{"id":"https://openalex.org/W7126098786","doi":"https://doi.org/10.1109/comcomap68359.2025.11353200","title":"Lightweight LLMs for Network Attack Detection in IoT Networks","display_name":"Lightweight LLMs for Network Attack Detection in IoT Networks","publication_year":2025,"publication_date":"2025-12-14","ids":{"openalex":"https://openalex.org/W7126098786","doi":"https://doi.org/10.1109/comcomap68359.2025.11353200"},"language":null,"primary_location":{"id":"doi:10.1109/comcomap68359.2025.11353200","is_oa":false,"landing_page_url":"https://doi.org/10.1109/comcomap68359.2025.11353200","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 Computing, Communications and IoT Applications (ComComAp)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5123614079","display_name":"Piyumi Bhagya Sudasinghe","orcid":null},"institutions":[{"id":"https://openalex.org/I128559575","display_name":"University of Ruhuna","ror":"https://ror.org/033jvzr14","country_code":"LK","type":"education","lineage":["https://openalex.org/I128559575"]}],"countries":["LK"],"is_corresponding":true,"raw_author_name":"Piyumi Bhagya Sudasinghe","raw_affiliation_strings":["University of Ruhuna,Department of Electrical and Information Engineering,Matara,Sri Lanka,81000"],"affiliations":[{"raw_affiliation_string":"University of Ruhuna,Department of Electrical and Information Engineering,Matara,Sri Lanka,81000","institution_ids":["https://openalex.org/I128559575"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5123568714","display_name":"Kushan Sudheera Kalupahana Liyanage","orcid":null},"institutions":[{"id":"https://openalex.org/I128559575","display_name":"University of Ruhuna","ror":"https://ror.org/033jvzr14","country_code":"LK","type":"education","lineage":["https://openalex.org/I128559575"]}],"countries":["LK"],"is_corresponding":false,"raw_author_name":"Kushan Sudheera Kalupahana Liyanage","raw_affiliation_strings":["University of Ruhuna,Department of Electrical and Information Engineering,Matara,Sri Lanka,81000"],"affiliations":[{"raw_affiliation_string":"University of Ruhuna,Department of Electrical and Information Engineering,Matara,Sri Lanka,81000","institution_ids":["https://openalex.org/I128559575"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5123619580","display_name":"Harsha S. Gardiyawasam Pussewalage","orcid":null},"institutions":[{"id":"https://openalex.org/I200650556","display_name":"University of Agder","ror":"https://ror.org/03x297z98","country_code":"NO","type":"education","lineage":["https://openalex.org/I200650556"]}],"countries":["NO"],"is_corresponding":false,"raw_author_name":"Harsha S. Gardiyawasam Pussewalage","raw_affiliation_strings":["University of Agder (UiA),Department of Information and Communication Technology,Grimstad,Norway,N-4898"],"affiliations":[{"raw_affiliation_string":"University of Agder (UiA),Department of Information and Communication Technology,Grimstad,Norway,N-4898","institution_ids":["https://openalex.org/I200650556"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5123614079"],"corresponding_institution_ids":["https://openalex.org/I128559575"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.75301135,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"395","last_page":"400"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9139000177383423,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9139000177383423,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.019099999219179153,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11644","display_name":"Spam and Phishing Detection","score":0.00860000029206276,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/intrusion-detection-system","display_name":"Intrusion detection system","score":0.6485999822616577},{"id":"https://openalex.org/keywords/adaptation","display_name":"Adaptation (eye)","score":0.6245999932289124},{"id":"https://openalex.org/keywords/internet-of-things","display_name":"Internet of Things","score":0.5820000171661377},{"id":"https://openalex.org/keywords/random-forest","display_name":"Random forest","score":0.4916999936103821},{"id":"https://openalex.org/keywords/support-vector-machine","display_name":"Support vector machine","score":0.43230000138282776},{"id":"https://openalex.org/keywords/the-internet","display_name":"The Internet","score":0.4081000089645386},{"id":"https://openalex.org/keywords/scale","display_name":"Scale (ratio)","score":0.39489999413490295},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.39250001311302185}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7366999983787537},{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.6485999822616577},{"id":"https://openalex.org/C139807058","wikidata":"https://www.wikidata.org/wiki/Q352374","display_name":"Adaptation (eye)","level":2,"score":0.6245999932289124},{"id":"https://openalex.org/C81860439","wikidata":"https://www.wikidata.org/wiki/Q251212","display_name":"Internet of Things","level":2,"score":0.5820000171661377},{"id":"https://openalex.org/C169258074","wikidata":"https://www.wikidata.org/wiki/Q245748","display_name":"Random forest","level":2,"score":0.4916999936103821},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.45010000467300415},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.439300000667572},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.4392000138759613},{"id":"https://openalex.org/C12267149","wikidata":"https://www.wikidata.org/wiki/Q282453","display_name":"Support