{"id":"https://openalex.org/W7138911177","doi":"https://doi.org/10.1109/globecom59602.2025.11432529","title":"DLM-IDS: Leveraging LLM for Efficient IoT Intrusion Detection with Limited Training Data","display_name":"DLM-IDS: Leveraging LLM for Efficient IoT Intrusion Detection with Limited Training Data","publication_year":2025,"publication_date":"2025-12-08","ids":{"openalex":"https://openalex.org/W7138911177","doi":"https://doi.org/10.1109/globecom59602.2025.11432529"},"language":null,"primary_location":{"id":"doi:10.1109/globecom59602.2025.11432529","is_oa":false,"landing_page_url":"https://doi.org/10.1109/globecom59602.2025.11432529","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"GLOBECOM 2025 - 2025 IEEE Global Communications Conference","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5100748981","display_name":"Liying Li","orcid":"https://orcid.org/0000-0003-3516-6679"},"institutions":[{"id":"https://openalex.org/I14243506","display_name":"Hong Kong Polytechnic University","ror":"https://ror.org/0030zas98","country_code":"HK","type":"education","lineage":["https://openalex.org/I14243506"]}],"countries":["HK"],"is_corresponding":true,"raw_author_name":"Liying Li","raw_affiliation_strings":["The Hong Kong Polytechnic University,Department of Computing,Hong Kong"],"affiliations":[{"raw_affiliation_string":"The Hong Kong Polytechnic University,Department of Computing,Hong Kong","institution_ids":["https://openalex.org/I14243506"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5128850564","display_name":"Mingyang Zhao","orcid":null},"institutions":[{"id":"https://openalex.org/I14243506","display_name":"Hong Kong Polytechnic University","ror":"https://ror.org/0030zas98","country_code":"HK","type":"education","lineage":["https://openalex.org/I14243506"]}],"countries":["HK"],"is_corresponding":false,"raw_author_name":"Mingyang Zhao","raw_affiliation_strings":["The Hong Kong Polytechnic University,Department of Computing,Hong Kong"],"affiliations":[{"raw_affiliation_string":"The Hong Kong Polytechnic University,Department of Computing,Hong Kong","institution_ids":["https://openalex.org/I14243506"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100398237","display_name":"Zixuan Wang","orcid":"https://orcid.org/0000-0001-5255-6500"},"institutions":[{"id":"https://openalex.org/I14243506","display_name":"Hong Kong Polytechnic University","ror":"https://ror.org/0030zas98","country_code":"HK","type":"education","lineage":["https://openalex.org/I14243506"]}],"countries":["HK"],"is_corresponding":false,"raw_author_name":"Zixuan Wang","raw_affiliation_strings":["The Hong Kong Polytechnic University,Department of Computing,Hong Kong"],"affiliations":[{"raw_affiliation_string":"The Hong Kong Polytechnic University,Department of Computing,Hong Kong","institution_ids":["https://openalex.org/I14243506"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5122063567","display_name":"Guyue Li","orcid":null},"institutions":[{"id":"https://openalex.org/I76569877","display_name":"Southeast University","ror":"https://ror.org/04ct4d772","country_code":"CN","type":"education","lineage":["https://openalex.org/I76569877"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Guyue Li","raw_affiliation_strings":["Southeast University,School of Cyber Science and Engineering,Nanjing,China"],"affiliations":[{"raw_affiliation_string":"Southeast University,School of Cyber Science and Engineering,Nanjing,China","institution_ids":["https://openalex.org/I76569877"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5129923074","display_name":"Bin Xiao","orcid":null},"institutions":[{"id":"https://openalex.org/I14243506","display_name":"Hong Kong Polytechnic University","ror":"https://ror.org/0030zas98","country_code":"HK","type":"education","lineage":["https://openalex.org/I14243506"]}],"countries":["HK"],"is_corresponding":false,"raw_author_name":"Bin Xiao","raw_affiliation_strings":["The Hong Kong Polytechnic University,Department of Computing,Hong Kong"],"affiliations":[{"raw_affiliation_string":"The Hong Kong Polytechnic University,Department of Computing,Hong