approaches for the detection and defense of cyber attacks and threats are more advanced and efficient compared to the conventional signature-based and rule-based cyber security strategies, most ML-based techniques and DL-based techniques are deployed in the black-box manner, meaning that security experts and customers are unable to explain how such procedures reach particular conclusions. The deficiencies of transparency and interpretability of existing Artificial Intelligence techniques would decrease human users' confidence in the models utilized for the defense against cyber attacks, especially in current situations where cyber attacks become increasingly diverse and complicated. Therefore, it is essential to apply XAI in the establishment of cyber security models to create more explainable models while maintaining high accuracy and allowing human users to comprehend, trust, and manage the next generation of cyber defense mechanisms. Although there are papers reviewing Artificial Intelligence applications in cyber security areas and the vast literature on applying XAI in many fields including healthcare, financial services, and criminal justice, the surprising fact is that there are currently no survey research articles that concentrate on XAI applications in cyber security.

I. INTRODUCTION · A. RESEARCH MOTIVATION

The survey motivates XAI for cyber security by highlighting rising cyber threats, limits of conventional and black-box AI defenses, and the need for explainable, trustworthy protection. It reviews XAI techniques, applications, challenges, datasets, frameworks, research gaps, and future directions in cyber security.

  • I. INTRODUCTION: Internet expansion and increasingly sophisticated attacks have intensified the need for secure systems that protect information privacy, accessibility, and integrity.Global cyber attacks increased by 29% in 2021, alongside a 0.3-billion increase in internet users.
  • I. INTRODUCTION: Conventional signature-based and rule-based defenses face challenges as information volumes grow and attackers develop new, smart, and intricate methods.
  • I. INTRODUCTION: Machine learning and deep learning achieve impressive benchmark performance across cyber security applications, including intrusion, spam, botnet, fraud, and malicious-application detection.These techniques can nevertheless commit errors that are more expensive than those of conventional defensive approaches.
  • I. INTRODUCTION: The survey addresses the limited transparency and interpretability of many AI-based cyber defenses, which complicates understanding and trust in their conclusions.The paper context characterizes many ML and DL techniques as black boxes that prevent security experts and customers from explaining particular decisions.
  • A. RESEARCH MOTIVATION: Prior research surveyed AI in cyber security and XAI in other fields, but no survey had concentrated specifically on XAI applications in cyber security.
  • A. RESEARCH MOTIVATION: The survey provides a comprehensive review of state-of-the-art XAI applications in cyber security and reviews different XAI techniques and categorizations.
  • A. RESEARCH MOTIVATION: It examines existing XAI challenges and problems, along with frameworks and available datasets for XAI-based cyber defensive mechanisms.
  • A. RESEARCH MOTIVATION: It reviews successful XAI-based cyber security systems, identifies research gaps, and presents key insights and future research directions.

B. PREVIOUS SURVEYS

Previous surveys largely treated XAI and cyber security separately, leaving their crossover insufficiently covered. This survey distinguishes itself by comprehensively organizing XAI techniques, applications, datasets, evaluation measures, challenges, and frameworks for cyber security.

  • Previous surveys mostly reviewed XAI and cyber security separately, although crossovers between the domains have emerged.
  • The survey introduces XAI techniques applied in cyber defensive systems and provides comprehensive categorizations of XAI methods for cyber security.
  • It also examines XAI challenges and frameworks while providing assessment measures for evaluating XAI model performance.
  • It summarizes cyber security datasets, discusses popular XAI tools, and analyzes applications for defending different categories of cyber attacks.

C. SCOPE OF CYBER SECURITY ANALYSED · D. CONTRIBUTIONS

The survey examines XAI across major cyber security attack domains, including emerging adversarial threats against AI and XAI models. It contributes a systematic state-of-the-art review spanning motivations, datasets, defensive applications, industrial scenarios, limitations, and security challenges.

