DOI: https://doi.org/10.1007/s44397-026-00047-z
تاريخ النشر: 2026-03-05
المؤلف: Pawan Kumar Badhan
الموضوع الرئيسي: أمن الشبكات وكشف التسلل
نظرة عامة
تقدم هذه البحث إطار عمل خفيف الوزن يعتمد على الذكاء العصبي الرمزي للكشف عن التسلل في الوقت الحقيقي في بيئات إنترنت الأشياء الصناعية (IIoT)، مع معالجة تحديات الدقة، وقابلية التفسير، والكفاءة الحسابية تحت قيود الموارد الصارمة. يدمج النموذج المقترح التعلم العصبي الخفيف مع الاستدلال القائم على القواعد الرمزية ويستخدم تقنيات استخراج المعرفة لتحسين الأداء للنشر على الحافة. تم تقييمه على مجموعة بيانات Edge-IIoTset، التي تشمل 205,500 حالة تدفق شبكة مصنفة من مصنع ذكي، وقد حقق الإطار دقة مثيرة للإعجاب بلغت 94.3% ودرجة F1 متوسطة بلغت 93.5%. ومن الجدير بالذكر أنه أظهر تقليصًا بنسبة 37% في استخدام الذاكرة و54% في زمن الاستدلال مقارنةً بالنماذج التقليدية للتعلم العميق.
تستخدم عملية اختيار الميزات في الإطار تحليل الصلة القائم على المعلومات المتبادلة مع تضمين الميزات الرمزية، مما يسمح بالاختيار الفعال لأنواع ميزات متنوعة مع تقليل التكرار. يضمن دمج الدمج العصبي الرمزي الموزون التكيف مع أنماط المرور المتطورة ويعزز قابلية التفسير من خلال مسارات القرار الواضحة. تؤكد تحليل القوة أيضًا موثوقية النموذج ضد سيناريوهات الهجوم غير المرئية والهجينة، حيث حقق درجة F1 متوسطة بلغت 91.7%. يرسخ هذا العمل الإطار العصبي الرمزي كحل قابل للتوسع وقابل للتفسير لأمان حافة إنترنت الأشياء، مما يمهد الطريق للبحوث المستقبلية في تعلم القواعد الرمزية التكيفية والتعميم عبر الأجهزة في الشبكات المتنوعة لإنترنت الأشياء.
مقدمة
تسلط مقدمة هذه الورقة البحثية الضوء على الدور المحوري لإنترنت الأشياء (IoT) في البنية التحتية الرقمية الحديثة، مما يسهل الأتمتة واتخاذ القرارات الذكية عبر مختلف القطاعات. مع توسع شبكات إنترنت الأشياء، تنتج كميات هائلة من البيانات المتنوعة والحساسة زمنياً التي تتطلب معالجة تحت قيود صارمة عند حافة الشبكة. وقد أدى ذلك إلى زيادة الطلب على نماذج التعلم الذكي، التكيفية، والقابلة للتفسير، خاصة من خلال التقدم في الذكاء الاصطناعي العصبي الرمزي، الذي يجمع بين قابلية التكيف للشبكات العصبية والشفافية المنطقية للاستدلال الرمزي. تعتبر مثل هذه الأطر الهجينة مفيدة بشكل خاص في نظم المدن الذكية وأمن المعلومات، حيث تعزز من اتخاذ القرارات وقدرات الكشف عن التسلل في الوقت الحقيقي.
تحدد الورقة فجوة بحثية كبيرة في دمج الأساليب الرمزية والعصبية ضمن هياكل خفيفة الوزن مناسبة لبيئات حافة إنترنت الأشياء في الوقت الحقيقي. تقترح إطار عمل عصبي رمزي جديد يركز على قابلية التفسير، وكفاءة الموارد، والجدوى في الوقت الحقيقي للأجهزة المحدودة الموارد. تشمل مساهمات هذه الدراسة تطوير إطار عمل دمج عصبي رمزي خفيف الوزن، ودمج استخراج المعرفة لتحسين زمن الاستجابة واستخدام الذاكرة، وتقييم شامل لدقة الكشف عن التسلل، وقابلية التفسير، وكفاءة الحافة باستخدام مجموعة بيانات واقعية لإنترنت الأشياء الصناعية (IIoT). يضع هذا العمل الذكاء الاصطناعي العصبي الرمزي كعامل تمكين حاسم لتطور آمن ومستدام لنظم إنترنت الأشياء من الجيل التالي.
