Score
Designs and implements nonlinear classifiers and corresponding KAN network architectures that learn highly nonlinear decision boundaries to detect and distinguish attack classes from feature vectors or learned embeddings. These systems focus on handling imbalanced and low-frequency attack patterns by applying nonlinear mappings that complement upstream embeddings to improve separation and classification performance.
This work addresses the poor interpretability and low parameter efficiency of traditional multilayer perceptrons (MLPs) in nonlinear modeling. Methodologically, grounded in the Kolmogorov–Arnold representation theorem, it replaces fixed activation functions with learnable piecewise spline functions, introducing a novel “learnable activations-as-weights” paradigm, and develops a symbol-numerical co-optimization framework with differentiable grid refinement. Contributions include: (i) the first comprehensive survey of Kolmogorov–Arnold Networks (KANs); (ii) theoretical and empirical identification of their structural advantages in function approximation, intrinsic interpretability, and parameter efficiency; and (iii) experimental validation showing KANs significantly outperform MLPs in fitting accuracy, generalization, and few-shot learning. To foster reproducibility and adoption, we publicly release a unified training framework, advancing the field of interpretable neural modeling.
This work proposes a lightweight framework to address the high parameter count and inference latency of conventional intrusion detection models in edge and real-time monitoring scenarios. The approach introduces Kolmogorov–Arnold Networks (KANs) as teacher models to extract complex features and leverages decoupled knowledge distillation (DKD) to guide the training of extremely compact multilayer perceptron (MLP) student models. Evaluated on the WADI and SWaT datasets, the resulting student models contain only 2,522 and 1,622 parameters, respectively, while achieving F1-score improvements of 4.18% and 3.07%. These results demonstrate that the proposed method maintains high detection accuracy despite substantial model compression, confirming its efficiency and practicality in resource-constrained environments.
IoT systems face increasingly severe intrusion threats, yet existing detection models often fail to simultaneously achieve high accuracy and interpretability. This paper proposes a novel IoT intrusion detection framework based on Kolmogorov–Arnold Networks (KANs), which replace fixed nonlinear activation units with learnable, spline-based activation functions—thereby enhancing both representational capacity and structural interpretability. Evaluated on standard IoT benchmark datasets, KANs surpass traditional multilayer perceptrons (MLPs) in accuracy and F1-score, while matching the performance of strong tree-based baselines such as Random Forest and XGBoost. Crucially, KANs provide intrinsic, component-level functional visualizations—offering substantially greater transparency than black-box models. This work establishes a new paradigm for trustworthy IoT security analytics, unifying state-of-the-art detection performance with rigorous model interpretability.
To address the challenges of scarce labeled data, stringent real-time requirements, and insufficient model interpretability in IoT/IIoT intrusion detection, this paper proposes a real-time semi-supervised contrastive learning framework. Methodologically, it replaces conventional MLPs with Kolmogorov–Arnold Networks (KANs) featuring learnable activation functions to capture complex feature interactions; introduces a lightweight contrastive learning mechanism enabling fine-grained multi-class attack identification under extremely low labeling ratios (1.28%–8%); and integrates feature visualization and rule extraction modules to enhance model transparency and interpretability. Extensive experiments on UNSW-NB15, BoT-IoT, and Gas Pipeline datasets demonstrate that the proposed method significantly outperforms existing semi-supervised contrastive learning approaches in detection accuracy, robustness, and inference efficiency—making it particularly suitable for safety-critical IoT/IIoT applications.
This paper addresses strategic feature manipulation—where users incur costs to alter input features to improve classifier predictions—in strategic classification settings. We systematically investigate the learning dynamics and performance limits of nonlinear classifiers (e.g., neural networks) under such strategic behavior. Using game-theoretic modeling, decision boundary analysis, theoretical derivation for nonlinear models, and empirical evaluation, we establish that even universal approximators—such as deep neural networks—suffer significant expressive degradation under strategic manipulation: their classical universal approximation property fails in strategic environments. This reveals a fundamental tension between model capacity and strategic robustness in strategic machine learning. Crucially, we derive the first rigorous theoretical lower bound on the strategic robustness of nonlinear classifiers, thereby closing a critical theoretical gap beyond the linear-regime assumptions prevalent in prior work.