  • C. SCOPE OF CYBER SECURITY ANALYSED: The survey defines cyber security around internet-data privacy, integrity, and availability while framing cyber attacks as computer-enabled criminal actions against systems or networks.
  • C. SCOPE OF CYBER SECURITY ANALYSED: By 2026, the worldwide cybersecurity sector is anticipated to be worth 345.4 billion USD, alongside emerging adversarial threats targeting AI models.
  • C. SCOPE OF CYBER SECURITY ANALYSED: The analyzed scope covers malware, botnets, spam, fraud, phishing, CPS attacks, network intrusion, DoS, MITM, DGAs, and SQL injection attacks.
  • C. SCOPE OF CYBER SECURITY ANALYSED: The survey introduces XAI for cyber security across domains and investigates adversarial threats against XAI models, defensive approaches, and secure XAI cyber systems.
  • D. CONTRIBUTIONS: The study evaluates state-of-the-art XAI solutions for cyber security applications and defensive mechanisms, addressing the absence of a systematic survey covering both defense schemes and industrial applications.
  • D. CONTRIBUTIONS: Its contributions rationalize integrating XAI into AI-based cyber security models, present XAI background, and summarize accessible datasets for cyber security applications.
  • D. CONTRIBUTIONS: The survey reviews XAI defensive applications, their advantages and limitations, industry scenarios, adversarial threats, defense approaches, and outstanding issues and challenges.

E. STRUCTURE OF THIS SURVEY · II. METHODOLOGY OF RESEARCH · III. XAI BACKGROUND

The survey first outlines its research methodology, then establishes XAI’s conceptual background before examining cyber security applications, challenges, future directions, and conclusions. Its methodology targets the state of the art through searches using XAI- and cyber-security-related terms across academic databases, while the background clarifies XAI concepts and perspectives.

  • E. STRUCTURE OF THIS SURVEY: The survey is organized to present research background and methodology before reviewing XAI applications in cyber security.Later sections address applications, challenges, future directions, and conclusions.
  • II. METHODOLOGY OF RESEARCH: The methodology investigates the state of the art in XAI applications in cyber security.The research methodology is documented in a flow chart in Figure 2.
  • II. METHODOLOGY OF RESEARCH: A thorough literature search used the academic search engines listed in Table 2 to collect relevant papers.The listed sources include Springer, Taylor & Francis, Semantic Scholar, ACM Digital Library, ResearchGate, Google Scholar, IEEE Xplore, Elsevier, and Research Rabbit.
  • II. METHODOLOGY OF RESEARCH: The search strategy used two keyword aspects: “XAI” and “Cyber Security,” with pertinent synonyms identified across databases.The percentage of reviewed papers from sources is depicted in Figure 3.
  • III. XAI BACKGROUND: XAI is defined as a technique that improves human understanding of how AI makes decisions.This background supplies prior knowledge for understanding subsequent cyber security applications.
  • III. XAI BACKGROUND: The XAI domain includes intelligibility, explainability, transparency, and interpretability, with interpretability described as similar to explainability.Their relationships are presented in Figure 5’s Venn diagram.
  • III. XAI BACKGROUND: The background section covers motivations for integrating XAI into cyber security, XAI categorizations, and existing XAI challenges.These perspectives provide readers with a general description of XAI and support deeper understanding of cyber security applications.

A. MOTIVATIONS TO INTEGRATE XAI INTO CYBER

Cyber attacks are becoming harder to manage as their complexity, volume, and data demands increase, while conventional approaches struggle with massive data and computing costs. XAI addresses AI’s black-box limitations by improving understanding, trust, regulatory compliance, fairness, and justification in cyber security systems.

  • Challenges and limitations: Growing cyber-attack complexity, volume, and emerging networking paradigms make cyber security increasingly difficult to manage.These challenges include malware, intrusion, spam, IoT, cloud computing, and fog/edge computing.
  • Challenges and limitations: Traditional approaches have low capacity to process massive data and high computing costs.
  • Challenges and limitations: AI-based cyber security systems face limitations involving data access, adversarial attacks, ethics, privacy, and especially black-box models.
  • Role of XAI: XAI helps users and specialists understand AI-generated results through logical explanations and the main supporting data evidence.
  • Motivations for integration: Motivations for integrating XAI include building trust, meeting regulations and GDPR requirements, addressing justice and risk, reducing bias, and providing justification.Transparency, understanding, fairness, social responsibility, and risk mitigation are presented as central concerns.