طرق
يهدف إطار عمل الكشف عن التسلل العصبي الرمزي المقترح إلى تعزيز الكشف عن التهديدات في بيئات إنترنت الأشياء الصناعية من خلال دمج المعالجة المسبقة، والمعالجة العصبية الخفيفة، وتقييم القواعد الرمزية. تتضمن المنهجية معالجة مجموعة بيانات Edge-IIoTset من خلال استخراج الميزات والمعالجة المسبقة، حيث يتعاون نموذج عصبي خفيف مع محرك قواعد رمزية لتحليل سلوك حركة مرور الشبكة. يسهل هذا الدمج من المخرجات الكشف عن التسلل القابل للتفسير مع ضمان نشر فعال في الوقت الحقيقي على الأجهزة المحدودة الموارد من خلال استخراج المعرفة. تتميز مجموعة بيانات Edge-IIoTset بميزات متنوعة تلتقط كل من السلوكيات التشغيلية والضارة، مصنفة بشكل منهجي لدعم الاستدلال المنطقي والتقييم في الوقت الحقيقي.
المفتاح لفعالية الإطار هو النهج المنظم لاختيار الميزات والمعالجة المسبقة، والذي يتضمن التقييس العددي، والترميز الفئوي، وتضمين المنطق الرمزي. تهدف عملية اختيار الميزات إلى تعظيم الصلة مع تقليل التكرار، ويتم صياغتها من خلال مقاييس المعلومات المتبادلة. يتم تحويل فئات الميزات المختلفة، مثل إحصائيات تدفق الشبكة، والميزات الزمنية، ومعرفات البروتوكول، رياضيًا لضمان التوافق مع الهياكل الخفيفة الوزن. بالإضافة إلى ذلك، تتضمن الميزات المنطقية معرفة المجال لتعزيز قابلية التفسير. يتم استخدام تقنيات استخراج المعرفة لضغط النماذج المعقدة للنشر على الأجهزة الحافة، مما يضمن تلبية قيود الذاكرة وزمن الاستجابة مع الحفاظ على دقة التنبؤ وقابلية التفسير. تؤكد هذه المنهجية الشاملة على التوازن بين الأداء وكفاءة الموارد في الكشف عن الشذوذ في إنترنت الأشياء.
نقاش
تسلط قسم النقاش في الورقة البحثية الضوء على التقاطع المتزايد بين الذكاء الاصطناعي العصبي الرمزي وإنترنت الأشياء (IoT)، خاصة في معالجة التحديات المتعلقة بالقدرة على التوسع وقابلية التفسير في الأنظمة الذكية في الوقت الحقيقي. تشير الأدبيات التي تمت مراجعتها إلى أنه بينما تظهر الأطر العصبية الرمزية الحالية وعدًا في تعزيز شفافية اتخاذ القرار والموثوقية في البيئات غير المؤكدة، فإنها غالبًا ما تتجاهل القيود الحرجة المحددة للحافة مثل زمن الاستدلال واستخدام الذاكرة. يهدف هذا العمل إلى سد تلك الفجوة من خلال اقتراح إطار عمل عصبي رمزي جديد مُحسَّن للأجهزة الحافة المحدودة الموارد، محققًا دقة تزيد عن 94% مع زمن استجابة أقل من 20 مللي ثانية.
يدمج الإطار المقترح الاستدلال الرمزي في الهياكل العصبية الخفيفة، مما يسمح بالتوازن بين الدقة، وقابلية التفسير، والكفاءة. توفر مجموعة بيانات Edge-IIoTset، المستخدمة للتقييم، معيارًا شاملاً لتقييم أداء النموذج في سيناريوهات إنترنت الأشياء الصناعية الواقعية. تكشف النتائج أن النموذج الهجين لا يعزز فقط من قدرات الكشف – خاصة لأنواع الهجمات المعقدة مثل هجوم الرجل في المنتصف (MITM) والاستطلاع – ولكنه يحافظ أيضًا على الأداء في الوقت الحقيقي والاستقرار عبر سيناريوهات هجوم متنوعة. بشكل عام، يبرز هذا البحث إمكانيات الأساليب العصبية الرمزية في تعزيز أمان إنترنت الأشياء مع معالجة الحاجة الملحة لنماذج خفيفة الوزن وقابلة للتفسير مناسبة للنشر على الحافة.