Kong","institution_ids":["https://openalex.org/I14243506"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5100748981"],"corresponding_institution_ids":["https://openalex.org/I14243506"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.88124509,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"3073","last_page":"3078"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.8241000175476074,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.8241000175476074,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.11729999631643295,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.004399999976158142,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/intrusion-detection-system","display_name":"Intrusion detection system","score":0.6401000022888184},{"id":"https://openalex.org/keywords/software-deployment","display_name":"Software deployment","score":0.5397999882698059},{"id":"https://openalex.org/keywords/leverage","display_name":"Leverage (statistics)","score":0.5171999931335449},{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.47110000252723694},{"id":"https://openalex.org/keywords/overhead","display_name":"Overhead (engineering)","score":0.45649999380111694},{"id":"https://openalex.org/keywords/training","display_name":"Training (meteorology)","score":0.4108999967575073},{"id":"https://openalex.org/keywords/traffic-analysis","display_name":"Traffic analysis","score":0.3880000114440918},{"id":"https://openalex.org/keywords/alarm","display_name":"ALARM","score":0.3837999999523163}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7106999754905701},{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.6401000022888184},{"id":"https://openalex.org/C105339364","wikidata":"https://www.wikidata.org/wiki/Q2297740","display_name":"Software deployment","level":2,"score":0.5397999882698059},{"id":"https://openalex.org/C153083717","wikidata":"https://www.wikidata.org/wiki/Q6535263","display_name":"Leverage (statistics)","level":2,"score":0.5171999931335449},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.47110000252723694},{"id":"https://openalex.org/C2779960059","wikidata":"https://www.wikidata.org/wiki/Q7113681","display_name":"Overhead (engineering)","level":2,"score":0.45649999380111694},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4424999952316284},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.4214000105857849},{"id":"https://openalex.org/C2777211547","wikidata":"https://www.wikidata.org/wiki/Q17141490","display_name":"Training (meteorology)","level":2,"score":0.4108999967575073},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.38989999890327454},{"id":"https://openalex.org/C2781317605","wikidata":"https://www.wikidata.org/wiki/Q7832483","display_name":"Traffic analysis","level":2,"score":0.3880000114440918},{"id":"https://openalex.org/C2779119184","wikidata":"https://www.wikidata.org/wiki/Q294350","display_name":"ALARM","level":2,"score":0.3837999999523163},{"id":"https://openalex.org/C81860439","wikidata":"https://www.wikidata.org/wiki/Q251212","display_name":"Internet of Things","level":2,"score":0.38260000944137573},{"id":"https://openalex.org/C77052588","wikidata":"https://www.wikidata.org/wiki/Q644307","display_name":"Constant false alarm rate","level":2,"score":0.36230000853538513},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.34610000252723694},{"id":"https://openalex.org/C2776836416","wikidata":"https://www.wikidata.org/wiki/Q1364844","display_name":"False alarm","level":2,"score":0.3452000021934509},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.3050000071525574},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.290800005197525},{"id":"https://openalex.org/C2779304628","wikidata":"https://www.wikidata.org/wiki/Q3503480","display_name":"Face (sociological concept)","level":2,"score":0.2818000018596649},{"id":"https://openalex.org/C82876162","wikidata":"https://www.wikidata.org/wiki/Q17096504","display_name":"Latency (audio)","level":2,"score":0.28040000796318054},{"id":"https://openalex.org/C79403827","wikidata":"https://www.wikidata.org/wiki/Q3988","display_name":"Real-time computing","level":1,"score":0.2630000114440918},{"id":"https://openalex.org/C75684735","wikidata":"https://www.wikidata.org/wiki/Q858810","display_name":"Big