B. CATEGORIZATIONS OF XAI · C. EXISTING CHALLENGES OF XAI

XAI can be categorized across multiple, potentially overlapping perspectives, including model construction, model dependence, decision scope, and explanation format. Its adoption remains constrained by security vulnerabilities, inadequate evaluation standards, legal and privacy concerns, and the trade-off between interpretability and predictive accuracy.

  • B. CATEGORIZATIONS OF XAI: XAI categorizations may overlap, so analyzing a technique from multiple perspectives reveals more of its characteristics.The survey organizes XAI across different aspects rather than treating categories as mutually exclusive.
  • B. CATEGORIZATIONS OF XAI: Intrinsic methods generate explanations during prediction, whereas post-hoc methods analyze the model after training.Intrinsic approaches limit model complexity, while post-hoc approaches derive explanations from an already trained methodology.
  • B. CATEGORIZATIONS OF XAI: Model-specific explainers target one model or model class, while model-agnostic methods analyze inputs and outputs without internal model information.The graph neural network explainer is model-specific; SHAP, Saliency Map, and Grad-CAM are identified as widely used model-agnostic tools.
  • B. CATEGORIZATIONS OF XAI: Local explanations show why a particular decision was made, whereas global explanations concern the decision model’s broader scope.LIME, SHAP, and counterfactual explanations are listed as local methods, and local explainability is emphasized as a crucial component of transparency.
  • B. CATEGORIZATIONS OF XAI: Explanation outputs can be text-based or visualized, with their format influencing users and supporting different application domains.Text-based explanations are widely used in NLP, while visualized approaches are applied across broader domains.
  • C. EXISTING CHALLENGES OF XAI: XAI security is challenged because frequently deployed explanation models can be susceptible to adversarial attacks.The literature calls for defenses that recognize targeted attacks against XAI engines, particularly where human trust supports safety-critical autonomy.
  • C. EXISTING CHALLENGES OF XAI: XAI lacks an accepted evaluation system for determining whether one system is more user-intelligent or explainable than another.Proposed responses include feature-relevance testing environments for tabular data and ground-truth frameworks for evaluating heatmap quality.
  • C. EXISTING CHALLENGES OF XAI: XAI also faces legal and privacy issues, while explainability and predictive accuracy generally trade off against each other.Ethical guidance emphasizes privacy, data quality and integrity, and data access; highly performing models such as DL are often less explainable, while engineered or high-dimensional features can compromise simple models’ explainability.

IV. XAI FRAMEWORK AND DATASETS FOR CYBER SECURITY … V. XAI APPLICATIONS TO CYBER SECURITY

The paper proposes a general XAI workflow for cyber security, emphasizes careful data selection and quality, and organizes applications into defensive, industrial, and adversarial-threat domains. It also surveys public cyber-attack datasets and industry-specific datasets supporting XAI research.

