nonlinear attack classification

Designs and implements nonlinear classifiers and corresponding KAN network architectures that learn highly nonlinear decision boundaries to detect and distinguish attack classes from feature vectors or learned embeddings. These systems focus on handling imbalanced and low-frequency attack patterns by applying nonlinear mappings that complement upstream embeddings to improve separation and classification performance.

nonlinearattackclassification

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
-0.43
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$200K/year
Oct 01, 2026Oct 01, 2026

Recommended Survey Paper

Quick overview of the field
View more

Must-Read Papers

Most classic and influential ideas
View more

This work proposes a lightweight framework to address the high parameter count and inference latency of conventional intrusion detection models in edge and real-time monitoring scenarios. The approach introduces Kolmogorov–Arnold Networks (KANs) as teacher models to extract complex features and leverages decoupled knowledge distillation (DKD) to guide the training of extremely compact multilayer perceptron (MLP) student models. Evaluated on the WADI and SWaT datasets, the resulting student models contain only 2,522 and 1,622 parameters, respectively, while achieving F1-score improvements of 4.18% and 3.07%. These results demonstrate that the proposed method maintains high detection accuracy despite substantial model compression, confirming its efficiency and practicality in resource-constrained environments.

cyber-securityinference timeintrusion detection

Optimizing IoT Threat Detection with Kolmogorov-Arnold Networks (KANs)

Aug 07, 2025
NE
Natalia Emelianova
🏛️ Federal University of ABC (UFABC)

IoT systems face increasingly severe intrusion threats, yet existing detection models often fail to simultaneously achieve high accuracy and interpretability. This paper proposes a novel IoT intrusion detection framework based on Kolmogorov–Arnold Networks (KANs), which replace fixed nonlinear activation units with learnable, spline-based activation functions—thereby enhancing both representational capacity and structural interpretability. Evaluated on standard IoT benchmark datasets, KANs surpass traditional multilayer perceptrons (MLPs) in accuracy and F1-score, while matching the performance of strong tree-based baselines such as Random Forest and XGBoost. Crucially, KANs provide intrinsic, component-level functional visualizations—offering substantially greater transparency than black-box models. This work establishes a new paradigm for trustworthy IoT security analytics, unifying state-of-the-art detection performance with rigorous model interpretability.

Comparing KANs with traditional ML models for securityEnhancing IoT threat detection using KANsImproving interpretability in IoT intrusion detection systems

Contrastive-KAN: A Semi-Supervised Intrusion Detection Framework for Cybersecurity with scarce Labeled Data

Jul 14, 2025
MA
Mohammad Alikhani
🏛️ K.N. Toosi University of Technology

To address the challenges of scarce labeled data, stringent real-time requirements, and insufficient model interpretability in IoT/IIoT intrusion detection, this paper proposes a real-time semi-supervised contrastive learning framework. Methodologically, it replaces conventional MLPs with Kolmogorov–Arnold Networks (KANs) featuring learnable activation functions to capture complex feature interactions; introduces a lightweight contrastive learning mechanism enabling fine-grained multi-class attack identification under extremely low labeling ratios (1.28%–8%); and integrates feature visualization and rule extraction modules to enhance model transparency and interpretability. Extensive experiments on UNSW-NB15, BoT-IoT, and Gas Pipeline datasets demonstrate that the proposed method significantly outperforms existing semi-supervised contrastive learning approaches in detection accuracy, robustness, and inference efficiency—making it particularly suitable for safety-critical IoT/IIoT applications.

Addressing data imbalance in cybersecurity machine learningDetecting cyber intrusions with scarce labeled dataEnhancing real-time attack detection in critical infrastructure

Strategic Classification with Non-Linear Classifiers

May 29, 2025
BT
Benyamin Trachtenberg
🏛️ Technion - Israel Institute of Technology

This paper addresses strategic feature manipulation—where users incur costs to alter input features to improve classifier predictions—in strategic classification settings. We systematically investigate the learning dynamics and performance limits of nonlinear classifiers (e.g., neural networks) under such strategic behavior. Using game-theoretic modeling, decision boundary analysis, theoretical derivation for nonlinear models, and empirical evaluation, we establish that even universal approximators—such as deep neural networks—suffer significant expressive degradation under strategic manipulation: their classical universal approximation property fails in strategic environments. This reveals a fundamental tension between model capacity and strategic robustness in strategic machine learning. Crucially, we derive the first rigorous theoretical lower bound on the strategic robustness of nonlinear classifiers, thereby closing a critical theoretical gap beyond the linear-regime assumptions prevalent in prior work.

Explores strategic behavior under non-linear classifiersInvestigates impact on decision boundaries and model complexityShows universal approximators fail in strategic environments

This study addresses the limitations of conventional threat detection models in IoT networks—namely, excessive parameter redundancy and poor generalization—by introducing Kolmogorov-Arnold Networks (KAN) to the cybersecurity domain for the first time. The authors propose a novel KAN-LSTM hybrid architecture that replaces traditional linear weights with learnable spline-based activation functions to dynamically capture spatiotemporal patterns in network traffic. Furthermore, they construct a large-scale, unbiased, multi-source fused benchmark dataset specifically designed for IoT threat detection. Experimental results demonstrate that the proposed model achieves superior detection accuracy compared to state-of-the-art deep learning approaches across multiple datasets—including UNSW-NB15, NSL-KDD, CICIDS2017, and a newly curated hybrid dataset—while significantly reducing the number of model parameters.

