轻量可解释的网络安全检测框架,提升入侵识别效率与透明度。
LENS-XAI: Redefining Lightweight and Explainable Network Security through Knowledge Distillation and Variational Autoencoders for Scalable Intrusion Detection in Cybersecurity
- 用知识蒸馏与变分自编码器压缩模型,实现高效检测。
- 仅用10%数据训练,四大数据集准确率超95%。
- 适合资源受限环境,解释性强,适合实际部署。
工业物联网(IIoT)系统的快速发展要求具备先进性、可解释性和可扩展性的入侵检测系统(IDS)来应对新型网络威胁。传统IDS存在计算开销大、解释性差、难以适应不断演化的攻击模式等问题。为此,本文提出轻量可解释网络安全框架LENS-XAI,融合知识蒸馏、变分自编码器与基于归因的可解释性技术,实现高精度检测与决策透明化。该框架仅使用10%的训练数据,在四个基准数据集Edge-IIoTset、UKM-IDS20、CTU-13和NSL-KDD上分别达到95.34%、99.92%、98.42%和99.34%的检测准确率。同时,该框架显著降低误报率,适应复杂攻击场景,优于现有主流方法。其轻量设计适用于资源受限环境,可扩展性强,解释模块增强信任度,对动态敏感场景的实际应用至关重要。本研究推动了入侵检测在计算效率、特征可解释性与实际适用性方面的进展。未来工作可拓展至分布式环境下的集成式AI系统,进一步提升鲁棒性与适应性。
原文摘要 · Abstract (English)
The rapid proliferation of Industrial Internet of Things (IIoT) systems necessitates advanced, interpretable, and scalable intrusion detection systems (IDS) to combat emerging cyber threats. Traditional IDS face challenges such as high computational demands, limited explainability, and inflexibility against evolving attack patterns. To address these limitations, this study introduces the Lightweight Explainable Network Security framework (LENS-XAI), which combines robust intrusion detection with enhanced interpretability and scalability. LENS-XAI integrates knowledge distillation, variational autoencoder models, and attribution-based explainability techniques to achieve high detection accuracy and transparency in decision-making. By leveraging a training set comprising 10% of the available data, the framework optimizes computational efficiency without sacrificing performance. Experimental evaluation on four benchmark datasets: Edge-IIoTset, UKM-IDS20, CTU-13, and NSL-KDD, demonstrates the framework's superior performance, achieving detection accuracies of 95.34%, 99.92%, 98.42%, and 99.34%, respectively. Additionally, the framework excels in reducing false positives and adapting to complex attack scenarios, outperforming existing state-of-the-art methods. Key strengths of LENS-XAI include its lightweight design, suitable for resource-constrained environments, and its scalability across diverse IIoT and cybersecurity contexts. Moreover, the explainability module enhances trust and transparency, critical for practical deployment in dynamic and sensitive applications. This research contributes significantly to advancing IDS by addressing computational efficiency, feature interpretability, and real-world applicability. Future work could focus on extending the framework to ensemble AI systems for distributed environments, further enhancing its robustness and adaptability.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。