  • A. XAI FRAMEWORK FOR CYBER SECURITY: The proposed framework models XAI application in cyber security as a multistage workflow with sample instances at each stage.The framework is presented as broadly applicable across cyber security domains.
  • A. XAI FRAMEWORK FOR CYBER SECURITY: The framework connects cyber security problems to corresponding data and model-training stages before applying XAI across cyber defense domains.This synthesis follows the workflow’s task-definition, data-processing, feature-extraction, and model-training sequence.
  • A. XAI FRAMEWORK FOR CYBER SECURITY: The workflow identifies cyber security tasks, collects corresponding data, extracts significant features, and trains Artificial Intelligence models for specific situations.Example tasks include malware, spam, and fraud detection; data sources include emails, network traffic, and application activities.
  • B. CYBER SECURITY DATABASES: Data selection is significant in cyber security research because data quality and capacity strongly influence ML- and DL-based XAI model decisions.Network packets can be captured using tools such as Win Dump or Wireshark.
  • B. CYBER SECURITY DATABASES: Frequently used public datasets cover malware, Botnet, spam, DGA, DoS, CPSs, phishing, and network intrusion attacks.Some datasets overlap because they contain multiple cyber-attack categories.
  • V. XAI APPLICATIONS TO CYBER SECURITY: Together, the reviewed datasets and application categories position XAI research across cyber-attack detection, industry-specific security, and attacks against explainable systems.The dataset overview includes both cyber-attack categories and industrial contexts.
  • B. CYBER SECURITY DATABASES: Industrial datasets demonstrate potential XAI applications for cyber security in smart cities, healthcare, agriculture, transportation, finance, and HCI.The overview considers applications across distinct industries and Human-Computer Interaction.
  • V. XAI APPLICATIONS TO CYBER SECURITY: The survey categorizes XAI cyber security applications into defensive applications, industrial applications, and cyber adversarial threats targeting XAI.It also discusses defense approaches against attacks targeting XAI applications.

A. XAI APPLICATIONS IN DEFENDING AGAINST

XAI applications span intrusion, botnet, fraud, phishing, spam, and adversarial-network defense, combining interpretable models or post-hoc explanations with strong detection performance. The reviewed studies also show trade-offs between explanation quality, speed, feature complexity, scalability, and model maintenance.

  • Spam Classification: Spam-classification research emphasized selecting a task-appropriate model and evaluating interpretability with metrics including Intersection-Over-Union, comprehensiveness, and sufficiency.HateXplain was introduced as a benchmark dataset addressing bias and explainability, while another study used 5574 SMS messages to examine the accuracy–explainability trade-off.
  • Botnet Detection: Botnet detection studies used feature reduction and interpretable or post-hoc methods to address computational complexity and increase user trust.PCA reduced feature dimensions while a Decision Tree illustrated label decisions; another DCNN system used SHAP and improved all performance metrics by up to 15%.
  • Explanation and Trust: Across detection applications, SHAP was described as more reliable and LIME as faster, while a three-stage adversarial-defense architecture achieved accuracy rates of 98.5 percent and 100 percent on test data and adversarial samples.The reviewed work suggested combining SHAP for regulatory compliance with LIME for real-time explanations and using transparency to increase user trust.
  • Fraud Detection: Fraud detection research combined SHAP, memory networks, clustering, and explanation-driven pipelines to improve interpretability while addressing abnormal behavior and concept drift.SHAP_Model achieved overall accuracy of 94% and AUC of 96.9%; FraudMemory achieved precision of 0.968 and AUC of 0.969.
  • Phishing Detection: Phishing detection systems added explainability through LIME, EBM, visual explanations, and brand or logo recognition while maintaining accurate URL classification.EBM, Random Forest, and SVM achieved accuracy of 0.9646, 0.9732, and 0.9469 respectively.

B. XAI FOR CYBER SECURITY IN INDUSTRIAL APPLICATIONS

This section surveys explainable AI applications for cybersecurity across industrial domains, focusing on healthcare and smart cities. It highlights how XAI addresses black-box limitations by improving transparency, interpretability, accountability, and trust in high-risk, data-driven systems.

