DKD-KAN: A Lightweight knowledge-distilled KAN intrusion detection framework, based on MLP and KAN

📅 2026-03-03
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This work proposes a lightweight framework to address the high parameter count and inference latency of conventional intrusion detection models in edge and real-time monitoring scenarios. The approach introduces Kolmogorov–Arnold Networks (KANs) as teacher models to extract complex features and leverages decoupled knowledge distillation (DKD) to guide the training of extremely compact multilayer perceptron (MLP) student models. Evaluated on the WADI and SWaT datasets, the resulting student models contain only 2,522 and 1,622 parameters, respectively, while achieving F1-score improvements of 4.18% and 3.07%. These results demonstrate that the proposed method maintains high detection accuracy despite substantial model compression, confirming its efficiency and practicality in resource-constrained environments.

Technology Category

Machine Learning: Learning on the Edge & Model CompressionData Mining & Knowledge Management: Anomaly/Outlier DetectionComputer Vision: Generative Adversarial Networks (GANs) for Vision

Application Category

Systems and Infrastructure for Web, Mobile and WoT: Applied ML and AI for Web-based mobile applicationsGraph Algorithms and Modeling for the Web: Graph neural networks and deep learning approaches for Web-related graphsWeb Mining and Content Analysis: Large pretrained models with web data
📝 Abstract
Cyber-security systems often operate in resource-constrained environments, such as edge environments and real-time monitoring systems, where model size and inference time are crucial. A light-weight intrusion detection framework is proposed that utilizes the Kolmogorov-Arnold Network (KAN) to capture complex features in the data, with the efficiency of decoupled knowledge distillation (DKD) training approach. A high-capacity KAN network is first trained to detect attacks performed on the test bed. This model then serves as a teacher to guide a much smaller multilayer perceptron (MLP) student model via DKD. The resulting DKD-MLP model contains only 2,522 and 1,622 parameters for WADI and SWaT datasets, which are significantly smaller than the number of parameters of the KAN teacher model. This is highly appropriate for deployment in resource-constrained devices with limited computational resources. Despite its low size, the student model maintains a high performance. Our approach demonstrate the practicality of using KAN as a knowledge-rich teacher to train much smaller student models, without considerable drop in accuracy in intrusion detection frameworks. We have validated our approach on two publicly available datasets. We report F1-score improvements of 4.18% on WADI and 3.07% on SWaT when using the DKD-MLP model, compared to the bare student model. The implementation of this paper is available on our GitHub repository.
Problem

Research questions and friction points this paper is trying to address.

intrusion detection
resource-constrained environments
model size
inference time
cyber-security
Innovation

Methods, ideas, or system contributions that make the work stand out.

Kolmogorov-Arnold Network
Knowledge Distillation
Lightweight Intrusion Detection
Decoupled Knowledge Distillation
Edge Security
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
M
Mohammad Alikhani
Faculty of Electrical Engineering, K.N. Toosi University of Technology