arXiv:2503.21674cs.CRcs.AI2025-03AAAI被引 9

用边缘大模型+知识库,高效识别复杂物联网攻击

Intelligent IoT Attack Detection Design via ODLLM with Feature Ranking-based Knowledge Base

  • 在设备端用大模型结合特征排序构建知识库
  • 小模型在边缘环境仍保持高准确率检测
  • 适合资源受限的物联网安全实时防护

物联网设备的普及带来了严峻的网络安全挑战,尤其是分布式拒绝服务(DDoS)攻击日益频繁且复杂。传统机器学习方法难以应对混合演化型攻击模式。为此,本文提出一种新框架,利用设备端大语言模型(ODLLM)结合微调与知识库(KB)集成,实现智能物联网网络攻击检测。通过特征排序技术,构建适配模型容量的长短知识库,兼顾效率与精度,在计算和隐私受限条件下有效检测DDoS攻击。仿真结果表明,优化后的框架在多种攻击类型下均表现优异,尤其在边缘计算环境中使用紧凑模型时依然保持高准确率。该工作为实时物联网安全提供可扩展、高可靠的解决方案,推动边缘智能在网络安全中的应用。

原文摘要 · Abstract (English)

The widespread adoption of Internet of Things (IoT) devices has introduced significant cybersecurity challenges, particularly with the increasing frequency and sophistication of Distributed Denial of Service (DDoS) attacks. Traditional machine learning (ML) techniques often fall short in detecting such attacks due to the complexity of blended and evolving patterns. To address this, we propose a novel framework leveraging On-Device Large Language Models (ODLLMs) augmented with fine-tuning and knowledge base (KB) integration for intelligent IoT network attack detection. By implementing feature ranking techniques and constructing both long and short KBs tailored to model capacities, the proposed framework ensures efficient and accurate detection of DDoS attacks while overcoming computational and privacy limitations. Simulation results demonstrate that the optimized framework achieves superior accuracy across diverse attack types, especially when using compact models in edge computing environments. This work provides a scalable and secure solution for real-time IoT security, advancing the applicability of edge intelligence in cybersecurity.

物联网安全边缘计算大模型攻击检测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。