  • XAI FOR CYBER SECURITY OF HEALTHCARE: Healthcare applications use XAI to improve transparency and explainability amid vulnerabilities arising from connected devices, patient monitoring, and privacy concerns.Studies apply XAI frameworks to address privacy and security issues in smart healthcare systems.
  • XAI FOR CYBER SECURITY OF HEALTHCARE: Healthcare studies use Anchors, Counterfactuals, Integrated Gradients, Contrastive Explanation Method, and Kernel Shapley to expose deep-learning black boxes and support accountability.The approaches were discussed using a heart disease dataset to motivate explainability-method selection in medical DL systems.
  • XAI FOR CYBER SECURITY OF HEALTHCARE: BrainGNN explains neurological-biomarker predictions by using ROI-selection pooling to highlight prominent brain regions relevant to classification.The framework analyzes functional magnetic resonance images with an explainable graph neural network.
  • XAI FOR CYBER SECURITY OF SMART CITIES: Smart-city applications require XAI because IoT-, blockchain-, and deep-learning services operate in high-risk, privacy-sensitive scenarios requiring justified data-driven decisions.XAI integration is presented as a way to address black-box difficulties and provide authorities with information about decisions and their implications.
  • XAI FOR CYBER SECURITY OF SMART CITIES: Smart-city research includes SHAP-enhanced gradient-boosted regression trees for analyzing meteorological determinants and interpretable surrogate modeling for bus-passenger-demand prediction.The transport approach uses an LSTM, a surrogate model, and a 2-tuple fuzzy linguistic model to enhance linguistic interpretability without sacrificing precision.

3) XAI FOR CYBER SECURITY OF SMART FARMING

Smart farming combines interconnected technologies and AI, increasing exposure to cyber-security risks that can threaten agricultural infrastructure and economies. XAI applications in this domain include plant-disease classification and interpretable analysis of agricultural land-use factors.

  • Motivation: Smart farming integrates IoT, robots, drones, sensors, geolocation, big data, cloud computing, AI, and augmented reality, creating cyber-security risks for its infrastructure.Cyber attacks can also harm economies that heavily rely on agriculture.
  • Plant-disease detection: Custom-Net deep-learning models classified rust and blast in pearl millet with 98.78% accuracy and reduced training time by 86.67%.The models used parametric data from pearl millet farmland at ICAR, Mysore, India, and achieved accuracy similar to state-of-the-art comparison models.
  • Agricultural land-use analysis: Random Forest and LIME were applied to approximately 140 socioeconomic, biophysical, and bioclimatic variables to provide global and local explanations of agricultural land-use factors.The analysis examined plantation use for wheat, maize, and olive trees.

C. CYBER THREATS TARGETING XAI AND DEFENSIVE

XAI models and their explainability components are themselves vulnerable to cyber attacks, including attacks that exploit explanations to compromise model behavior or conceal bias. The reviewed defensive approaches modify training data or processes, model networks, or use auxiliary tools to improve resilience.

  • Threats targeting XAI: XAI models and their explainability components can both be vulnerable to cyber attacks.Attackers may target the deployed AI model, the explainability component, or both.
  • Threats targeting XAI: Attackers can exploit explainable characteristics, motivating a dedicated review of threats targeting XAI and corresponding defenses.The explainable part requires protection in addition to samples, learning models, and interoperation processes.
  • Threats targeting XAI: Black-box attacks can target gradient-based XAI consistency, accuracy, and confidence through integrity-only or classifier-and-explainer compromise.The I attack targets a single explainer without changing classifier predictions on natural samples, whereas the CI attack compromises both classifier and explainer.
  • Threats targeting XAI: Adversarial image patches, activation manipulation, and deceptive scaffolding can distort explanations or hide classifier biases across vision and NLP models.Reported attacks target methods including gradient-weighted class activation mapping, InteGrad, SmoothGrad, LIME, and SHAP; LIME was more susceptible than SHAP in one fooling study.
  • Defensive approaches: Defensive approaches are grouped into modifying training processes or input data, modifying model networks, and using auxiliary tools.Examples include JPG compression, DeepCloak, and Defense-GAN for mitigating adversarial attacks.

VI. ANALYSIS AND DISCUSSION · A. CHALLENGES OF USING XAI FOR CYBER

The review identifies major challenges for using XAI in cyber security, including outdated datasets, inadequate explanation evaluation, attacks against XAI models, and privacy and ethical concerns. It also highlights implementation priorities involving user trust, model inspection, algorithm selection, tuning, and model defense.