القيود
يوازن الإطار العصبي الرمزي المقترح للنشر على الحافة بشكل فعال بين دقة الكشف، وقابلية التفسير، والكفاءة الحسابية، مما يجعله مناسبًا للبيئات المحدودة الموارد. من خلال استخدام استخراج المعرفة، يقلل الإطار بشكل كبير من استخدام الذاكرة وزمن الاستدلال، مما يسهل النشر على بوابات الحافة. يعزز تضمين طبقة الاستدلال الرمزي الشفافية في اتخاذ القرار، مما يعزز ثقة المشغل ويساعد في تحليل ما بعد الحدث. ومع ذلك، في إعدادات إنترنت الأشياء واسعة النطاق، قد يتطلب زيادة الحركة نشرًا موزعًا أو هرميًا عبر عدة عقد حافة لضمان الاستجابة، على الرغم من أن نموذج الطالب الخفيف يدعم هذا التوسع مع الحد الأدنى من الأعباء.
على الرغم من النتائج الواعدة المستمدة من مجموعة بيانات صناعية تمثيلية، فإن قابلية تكيف الإطار مع البيئات الجديدة من خلال تعديلات العتبات وتحديثات القواعد جديرة بالملاحظة. تتمثل القيود الرئيسية المحددة في نقص التحقق على مستوى الأجهزة، والذي من المخطط له في النشر المستقبلي. ومع ذلك، تؤكد النتائج الحالية على جدوى الإطار لتطبيقات الكشف عن التسلل القائمة على الحافة في العالم الحقيقي.
DOI: https://doi.org/10.1007/s44397-026-00047-z
Publication Date: 2026-03-05
Author(s): Pawan Kumar Badhan
Primary Topic: Network Security and Intrusion Detection
Overview
This research presents a lightweight neuro-symbolic framework for real-time intrusion detection in Industrial Internet of Things (IIoT) edge environments, addressing the challenges of accuracy, interpretability, and computational efficiency under strict resource constraints. The proposed model integrates lightweight neural learning with symbolic rule-based reasoning and employs knowledge distillation to optimize performance for edge deployment. Evaluated on the Edge-IIoTset dataset, which includes 205,500 labeled network-flow instances from a smart factory, the framework achieved an impressive accuracy of 94.3% and a macro-averaged F1-score of 93.5%. Notably, it demonstrated a 37% reduction in memory usage and a 54% decrease in inference latency compared to traditional deep learning models.
The framework’s feature selection process utilizes mutual information-based relevance analysis combined with symbolic feature embedding, allowing for the effective selection of diverse feature types while minimizing redundancy. The incorporation of weighted neuro-symbolic fusion ensures adaptability to evolving traffic patterns and enhances interpretability through explicit decision pathways. Robustness analysis further confirms the model’s reliability against unseen and hybrid attack scenarios, achieving a macro F1-score of 91.7%. This work establishes the neuro-symbolic framework as a scalable and explainable solution for IoT edge security, paving the way for future research into adaptive symbolic rule learning and cross-device generalization in heterogeneous IoT networks.
Introduction
The introduction of this research paper highlights the pivotal role of the Internet of Things (IoT) in modern digital infrastructure, facilitating automation and intelligent decision-making across various sectors. As IoT networks expand, they produce vast amounts of heterogeneous and time-sensitive data that require processing under strict constraints at the network edge. This has led to a demand for intelligent, adaptive, and explainable learning paradigms, particularly through advancements in neuro-symbolic artificial intelligence, which combines the adaptability of neural networks with the logical transparency of symbolic reasoning. Such hybrid frameworks are particularly beneficial in smart city ecosystems and cybersecurity, where they enhance decision-making and real-time intrusion detection capabilities.
