Lightweight LLMs for Network Attack Detection in IoT Networks

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Sudasinghe, Piyumi Bhagya, Liyanage, Kushan Sudheera Kalupahana, Pussewalage, Harsha S. Gardiyawasam
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909997131104256
author Sudasinghe, Piyumi Bhagya
Liyanage, Kushan Sudheera Kalupahana
Pussewalage, Harsha S. Gardiyawasam
author_facet Sudasinghe, Piyumi Bhagya
Liyanage, Kushan Sudheera Kalupahana
Pussewalage, Harsha S. Gardiyawasam
contents The rapid growth of Internet of Things (IoT) devices has increased the scale and diversity of cyberattacks, exposing limitations in traditional intrusion detection systems. Classical machine learning (ML) models such as Random Forest and Support Vector Machine perform well on known attacks but require retraining to detect unseen or zero-day threats. This study investigates lightweight decoder-only Large Language Models (LLMs) for IoT attack detection by integrating structured-to-text conversion, Quantized Low-Rank Adaptation (QLoRA) fine-tuning, and Retrieval-Augmented Generation (RAG). Network traffic features are transformed into compact natural-language prompts, enabling efficient adaptation under constrained hardware. Experiments on the CICIoT2023 dataset show that a QLoRA-tuned LLaMA-1B model achieves an F1-score of 0.7124, comparable to the Random Forest (RF) baseline (0.7159) for known attacks. With RAG, the system attains 42.63% accuracy on unseen attack types without additional training, demonstrating practical zero-shot capability. These results highlight the potential of retrieval-enhanced lightweight LLMs as adaptable and resource-efficient solutions for next-generation IoT intrusion detection.
format Preprint
id arxiv_https___arxiv_org_abs_2601_15269
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Lightweight LLMs for Network Attack Detection in IoT Networks
Sudasinghe, Piyumi Bhagya
Liyanage, Kushan Sudheera Kalupahana
Pussewalage, Harsha S. Gardiyawasam
Cryptography and Security
C.2.0; C.2.3; I.2.6; I.2.7
The rapid growth of Internet of Things (IoT) devices has increased the scale and diversity of cyberattacks, exposing limitations in traditional intrusion detection systems. Classical machine learning (ML) models such as Random Forest and Support Vector Machine perform well on known attacks but require retraining to detect unseen or zero-day threats. This study investigates lightweight decoder-only Large Language Models (LLMs) for IoT attack detection by integrating structured-to-text conversion, Quantized Low-Rank Adaptation (QLoRA) fine-tuning, and Retrieval-Augmented Generation (RAG). Network traffic features are transformed into compact natural-language prompts, enabling efficient adaptation under constrained hardware. Experiments on the CICIoT2023 dataset show that a QLoRA-tuned LLaMA-1B model achieves an F1-score of 0.7124, comparable to the Random Forest (RF) baseline (0.7159) for known attacks. With RAG, the system attains 42.63% accuracy on unseen attack types without additional training, demonstrating practical zero-shot capability. These results highlight the potential of retrieval-enhanced lightweight LLMs as adaptable and resource-efficient solutions for next-generation IoT intrusion detection.
title Lightweight LLMs for Network Attack Detection in IoT Networks
topic Cryptography and Security
C.2.0; C.2.3; I.2.6; I.2.7
url https://arxiv.org/abs/2601.15269