  • A. CHALLENGES OF USING XAI FOR CYBER: XAI applications in cyber security face challenges despite improving transparency and explainability for AI-enabled defense systems.The review organizes these challenges around datasets, evaluation, cyber threats, and privacy and ethical issues.
  • A. CHALLENGES OF USING XAI FOR CYBER: Many commonly used cyber security datasets are outdated and omit recent attack categories, potentially because of privacy and ethical issues.This limitation can reduce the relevance of XAI-based cyber security systems to evolving threats.
  • A. CHALLENGES OF USING XAI FOR CYBER: XAI evaluation must assess explanation accuracy and completeness alongside conventional performance measures such as F1-Score, Precision, and ROC.Explanation-focused assessment is required in addition to measuring the cyber security mechanism’s predictive performance.
  • A. CHALLENGES OF USING XAI FOR CYBER: Explanation evaluations should measure quality, value, satisfaction, users’ mental-model improvement, model effectiveness, confidence, and reliance.The review notes that existing findings do not fully establish these explanation-related measurements.
  • A. CHALLENGES OF USING XAI FOR CYBER: Current XAI models face cyber attacks targeting vulnerabilities in explanation approaches, threatening cyber security systems that depend on explainability.Maintaining explanation transparency and system efficiency is important for preventing cyber attacks.
  • A. CHALLENGES OF USING XAI FOR CYBER: Privacy and ethical issues require XAI models to address privacy throughout the system life cycle, especially for authentication, e-mails, and passwords.The review emphasizes respecting individuals’ privacy in sensitive cyber security applications.
  • A. CHALLENGES OF USING XAI FOR CYBER: Key implementation insights include satisfying user trust and reliance, supporting model visualization and inspection, and selecting explanation approaches appropriate to each task.Explanations allow users to assess system correctness and reliability, while visualization and inspection support examination of model behavior.
  • A. CHALLENGES OF USING XAI FOR CYBER: XAI implementation also requires tuning parameters and model structures and defending decision models, security data, and explanations against cyber attackers.Different ML or DL algorithms and explanation approaches can significantly affect model performance and explainability.

C. FUTURE RESEARCH DIRECTIONS · VII. CONCLUSION

The paper identifies future research priorities for XAI in cyber security, including trustworthy data, balanced performance and explainability, user-centered evaluation, multimodality, adversarial robustness, and data protection. It concludes that XAI provides transparency for AI-based cyber security decisions and surveys state-of-the-art research in this area.

  • C. FUTURE RESEARCH DIRECTIONS: High-quality datasets are needed because dataset quantity, quality, bias, and constraints affect cyber security XAI decisions and explanations.Existing datasets may not represent recent cyber attacks because of privacy and ethical issues.
  • C. FUTURE RESEARCH DIRECTIONS: Future XAI research must examine the trade-off between cyber security model performance and explainability.Decision Trees are transparent and easier to understand, while some researchers have explored methods to reduce this trade-off.
  • C. FUTURE RESEARCH DIRECTIONS: User-centered XAI should prioritize human understandability and user satisfaction when evaluating generated explanations.Cyber security user questionnaires and feedback remain limited because of security concerns.
  • C. FUTURE RESEARCH DIRECTIONS: Multimodal XAI can combine text, video, audio, and images to provide richer and more comprehensive representations of cyber security issues.People can readily understand multimodal information in the same context, while cyber security decisions may involve variables from multiple signals.
  • C. FUTURE RESEARCH DIRECTIONS: Future research should address adversarial attacks against both XAI model performance and explainability, including attacks using adversarial sample inputs.Powerful tools have been developed to fool state-of-the-art XAI methods such as LIME and SHAP.
  • C. FUTURE RESEARCH DIRECTIONS: XAI cyber security systems must protect both user-related decisions and generated explanations while preserving legitimate data access.This creates a conflict between using big data for security and safeguarding it from adversarial assaults, manipulation, and unauthorized users.
  • VII. CONCLUSION: XAI introduces explainability and transparency to conventional ML and DL decisions, which are required for defending against threats and analyzing security decisions.The paper presents a comprehensive survey of state-of-the-art research on XAI for cyber security applications.
Loading 2208.14937v1…