{"id":"https://openalex.org/W4416924768","doi":"https://doi.org/10.1109/wimob66857.2025.11257572","title":"Lightweight Fine-Tuning of LLMS for Explainable Intrusion Detection in SDN","display_name":"Lightweight Fine-Tuning of LLMS for Explainable Intrusion Detection in SDN","publication_year":2025,"publication_date":"2025-10-20","ids":{"openalex":"https://openalex.org/W4416924768","doi":"https://doi.org/10.1109/wimob66857.2025.11257572"},"language":null,"primary_location":{"id":"doi:10.1109/wimob66857.2025.11257572","is_oa":false,"landing_page_url":"https://doi.org/10.1109/wimob66857.2025.11257572","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 21th International Conference on Wireless and Mobile Computing, Networking and Communications (WiMob)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5120678667","display_name":"Suvajit Lodh","orcid":null},"institutions":[{"id":"https://openalex.org/I104546213","display_name":"National College of Ireland","ror":"https://ror.org/02qzs9336","country_code":"IE","type":"education","lineage":["https://openalex.org/I104546213"]}],"countries":["IE"],"is_corresponding":true,"raw_author_name":"Suvajit Lodh","raw_affiliation_strings":["School of Computing, National College of Ireland,Dublin,Ireland"],"affiliations":[{"raw_affiliation_string":"School of Computing, National College of Ireland,Dublin,Ireland","institution_ids":["https://openalex.org/I104546213"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5005612783","display_name":"Islam Obaidat","orcid":"https://orcid.org/0000-0002-2258-0785"},"institutions":[{"id":"https://openalex.org/I35777872","display_name":"North Carolina Agricultural and Technical State University","ror":"https://ror.org/02aze4h65","country_code":"US","type":"education","lineage":["https://openalex.org/I35777872"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Islam Obaidat","raw_affiliation_strings":["North Carolina A&#x0026;T State University,Department of CST,USA"],"affiliations":[{"raw_affiliation_string":"North Carolina A&#x0026;T State University,Department of CST,USA","institution_ids":["https://openalex.org/I35777872"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5058941449","display_name":"Furqan Rustam","orcid":"https://orcid.org/0000-0001-8403-1047"},"institutions":[{"id":"https://openalex.org/I104546213","display_name":"National College of Ireland","ror":"https://ror.org/02qzs9336","country_code":"IE","type":"education","lineage":["https://openalex.org/I104546213"]}],"countries":["IE"],"is_corresponding":false,"raw_author_name":"Furqan Rustam","raw_affiliation_strings":["School of Computing, National College of Ireland,Dublin,Ireland"],"affiliations":[{"raw_affiliation_string":"School of Computing, National College of Ireland,Dublin,Ireland","institution_ids":["https://openalex.org/I104546213"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5022546955","display_name":"Anca Delia Jurcut","orcid":"https://orcid.org/0000-0002-2705-1823"},"institutions":[{"id":"https://openalex.org/I100930933","display_name":"University College Dublin","ror":"https://ror.org/05m7pjf47","country_code":"IE","type":"education","lineage":["https://openalex.org/I100930933"]}],"countries":["IE"],"is_corresponding":false,"raw_author_name":"Anca Delia Jurcut","raw_affiliation_strings":["School of Computer Science, University College Dublin,Ireland"],"affiliations":[{"raw_affiliation_string":"School of Computer Science, University College Dublin,Ireland","institution_ids":["https://openalex.org/I100930933"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5120678667"],"corresponding_institution_ids":["https://openalex.org/I104546213"],"apc_list":null,"apc_paid":null,"fwci":5.4504,"has_fulltext":false,"cited_by_count":4,"citation_normalized_percentile":{"value":0.96100758,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":91,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"6"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.3174000084400177,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.3174000084400177,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10714","display_name":"Software-Defined