提出轻量可解释AI框架,实现在边缘设备的实时威胁检测
Towards Explainable and Lightweight AI for Real-Time Cyber Threat Hunting in Edge Networks
- 结合决策树与注意力机制,兼顾模型透明度与效率
- 在CICIDS和UNSW-NB15数据集上实现高检出率且误报低
- 适合资源受限的边缘安全场景,便于分析师理解判断
随着网络攻击持续演化,由于边缘网络分布特性及资源限制,其安全防护日益困难。现有基于深度学习的威胁检测系统虽精度高,但存在不可解释性和计算开销大两大缺陷。黑箱模型难以让安全分析师理解预测依据,且传统深度学习需大量算力,不适配边缘设备。为此,本文提出面向边缘网络的可解释轻量级AI(ELAI)框架,融合可解释机器学习与优化的轻量深度学习技术,兼顾透明性与计算效率。系统采用决策树、注意力机制与联邦学习,在多个攻击场景下提升检测性能。基于CICIDS与UNSW-NB15等基准数据集的实验表明,该框架在显著降低计算开销的同时,实现高检测率与低误报率。主要贡献包括:(1)专为边缘计算设计的可解释网络安全模型;(2)面向实时威胁检测的轻量化深度学习优化方法;(3)对AI安全应用中可解释性技术的系统分析。
原文摘要 · Abstract (English)
As cyber threats continue to evolve, securing edge networks has become increasingly challenging due to their distributed nature and resource limitations. Many AI-driven threat detection systems rely on complex deep learning models, which, despite their high accuracy, suffer from two major drawbacks: lack of interpretability and high computational cost. Black-box AI models make it difficult for security analysts to understand the reasoning behind their predictions, limiting their practical deployment. Moreover, conventional deep learning techniques demand significant computational resources, rendering them unsuitable for edge devices with limited processing power. To address these issues, this study introduces an Explainable and Lightweight AI (ELAI) framework designed for real-time cyber threat detection in edge networks. Our approach integrates interpretable machine learning algorithms with optimized lightweight deep learning techniques, ensuring both transparency and computational efficiency. The proposed system leverages decision trees, attention-based deep learning, and federated learning to enhance detection accuracy while maintaining explainability. We evaluate ELAI using benchmark cybersecurity datasets, such as CICIDS and UNSW-NB15, assessing its performance across diverse cyberattack scenarios. Experimental results demonstrate that the proposed framework achieves high detection rates with minimal false positives, all while significantly reducing computational demands compared to traditional deep learning methods. The key contributions of this work include: (1) a novel interpretable AI-based cybersecurity model tailored for edge computing environments, (2) an optimized lightweight deep learning approach for real-time cyber threat detection, and (3) a comprehensive analysis of explainability techniques in AI-driven cybersecurity applications.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。