Sec-Llama: a Compact Fine-Tuned LLM for Network Intrusion Detection in Kubernetes Clusters
Anes Abdennebi, Nadjia Kara, Laaziz Lahlou, Mohamed Younis, Hakima Ould‐Slimane · 2025
In today’s interconnected world, cyber threats have grown both pervasive and sophisticated, especially in the Artificial Intelligence (AI) era, where digital systems face unprecedented risks. As companies and enterprises increasingly rely on Kubernetes to orchestrate an enormous number of microservices and deliver high-quality services to users, a serious security threat endangers the application flow. In particular, recent advances in generative AI have increased the pace, scale, and level of cyberattacks on microservice-based systems. At the network level, traditional defensive tools fail to detect these threats accurately and timely, increasing the average latencies of detection and remediation and hence, risking worse damages on the services and system levels. Due to their excessive computation and memory requirements, large language models (LLM) have not been considered viable network intrusion detection systems (NIDS) or tools within the Kubernetes clusters. We developed Sec-Llama, a compact LLM for intrusion detection. We demonstrated a case study where we applied a memory-efficient data-driven technique incorporating Byte-based transformation of the raw network flow, to optimize the model’s training and inference processes, on resource-wise, while maintaining a 96% threat detection F1-score. To facilitate the model’s training and deployment processes for users, we have developed an application to monitor, train, and launch our Sec-Llama for real-time inferences that took, on average, 21.1ms per inference while occupying only 172 MB.