Networks and 5G","score":0.2248000055551529,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.1200999990105629,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/interpretability","display_name":"Interpretability","score":0.7849000096321106},{"id":"https://openalex.org/keywords/intrusion-detection-system","display_name":"Intrusion detection system","score":0.6557000279426575},{"id":"https://openalex.org/keywords/intrusion-prevention-system","display_name":"Intrusion prevention system","score":0.4474000036716461},{"id":"https://openalex.org/keywords/adaptation","display_name":"Adaptation (eye)","score":0.4278999865055084},{"id":"https://openalex.org/keywords/quantization","display_name":"Quantization (signal processing)","score":0.40139999985694885},{"id":"https://openalex.org/keywords/intrusion","display_name":"Intrusion","score":0.38600000739097595},{"id":"https://openalex.org/keywords/network-security","display_name":"Network security","score":0.3774000108242035}],"concepts":[{"id":"https://openalex.org/C2781067378","wikidata":"https://www.wikidata.org/wiki/Q17027399","display_name":"Interpretability","level":2,"score":0.7849000096321106},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.770799994468689},{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.6557000279426575},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5185999870300293},{"id":"https://openalex.org/C27061796","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion prevention system","level":3,"score":0.4474000036716461},{"id":"https://openalex.org/C139807058","wikidata":"https://www.wikidata.org/wiki/Q352374","display_name":"Adaptation (eye)","level":2,"score":0.4278999865055084},{"id":"https://openalex.org/C28855332","wikidata":"https://www.wikidata.org/wiki/Q198099","display_name":"Quantization (signal processing)","level":2,"score":0.40139999985694885},{"id":"https://openalex.org/C158251709","wikidata":"https://www.wikidata.org/wiki/Q354025","display_name":"Intrusion","level":2,"score":0.38600000739097595},{"id":"https://openalex.org/C182590292","wikidata":"https://www.wikidata.org/wiki/Q989632","display_name":"Network security","level":2,"score":0.3774000108242035},{"id":"https://openalex.org/C123657996","wikidata":"https://www.wikidata.org/wiki/Q12271","display_name":"Architecture","level":2,"score":0.37139999866485596},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.33090001344680786},{"id":"https://openalex.org/C2777212361","wikidata":"https://www.wikidata.org/wiki/Q5127848","display_name":"Class (philosophy)","level":2,"score":0.32850000262260437},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.2973000109195709},{"id":"https://openalex.org/C195324797","wikidata":"https://www.wikidata.org/wiki/Q33742","display_name":"Natural language","level":2,"score":0.29179999232292175},{"id":"https://openalex.org/C2775936607","wikidata":"https://www.wikidata.org/wiki/Q466845","display_name":"Tracking (education)","level":2,"score":0.29120001196861267},{"id":"https://openalex.org/C48372109","wikidata":"https://www.wikidata.org/wiki/Q3913","display_name":"Binary number","level":2,"score":0.2799000144004822},{"id":"https://openalex.org/C186370098","wikidata":"https://www.wikidata.org/wiki/Q442787","display_name":"Energy (signal processing)","level":2,"score":0.27320000529289246},{"id":"https://openalex.org/C2522767166","wikidata":"https://www.wikidata.org/wiki/Q2374463","display_name":"Data science","level":1,"score":0.2703000009059906},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.26989999413490295}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/wimob66857.2025.11257572","is_oa":false,"landing_page_url":"https://doi.org/10.1109/wimob66857.2025.11257572","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 21th International Conference on Wireless and Mobile