计算机科学
入侵检测系统
人工智能
推论
稳健性(进化)
机器学习
钥匙(锁)
对偶(语法数字)
适应性
物联网
语言模型
特征(语言学)
互操作性
注释
数据挖掘
模型攻击
语义学(计算机科学)
数据建模
分类器(UML)
随机森林
监督学习
特征工程
聊天机器人
计算智能
编码(社会科学)
人工智能应用
标识
DOI:10.1093/comjnl/bxag081
摘要
Abstract Intrusion detection systems (IDS) are pivotal for safeguarding artificial intelligence of things (AIoT)-enabled smart societies, where intensive interactions among IoT devices and AI services create expanding attack surfaces. However, conventional supervised IDS approaches depend heavily on large labeled datasets and often lack adaptability to emerging attacks. To overcome these limitations, we propose a unified intrusion detection system with dual re-ranking and large language model inference (UIDS-DRLLM), a parameter-training-free, retrieval-augmented framework for AIoT environments . UIDS-DRLLM introduces a dual re-ranking strategy that combines large language model (LLM)-based semantic similarity, correlation-weighted IoT feature analysis, and Elasticsearch retrieval to identify relevant historical threat patterns without model retraining. Based on the retrieved few-shot context, a prompt-driven LLM inference module performs interpretable attack classification through expert-like reasoning. Furthermore, a dynamic weighted aggregation mechanism adaptively integrates multi-source outputs to improve robustness across heterogeneous IoT scenarios. Experiments on NSL-KDD and UNSW-NB15 show that UIDS-DRLLM achieves competitive accuracy of 0.896 and 0.916, respectively, outperforming baseline methods. Its parameter-training-free and few-shot learning design reduce annotation and computational costs, while LLM-driven reasoning enhances explainability and trustworthiness. By addressing key challenges in IoT security—scalability, adaptability, and explainability—UIDS-DRLLM provides a scalable, adaptive, and interpretable solution for securing AIoT ecosystems against evolving cyber threats.
科研通智能强力驱动
Strongly Powered by AbleSci AI