The paper identifies a significant research gap in the integration of symbolic and neural approaches within lightweight architectures suitable for real-time IoT edge environments. It proposes a novel neuro-symbolic framework that emphasizes interpretability, resource efficiency, and real-time feasibility for constrained IoT devices. The contributions of this study include the development of a lightweight neuro-symbolic fusion framework, the incorporation of knowledge distillation to optimize latency and memory usage, and a comprehensive evaluation of intrusion detection accuracy, explainability, and edge efficiency using a realistic Industrial IoT (IIoT) dataset. This work positions neuro-symbolic AI as a crucial enabler for the secure and sustainable evolution of next-generation IoT ecosystems.
Methods
The proposed Neuro-Symbolic Edge Intrusion Detection Framework aims to enhance threat detection in Industrial IoT environments by integrating preprocessing, lightweight neural processing, and symbolic rule evaluation. The methodology involves processing the Edge-IIoTset dataset through feature extraction and preprocessing, where a lightweight neural model collaborates with a symbolic rule engine to analyze network traffic behavior. This fusion of outputs facilitates interpretable intrusion detection while ensuring efficient real-time deployment on resource-constrained edge devices through knowledge distillation. The Edge-IIoTset dataset is characterized by diverse features that capture both operational and malicious behaviors, systematically categorized to support logical reasoning and real-time evaluation.
Key to the framework’s effectiveness is the structured approach to feature selection and preprocessing, which includes numerical scaling, categorical encoding, and symbolic logic embedding. The feature selection process aims to maximize relevance while minimizing redundancy, formalized through mutual information metrics. Various feature categories, such as network flow statistics, temporal features, and protocol identifiers, are mathematically transformed to ensure compatibility with lightweight architectures. Additionally, logical features incorporate domain knowledge to enhance explainability. Knowledge distillation techniques are employed to compress complex models for deployment on edge devices, ensuring they meet memory and latency constraints while maintaining predictive accuracy and interpretability. This comprehensive methodology underscores the balance between performance and resource efficiency in IoT anomaly detection.
Discussion
The discussion section of the research paper highlights the growing intersection of neuro-symbolic AI and the Internet of Things (IoT), particularly in addressing challenges related to scalability and interpretability in real-time intelligent systems. The literature reviewed indicates that while existing neuro-symbolic frameworks demonstrate promise in enhancing decision-making transparency and robustness in uncertain environments, they often overlook critical edge-specific constraints such as inference latency and memory usage. This work aims to fill that gap by proposing a novel neuro-symbolic framework optimized for resource-constrained IoT edge devices, achieving over 94% accuracy with latency under 20 ms.
The proposed framework integrates symbolic reasoning into lightweight neural architectures, allowing for a balance between accuracy, interpretability, and efficiency. The Edge-IIoTset dataset, used for evaluation, provides a comprehensive benchmark for assessing the model’s performance in real-world industrial IoT scenarios. The findings reveal that the hybrid model not only enhances detection capabilities—especially for complex attack types like Man-in-the-Middle (MITM) and reconnaissance—but also maintains real-time performance and stability across diverse attack scenarios. Overall, this research underscores the potential of neuro-symbolic approaches in advancing IoT security while addressing the critical need for lightweight and interpretable models suitable for edge deployment.
Limitations
The proposed neuro-symbolic framework for edge deployment effectively balances detection accuracy, interpretability, and computational efficiency, making it suitable for resource-constrained environments. By employing knowledge distillation, the framework significantly reduces memory usage and inference latency, facilitating deployment on edge gateways. The inclusion of a symbolic reasoning layer enhances transparency in decision-making, fostering operator trust and aiding in post-event analysis. However, in large-scale IoT settings, the increased traffic may necessitate distributed or hierarchical deployment across multiple edge nodes to ensure responsiveness, although the lightweight student model supports this scaling with minimal overhead.
Despite the promising results derived from a representative industrial dataset, the framework’s adaptability to new environments through threshold adjustments and rule updates is noteworthy. The primary limitation identified is the lack of hardware-level validation, which is planned for future deployments. Nonetheless, the current findings underscore the framework’s feasibility for real-world edge-based intrusion detection applications.