Computing, Networking and Communications (WiMob)","raw_type":"proceedings-article"},{"id":"pmh:oai:norma.ncirl.ie:9170","is_oa":false,"landing_page_url":null,"pdf_url":null,"source":{"id":"https://openalex.org/S7407055118","display_name":"NORMA","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"acceptedVersion","is_accepted":true,"is_published":false,"raw_source_name":null,"raw_type":"PeerReviewed"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":23,"referenced_works":["https://openalex.org/W3084346886","https://openalex.org/W3185746581","https://openalex.org/W4323966580","https://openalex.org/W4388573952","https://openalex.org/W4391094158","https://openalex.org/W4394975949","https://openalex.org/W4395471110","https://openalex.org/W4404704266","https://openalex.org/W4404739647","https://openalex.org/W4406265325","https://openalex.org/W4406418102","https://openalex.org/W4406882703","https://openalex.org/W4407070057","https://openalex.org/W4407639385","https://openalex.org/W4408324654","https://openalex.org/W4410359337","https://openalex.org/W4410857897","https://openalex.org/W4411183121","https://openalex.org/W4411269989","https://openalex.org/W4411639796","https://openalex.org/W4411948870","https://openalex.org/W4412192300","https://openalex.org/W4416470949"],"related_works":[],"abstract_inverted_index":{"Cybersecurity":[0],"concerns":[1],"are":[2,80],"rising":[3],"with":[4,103,120,144,155],"the":[5,41,117,123,129,145,156,168],"rapid":[6],"adoption":[7],"of":[8,43,89,151,170],"technology":[9],"as":[10],"cybercriminals":[11],"grow":[12],"more":[13],"active.":[14],"Protecting":[15],"complex":[16],"networks":[17],"like":[18],"Software-Defined":[19],"Networking":[20],"(SDN)":[21],"is":[22],"increasingly":[23],"challenging":[24],"because":[25],"its":[26],"centralized":[27],"architecture":[28],"introduces":[29],"vulnerabilities":[30],"that":[31,97],"traditional":[32],"security":[33],"systems":[34],"struggle":[35],"to":[36],"handle.":[37],"This":[38],"paper":[39],"investigates":[40],"application":[42],"large":[44],"language":[45,84],"models":[46,99],"(LLMs)":[47],"for":[48,86,135,163],"intrusion":[49],"detection":[50],"in":[51,174],"SDN":[52],"environments.":[53],"Our":[54,132],"proposed":[55,133],"approach":[56],"fine-tunes":[57],"three":[58],"LLMs,":[59],"GPT_NEO,":[60],"Phi-2,":[61],"and":[62,73,91,105,126,137],"Llama2-7b,":[63],"through":[64],"Quantized":[65],"Low-Rank":[66],"Adaptation":[67],"(QLoRA),":[68],"enabling":[69],"efficient":[70],"4-bit":[71],"quantization":[72],"reduced":[74],"memory":[75],"usage.":[76],"Structured":[77],"network":[78],"features":[79],"transformed":[81],"into":[82],"natural":[83],"prompts":[85],"binary":[87],"classification":[88],"benign":[90],"malicious":[92],"traffic.":[93],"Experimental":[94],"results":[95],"show":[96],"all":[98],"achieve":[100],"high":[101,108],"accuracy,":[102],"Llama2-7b":[104],"Phi-2":[106,127,136],"reaching":[107],"scores":[109],"across":[110],"multiple":[111],"data":[112],"scales.":[113],"CodeCarbon":[114],"tracking":[115],"highlights":[116],"environmental":[118],"trade-offs,":[119],"Llama27b":[121],"consuming":[122],"most":[124,130],"energy":[125],"being":[128],"efficient.":[131],"framework":[134],"GPT_NEO":[138],"achieves":[139],"a":[140],"1.00":[141],"accuracy":[142],"score":[143],"lowest":[146],"<tex":[147],"xmlns:mml=\"http://www.w3.org/1998/Math/MathML\"":[148],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">$\\text{CO}_{2}$</tex>":[149],"emission":[150],"0.173":[152],"when":[153],"compared":[154],"baselines.":[157],"Further,":[158],"we":[159],"explore":[160],"explainability":[161],"challenges":[162],"our":[164],"LLM":[165],"models,":[166],"noting":[167],"limitations":[169],"token-level":[171],"interpretability":[172],"tools":[173],"handling":[175],"dense":[176],"textual":[177],"embeddings.":[178]},"counts_by_year":[{"year":2026,"cited_by_count":3},{"year":2025,"cited_by_count":1}],"updated_date":"2026-04-22T08:38:42.863108","created_date":"2025-12-02T00:00:00"}
