arrow
Return

An explainable, resource-efficient transformer-based IDS with adaptive agent routing

delete2026-08-15
delete0
PRE
AI
Ç
Çaǧdaş Özer
Z
Zeynep Orman *
DOI:10.1007/s10586-026-06495-xdelete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Intrusion Detection Systems (IDSs) must detect increasingly diverse cyber threats while operating under strict computational and latency constraints. Although Transformer-based models capture long-range dependencies in network traffic effectively, their deployment in real-time security environments remains limited by the quadratic cost of dense self-attention, the scarcity of labeled attack data, and the need for interpretable predictions. This study proposes an explainable and resource-efficient Transformer-based IDS framework that integrates hybrid sparse attention, mixed-precision training, adaptive agent routing, and a multi-stage auto-labeling strategy. The proposed architecture combines Reformer-style locality-sensitive hashing attention, a fixed local attention window, and a small set of global tokens to reduce computational overhead while preserving short- and long-range traffic dependencies. A lightweight adaptive agent routes high-confidence flows to specialized sub-models, whereas uncertain samples are processed through an auto-labeling pipeline that includes self-training, consistency regularization, MixMatch, adversarial training, and a co-training variant. Experimental results on standard intrusion detection benchmarks show that the proposed framework improves detection performance under limited-label conditions while reducing training time, memory usage, and inference latency relative to dense-attention baselines. In addition, SHAP-based explanations provide global, class-wise, and instance-level interpretability, supporting analyst trust and post hoc security auditing. The findings indicate that the proposed framework offers a practical balance among detection accuracy, computational efficiency, and explainability, making it suitable for deployment in resource-constrained and real-time network security environments.
Keywords:
Intrusion detection systems
Transformer-based IDS
Sparse attention
Adaptive agent routing
Semi-supervised learning
Auto-labeling
SHAP explainability

Journal

C
Cluster Computing-The Journal of Networks Software Tools and Applications
IF:
4.1
Papers:
5.0K
Citations:
7.5K

Organization

D
Department of Computer Engineering
Scholars:
305
Papers: 166
Citations: 0