vector machine","level":2,"score":0.43230000138282776},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.4081000089645386},{"id":"https://openalex.org/C2778755073","wikidata":"https://www.wikidata.org/wiki/Q10858537","display_name":"Scale (ratio)","level":2,"score":0.39489999413490295},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.39250001311302185},{"id":"https://openalex.org/C2778712577","wikidata":"https://www.wikidata.org/wiki/Q3505966","display_name":"Retraining","level":2,"score":0.3783999979496002},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.3472999930381775},{"id":"https://openalex.org/C12725497","wikidata":"https://www.wikidata.org/wiki/Q810247","display_name":"Baseline (sea)","level":2,"score":0.3287999927997589},{"id":"https://openalex.org/C182590292","wikidata":"https://www.wikidata.org/wiki/Q989632","display_name":"Network security","level":2,"score":0.321399986743927},{"id":"https://openalex.org/C158251709","wikidata":"https://www.wikidata.org/wiki/Q354025","display_name":"Intrusion","level":2,"score":0.3172000050544739},{"id":"https://openalex.org/C65856478","wikidata":"https://www.wikidata.org/wiki/Q3991682","display_name":"Attack model","level":2,"score":0.28949999809265137},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.2888000011444092},{"id":"https://openalex.org/C27061796","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion prevention system","level":3,"score":0.2840000092983246},{"id":"https://openalex.org/C137524506","wikidata":"https://www.wikidata.org/wiki/Q2247688","display_name":"Anomaly-based intrusion detection system","level":3,"score":0.2831000089645386},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.2825999855995178},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.2809999883174896},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.2736000120639801},{"id":"https://openalex.org/C120314980","wikidata":"https://www.wikidata.org/wiki/Q180634","display_name":"Distributed computing","level":1,"score":0.2648000121116638},{"id":"https://openalex.org/C2779208394","wikidata":"https://www.wikidata.org/wiki/Q7140460","display_name":"Participatory sensing","level":2,"score":0.26100000739097595}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/comcomap68359.2025.11353200","is_oa":false,"landing_page_url":"https://doi.org/10.1109/comcomap68359.2025.11353200","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 Computing, Communications and IoT Applications (ComComAp)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":15,"referenced_works":["https://openalex.org/W2991507433","https://openalex.org/W4206130810","https://openalex.org/W4393357391","https://openalex.org/W4401113920","https://openalex.org/W4402353070","https://openalex.org/W4403753254","https://openalex.org/W4404055433","https://openalex.org/W4405578990","https://openalex.org/W4406207657","https://openalex.org/W4407509125","https://openalex.org/W4409455823","https://openalex.org/W4409724337","https://openalex.org/W4410857897","https://openalex.org/W4411639796","https://openalex.org/W4416799781"],"related_works":[],"abstract_inverted_index":{"The":[0],"rapid":[1],"growth":[2],"of":[3,5,15,106,142],"Internet":[4],"Things":[6],"(IoT)":[7],"devices":[8],"has":[9],"increased":[10],"the":[11,94,110,121,140],"scale":[12],"and":[13,33,73,148],"diversity":[14],"cyberattacks,":[16],"exposing":[17],"limitations":[18],"in":[19],"traditional":[20],"intrusion":[21,154],"detection":[22,63],"systems.":[23],"Classical":[24],"machine":[25],"learning":[26],"(ML)":[27],"models":[28],"such":[29],"as":[30,146],"Random":[31,111],"Forest":[32,112],"Support":[34],"Vector":[35],"Machine":[36],"perform":[37],"well":[38],"on":[39,93,126],"known":[40,117],"attacks":[41],"but":[42],"require":[43],"retraining":[44],"to":[45,109],"detect":[46],"unseen":[47,127],"or":[48],"zero-day":[49],"threats.":[50],"This":[51],"study":[52],"investigates":[53],"lightweight":[54,144],"decoder-only":[55],"Large":[56],"Language":[57],"Models":[58],"(LLMs)":[59],"for":[60,116,151],"IoT":[61,153],"attack":[62,128],"by":[64],"integrating":[65],"structured-to-text":[66],"conversion,":[67],"Quantized":[68],"Low-Rank":[69],"Adaptation":[70],"(QLoRA)":[71],"fine-tuning,":[72],"Retrieval-Augmented":[74],"Generation":[75],"(RAG).":[76],"Network":[77],"traffic":[78],"features":[79],"are":[80],"transformed":[81],"into":[82],"compact":[83],"natural-language":[84],"prompts,":[85],"enabling":[86],"efficient":[87],"adaptation":[88],"under":[89],"constrained":[90],"hardware.":[91],"Experiments":[92],"CICIoT2023":[95],"dataset":[96],"show":[97],"that":[98],"a":[99],"QLoRA-tuned":[100],"LLaMA-1B":[101],"model":[102],"achieves":[103],"an":[104],"F1-score":[105],"0.7124,":[107],"comparable":[108],"(RF)":[113],"baseline":[114],"(0.7159)":[115],"attacks.":[118],"With":[119],"RAG,":[120],"system":[122],"attains":[123],"42.63%":[124],"accuracy":[125],"types":[129],"without":[130],"additional":[131],"training,":[132],"demonstrating":[133],"practical":[134],"zero-shot":[135],"capability.":[136],"These":[137],"results":[138],"highlight":[139],"potential":[141],"retrieval-enhanced":[143],"LLMs":[145],"adaptable":[147],"resource-efficient":[149],"solutions":[150],"next-generation":[152],"detection.":[155]},"counts_by_year":[],"updated_date":"2026-02-01T03:34:12.195049","created_date":"2026-01-30T00:00:00"}
