As the number of connected Internet of Things (IoT) devices continues to grow, securing these systems against cyber threats remains a pressing challenge, especially within environments constrained by limited computational and energy resources. This article presents an edge-centric intrusion detection system (IDS) framework that seamlessly integrates lightweight machine learning (ML)-based IDS models with pretrained large language models (LLMs) to enhance detection accuracy, semantic interpretability, and operational efficiency at the network edge. The system evaluates six ML-based IDS models: decision tree (DT), $K$ -nearest neighbor (KNN), random forest (RF), convolutional neural network (CNN), long short-term memory (LSTM), and a hybrid model of CNN and LSTM, on low-power edge gateways, achieving accuracy up to 98% under real-world cyberattacks. Furthermore, for anomaly detection, the system transmits a compact, secure telemetry snapshot (e.g., CPU usage, memory usage, latency, and energy consumption) via low-bandwidth application programming interface (API) calls to LLMs, including GPT-4-turbo, DeepSeek V2, and LLaMA 3.5. These models employ zero-shot, few-shot, and chain-of-thought (CoT) reasoning to deliver human-readable threat analyses and actionable mitigation recommendations. Extensive evaluations across diverse attacks such as denial of service (DoS), distributed denial of service (DDoS), brute force, and port scanning, demonstrate the system’s ability to enhance interpretability while maintaining low latency (<1.5 s), minimal bandwidth usage (<1.2 kB per prompt), and energy efficiency (<75 J), establishing it as a practical and scalable IDS solution for the edge gateway.
Paper
References (65)
Scroll for more · 38 remaining