Norns: Leveraging Multi-Modal Mamba for Efficient Network Intrusion Detection via Integrating Comprehensive Flow Features and Packet Bytes

S.C. Zhang, Defeng Zeng, Yaping Liu, Shuo Zhang · 2025

Intrusion detection has become an indispensable and critical component of network security. Using their advanced text processing and comprehension abilities, LLMs accurately analyze extensive network traffic to pinpoint potential threats and unusual behavior patterns. This can significantly reduce false alarms and missed detections, improving overall detection efficiency. However, current research on using Transformer-Based LLMs faces two main challenges. Primarily, concentrating solely on extracting features from packet bytes inadequately represents traffic and overlooks the significance of flow features in differentiating attacks. Furthermore, the quadratic computational complexity of Transformer-Based LLM models hinders cost-effective computation and deployment for intrusion detection systems. To address these challenges, we propose Norns, an effective multimodal linear state-space model with a comprehensive method for characterizing traffic. Using flow feature maps and bytes from multiple packets as input data, Norns significantly enhances traffic representation. Moreover, it utilizes a linear Mamba model with reduced time and space complexity. Experiments on the CIC-IDS-2017 dataset show that Norns outperforms the baselines. It achieves high-accuracy intrusion detection. A single 4090 graphics card can handle the entire process of model pre-training, fine-tuning, and inference, making it a promising network security solution.

Read the paper · More papers on PaperTik