LENS-XAI: Redefining Lightweight and Explainable Network Security through Knowledge Distillation and Variational Autoencoders for Scalable Intrusion Detection in Cybersecurity

Muhammet Anil Yagiz,Polat Goktas
2025-01-01
Abstract:The rapid proliferation of Industrial Internet of Things (IIoT) systems necessitates advanced, interpretable, and scalable intrusion detection systems (IDS) to combat emerging cyber threats. Traditional IDS face challenges such as high computational demands, limited explainability, and inflexibility against evolving attack patterns. To address these limitations, this study introduces the Lightweight Explainable Network Security framework (LENS-XAI), which combines robust intrusion detection with enhanced interpretability and scalability. LENS-XAI integrates knowledge distillation, variational autoencoder models, and attribution-based explainability techniques to achieve high detection accuracy and transparency in decision-making. By leveraging a training set comprising 10% of the available data, the framework optimizes computational efficiency without sacrificing performance. Experimental evaluation on four benchmark datasets: Edge-IIoTset, UKM-IDS20, CTU-13, and NSL-KDD, demonstrates the framework's superior performance, achieving detection accuracies of 95.34%, 99.92%, 98.42%, and 99.34%, respectively. Additionally, the framework excels in reducing false positives and adapting to complex attack scenarios, outperforming existing state-of-the-art methods. Key strengths of LENS-XAI include its lightweight design, suitable for resource-constrained environments, and its scalability across diverse IIoT and cybersecurity contexts. Moreover, the explainability module enhances trust and transparency, critical for practical deployment in dynamic and sensitive applications. This research contributes significantly to advancing IDS by addressing computational efficiency, feature interpretability, and real-world applicability. Future work could focus on extending the framework to ensemble AI systems for distributed environments, further enhancing its robustness and adaptability.
Cryptography and Security,Artificial Intelligence,Computers and Society,Emerging Technologies
What problem does this paper attempt to address?
The problems that this paper attempts to solve are as follows: Against the backdrop of the rapid development of the Industrial Internet of Things (IIoT) systems, traditional Intrusion Detection Systems (IDS) face challenges such as high computational requirements, limited interpretability, and poor adaptability to evolving attack patterns. To address these issues, this paper introduces a new lightweight and interpretable network security framework (LENS - XAI), aiming to achieve efficient intrusion detection through knowledge distillation and Variational Auto - Encoder (VAE) techniques and provide a transparent decision - making process. Specifically, this research mainly focuses on the following aspects: 1. **Improving computational efficiency**: Traditional IDS models usually require a large amount of computational resources, which is a major obstacle in resource - constrained environments (such as the Internet of Things and edge computing). LENS - XAI optimizes computational efficiency by transferring the knowledge of complex models to more lightweight models through knowledge distillation. 2. **Enhancing interpretability**: Many deep - learning models are difficult to be trusted in critical applications due to their "black - box" characteristics. LENS - XAI combines attribution - based interpretability techniques, enabling the model not only to accurately detect abnormal behaviors but also to clearly explain the basis for its decisions, thus increasing the credibility and transparency of the system. 3. **Improving adaptability and scalability**: As network attack patterns keep changing, IDS must be able to quickly adapt to emerging threats. LENS - XAI has designed a flexible and scalable architecture that can better cope with complex attack scenarios and reduce the false - positive rate. 4. **Achieving real - time performance**: To ensure effective operation in a real - time environment, LENS - XAI optimizes the training and inference processes, using a training set that accounts for only 10% of the total data to maintain high performance while reducing computational costs. In summary, this paper aims to redefine lightweight and interpretable network security by proposing the LENS - XAI framework, and in particular, to provide an efficient, reliable, and easy - to - understand intrusion detection solution in the case of limited computational resources.