This study addresses the limitations of conventional threat detection models in IoT networks—namely, excessive parameter redundancy and poor generalization—by introducing Kolmogorov-Arnold Networks (KAN) to the cybersecurity domain for the first time. The authors propose a novel KAN-LSTM hybrid architecture that replaces traditional linear weights with learnable spline-based activation functions to dynamically capture spatiotemporal patterns in network traffic. Furthermore, they construct a large-scale, unbiased, multi-source fused benchmark dataset specifically designed for IoT threat detection. Experimental results demonstrate that the proposed model achieves superior detection accuracy compared to state-of-the-art deep learning approaches across multiple datasets—including UNSW-NB15, NSL-KDD, CICIDS2017, and a newly curated hybrid dataset—while significantly reducing the number of model parameters.
This paper addresses the multi-class detection problem of five network intrusion types—Normal, DoS, Probe, R2L, and U2R—in the NSL-KDD dataset. We propose an efficient tree-ensemble-based detection framework, incorporating systematic feature analysis and standardized preprocessing (including categorical encoding and min-max normalization). Four supervised learning models—logistic regression, decision trees, random forest, and XGBoost—are comparatively evaluated. Experimental results demonstrate that random forest and XGBoost achieve superior performance, attaining ≈99% overall accuracy, high F1-scores, and strong AUC values—establishing a new performance benchmark for traditional network intrusion detection systems (NIDS). Furthermore, the study identifies persistent recognition bottlenecks for rare attack classes (R2L and U2R), revealing inherent challenges in long-tailed class imbalance. We propose targeted optimization strategies for minority-class detection, thereby contributing both methodological rigor and practical guidance for real-world NIDS deployment.
This work addresses the challenges of detecting advanced persistent threats (APTs) in wireless Internet of Things (IoT) environments, where extreme class imbalance and model opacity hinder effective security monitoring. To this end, the study introduces a neuro-symbolic system tailored for IoT scenarios, integrating an optimized BERT architecture with temporal feature encoding to preserve contextual dependencies. The framework further incorporates Logic Tensor Networks (LTNs) for interpretable reasoning, focal loss to mitigate class imbalance, hierarchical classification, and an adaptive sampling strategy. Evaluated on the SCVIC-APT2021 dataset, the proposed method achieves a binary-class F1 score of 95.27% with a false positive rate of only 0.14%, and a macro F1 score of 76.75% for multi-class attack detection, demonstrating superior performance and interpretability compared to existing approaches.
This work addresses the challenge of balancing expressive power and computational efficiency in nonlinear models by proposing and open-sourcing “tnkm,” a JAX-based Python library that unifies nonlinear feature mappings with low-rank tensor network architectures. The framework offers the first scalable and modular implementation of tensor network kernel machines, enabling flexible composition of feature maps, network topologies, and optimization strategies—including alternating least squares and gradient-based methods. Experimental results demonstrate that the approach achieves competitive predictive accuracy on multiple nonlinear benchmark tasks while substantially reducing model parameter count and improving training efficiency. By providing a reproducible and high-performance platform, this work advances research in efficient nonlinear modeling.
To address the degraded detection accuracy in network intrusion detection caused by class imbalance—particularly severe false negatives for rare attacks such as U2R—this paper proposes a collaborative “specialized-model + ensemble meta-classifier” framework. Methodologically, it constructs dedicated deep neural network branches for each attack class to enable fine-grained feature learning; outputs from these branches are then fused via a random forest meta-classifier to jointly optimize class-specific modeling and global decision-making. Experiments on the NSL-KDD dataset demonstrate substantial improvements: recall and F1-score for rare classes (e.g., U2R) reach 98.7% F1, overall detection rate achieves 99.9%, and false positive rate remains below 0.3%, outperforming state-of-the-art IDS approaches. The core contribution lies in the synergistic integration of an attack-class-driven multi-branch deep architecture with an interpretable ensemble strategy.
Addressing two critical challenges in Industry 4.0—difficult detection of zero-day attacks and extreme class imbalance in network traffic data (minority-class prevalence as low as 0.000004%)—this paper proposes a lightweight intrusion detection method integrating an enhanced SMOTE-ENN data augmentation technique with a deep neural network (DNN). Specifically, the Edited Nearest Neighbor (ENN) rule is innovatively embedded into the SMOTE oversampling pipeline to improve the quality and validity of synthetic minority samples. Additionally, a DNN classifier is designed to accommodate highly skewed distributions, effectively mitigating overfitting. Evaluated on the original imbalanced test set, the method achieves substantial gains in minority-class recall and F1-score while maintaining superior overall accuracy compared to state-of-the-art baselines. It also demonstrates enhanced generalization capability. This end-to-end solution offers both efficiency and robustness for zero-day attack detection in industrial cyber-physical systems.