Cyber SecurityIoT NetworksKolmogorov-Arnold Networks

Latest Papers

What's happening recently
View more

This paper addresses the multi-class detection problem of five network intrusion types—Normal, DoS, Probe, R2L, and U2R—in the NSL-KDD dataset. We propose an efficient tree-ensemble-based detection framework, incorporating systematic feature analysis and standardized preprocessing (including categorical encoding and min-max normalization). Four supervised learning models—logistic regression, decision trees, random forest, and XGBoost—are comparatively evaluated. Experimental results demonstrate that random forest and XGBoost achieve superior performance, attaining ≈99% overall accuracy, high F1-scores, and strong AUC values—establishing a new performance benchmark for traditional network intrusion detection systems (NIDS). Furthermore, the study identifies persistent recognition bottlenecks for rare attack classes (R2L and U2R), revealing inherent challenges in long-tailed class imbalance. We propose targeted optimization strategies for minority-class detection, thereby contributing both methodological rigor and practical guidance for real-world NIDS deployment.

Addresses challenges in detecting rare attack types effectively.Compares performance on multiclass NSL-KDD dataset categories.Evaluates machine learning models for network intrusion detection.

This work addresses the challenges of detecting advanced persistent threats (APTs) in wireless Internet of Things (IoT) environments, where extreme class imbalance and model opacity hinder effective security monitoring. To this end, the study introduces a neuro-symbolic system tailored for IoT scenarios, integrating an optimized BERT architecture with temporal feature encoding to preserve contextual dependencies. The framework further incorporates Logic Tensor Networks (LTNs) for interpretable reasoning, focal loss to mitigate class imbalance, hierarchical classification, and an adaptive sampling strategy. Evaluated on the SCVIC-APT2021 dataset, the proposed method achieves a binary-class F1 score of 95.27% with a false positive rate of only 0.14%, and a macro F1 score of 76.75% for multi-class attack detection, demonstrating superior performance and interpretability compared to existing approaches.

Advanced Persistent ThreatClass ImbalanceExplainable AI

This work addresses the challenge of balancing expressive power and computational efficiency in nonlinear models by proposing and open-sourcing “tnkm,” a JAX-based Python library that unifies nonlinear feature mappings with low-rank tensor network architectures. The framework offers the first scalable and modular implementation of tensor network kernel machines, enabling flexible composition of feature maps, network topologies, and optimization strategies—including alternating least squares and gradient-based methods. Experimental results demonstrate that the approach achieves competitive predictive accuracy on multiple nonlinear benchmark tasks while substantially reducing model parameter count and improving training efficiency. By providing a reproducible and high-performance platform, this work advances research in efficient nonlinear modeling.

kernel machinesmachine learningnonlinear system identification

Attack-Specialized Deep Learning with Ensemble Fusion for Network Anomaly Detection

Oct 14, 2025
ND
Nisith Dissanayake
🏛️ University of Moratuwa

To address the degraded detection accuracy in network intrusion detection caused by class imbalance—particularly severe false negatives for rare attacks such as U2R—this paper proposes a collaborative “specialized-model + ensemble meta-classifier” framework. Methodologically, it constructs dedicated deep neural network branches for each attack class to enable fine-grained feature learning; outputs from these branches are then fused via a random forest meta-classifier to jointly optimize class-specific modeling and global decision-making. Experiments on the NSL-KDD dataset demonstrate substantial improvements: recall and F1-score for rare classes (e.g., U2R) reach 98.7% F1, overall detection rate achieves 99.9%, and false positive rate remains below 0.3%, outperforming state-of-the-art IDS approaches. The core contribution lies in the synergistic integration of an attack-class-driven multi-branch deep architecture with an interpretable ensemble strategy.

Detecting diverse intrusion types in imbalanced network datasetsImproving accuracy for both frequent and rare cyberattacksReducing false negatives in minority attack classes

Cyberattack Detection in Critical Infrastructure and Supply Chains

Oct 21, 2025
SK
Smita Khapre
🏛️ Department of Engineering and Applied Science

Addressing two critical challenges in Industry 4.0—difficult detection of zero-day attacks and extreme class imbalance in network traffic data (minority-class prevalence as low as 0.000004%)—this paper proposes a lightweight intrusion detection method integrating an enhanced SMOTE-ENN data augmentation technique with a deep neural network (DNN). Specifically, the Edited Nearest Neighbor (ENN) rule is innovatively embedded into the SMOTE oversampling pipeline to improve the quality and validity of synthetic minority samples. Additionally, a DNN classifier is designed to accommodate highly skewed distributions, effectively mitigating overfitting. Evaluated on the original imbalanced test set, the method achieves substantial gains in minority-class recall and F1-score while maintaining superior overall accuracy compared to state-of-the-art baselines. It also demonstrates enhanced generalization capability. This end-to-end solution offers both efficiency and robustness for zero-day attack detection in industrial cyber-physical systems.

Addressing extreme data imbalance in network flow datasets for accurate detectionDetecting zero-day cyberattacks in critical infrastructure using intelligent IDSOvercoming overfitting issues in neural network models with imbalanced test data

Hot Scholars

SM

Sridhar Mahadevan

Director, Adobe Research & Professor, University of Massachusetts, Amherst
Artificial general intelligencemachine learning
GS

Giuseppe Sansonetti

Roma Tre University
User ModelingRecommender SystemsCase-Based ReasoningComputer Vision
RC

Rodrigo Clemente Thom de Souza

Professor of Artificial Intelligence at Federal University of Paraná (UFPR), Brazil
Deep LearningComputer VisionMetaheuristicsFeature Selection
JT

Joaquín Torres-Sospedra

Universitat de València (formerly at University of Minho, UBIK GS and Universitat Jaume I)
Indoor PositioningIndoor LocalizationIndoor NavigationSignal Processing