data","level":2,"score":0.2614000141620636},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.26019999384880066},{"id":"https://openalex.org/C34585555","wikidata":"https://www.wikidata.org/wiki/Q1368723","display_name":"Learning curve","level":2,"score":0.25949999690055847},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.2567000091075897},{"id":"https://openalex.org/C2776650193","wikidata":"https://www.wikidata.org/wiki/Q264661","display_name":"Obstacle","level":2,"score":0.2549999952316284},{"id":"https://openalex.org/C65856478","wikidata":"https://www.wikidata.org/wiki/Q3991682","display_name":"Attack model","level":2,"score":0.2517000138759613}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/globecom59602.2025.11432529","is_oa":false,"landing_page_url":"https://doi.org/10.1109/globecom59602.2025.11432529","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"GLOBECOM 2025 - 2025 IEEE Global Communications Conference","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":8,"referenced_works":["https://openalex.org/W2296509296","https://openalex.org/W2991140181","https://openalex.org/W4295789113","https://openalex.org/W4308119167","https://openalex.org/W4385567149","https://openalex.org/W4385571011","https://openalex.org/W4408324654","https://openalex.org/W7133224126"],"related_works":[],"abstract_inverted_index":{"Artificial":[0],"intelligence":[1],"has":[2],"demonstrated":[3],"significant":[4],"potential":[5],"for":[6,66,117],"traffic":[7,114,145,173],"analysis":[8,115,174],"in":[9,187],"IoT":[10,67,118,213],"intrusion":[11,68,119],"detection":[12,60,120],"systems.":[13],"However,":[14],"existing":[15],"machine":[16],"learning":[17,43],"(ML)":[18],"solutions":[19],"struggle":[20],"with":[21,121,183],"high":[22,56],"false":[23],"alarm":[24],"rates":[25],"due":[26],"to":[27,74,142,202],"a":[28,85,133,139,167],"lack":[29],"of":[30,35,100],"malicious":[31,92],"data.":[32],"The":[33],"advantages":[34],"large":[36],"language":[37],"models":[38],"(LLMs),":[39],"particularly":[40],"their":[41],"few-shot":[42],"capabilities,":[44],"can":[45],"effectively":[46],"address":[47],"this":[48,105],"issue.":[49],"Nonetheless,":[50],"LLMs":[51],"face":[52],"challenges":[53],"such":[54],"as":[55],"computational":[57],"overhead":[58],"and":[59,112],"latency,":[61],"which":[62],"make":[63],"them":[64],"impractical":[65],"detection.":[69],"One":[70],"promising":[71],"solution":[72],"is":[73],"leverage":[75],"knowledge":[76,128],"distillation,":[77],"shrinking":[78],"the":[79,81,96,157,162,188],"LLM,":[80],"teacher":[82,163],"model,":[83,164],"into":[84],"smaller":[86],"student":[87,172],"model":[88,175],"that":[89,137,182],"requires":[90],"limited":[91],"examples":[93,186],"while":[94,196],"preserving":[95],"low":[97],"latency":[98],"characteristic":[99],"traditional":[101],"ML-based":[102],"models.":[103],"In":[104],"paper,":[106],"we":[107],"propose":[108],"DLM-IDS,":[109],"an":[110],"efficient":[111],"accurate":[113,171],"framework":[116],"small":[122,168],"training":[123,150,189],"datasets,":[124],"empowered":[125],"by":[126],"LLM":[127,141,158],"distillation.":[129],"Specifically,":[130],"DLM-IDS":[131,165,191],"introduces":[132],"chain-of-thought":[134],"(CoT)":[135],"mechanism":[136],"enables":[138],"pre-trained":[140],"interpret":[143],"network":[144],"patterns":[146],"without":[147],"requiring":[148],"additional":[149],"or":[151],"fine-tuning.":[152],"By":[153],"extracting":[154],"rationales":[155],"from":[156,200],"(around":[159,176],"200B":[160],"parameters),":[161],"constructs":[166],"yet":[169],"highly":[170],"200":[177],"million":[178],"parameters).":[179],"Experiments":[180],"show":[181],"only":[184],"800":[185],"dataset,":[190],"maintains":[192],"over":[193],"98%":[194],"AUC":[195],"reducing":[197],"inference":[198],"time":[199],"3.2s":[201],"0.037s":[203],"per":[204],"flow":[205],"detection,":[206],"enabling":[207],"practical":[208],"low-latency":[209],"deployment":[210],"on":[211],"resource-constrained":[212],"devices.":[214]},"counts_by_year":[],"updated_date":"2026-03-20T20:54:20.808490","created_date":"2026-03-20T00:00:00"}
