A network intrusion detection method based on double-layer BiLSTM knowledge distillation
By optimizing network intrusion detection through a two-layer BiLSTM knowledge distillation and time attention mechanism, the high computational cost and low detection accuracy of existing methods are solved, achieving efficient and real-time intrusion detection results.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- KUNMING UNIV OF SCI & TECH
- Filing Date
- 2026-03-17
- Publication Date
- 2026-06-02
AI Technical Summary
Existing BiLSTM-based network intrusion detection methods suffer from high computational overhead, long inference latency, low utilization of temporal features, and degradation of detection accuracy under extremely imbalanced data.
We employ a two-layer BiLSTM knowledge distillation method, combining a time attention mechanism with a distillation training approach that integrates soft and hard labels. Through knowledge transfer between the two-layer BiLSTM teacher and student models, we optimize feature extraction and classification, reduce the number of model parameters, and improve detection efficiency.
It achieved a reduction of approximately 4.9 times in the number of model parameters, a reduction in inference latency to 12ms, and an improvement in detection accuracy to 99.86% and 99.32%, respectively. It meets the real-time detection requirements in resource-constrained environments and significantly improves the accuracy of identifying variant attacks and zero-day attacks.
Smart Images

Figure CN122137655A_ABST