A Lightweight Network Intrusion Detection Method Based on Protocol-Aware Dynamic Inverted Residuals and a Sliding-Window Multi-Batch Self-Knowledge Distillation Strategy
Shuquan Feng, Shizhao Ma, Minghong Ma · 2025
With the exponential growth of edge computing and Internet of Things (IoT) devices, network attacks have become increasingly large-scale, stealthy, and adaptive. Traditional rule-based defense mechanisms struggle to cope with emerging attack patterns such as zero-day vulnerabilities and advanced persistent threats (APT). As a critical component of the network security defense-in-depth framework, Intrusion Detection Systems (IDS) play a vital role in identifying and responding to potential threats. Although current deep learning-based IDS approaches demonstrate excellent detection accuracy, their high computational overhead and complex model architectures limit their applicability in resource-constrained environments. To address this challenge, this paper proposes a novel lightweight network intrusion detection method called IRNet-MBSKD (Inverted Residual Network with Multi-Batch Self-Knowledge Distillation). By leveraging a protocol-aware dynamic inverted residual architecture coupled with a sliding-window multi-batch self-distillation mechanism, IRNet-MBSKD achieves a detection accuracy of 98.79% on the NSL-KDD dataset while reducing model complexity to 198.65K FLOPs—a 47.2% reduction in computational cost compared to baseline models. Extensive experiments conducted on benchmark datasets demonstrate that IRNet-MBSKD not only excels in detection accuracy but also achieves an impressive balance between parameter count and computational load. This makes it an efficient, reliable, and lightweight solution for network security, especially in resource-limited environments.