Skip to content
Open access

HEDM-KD: A Parallel Heterogeneous Knowledge Distillation Framework for Class-Imbalanced Intrusion Detection

2026 · IEEE Access · Vol 14, pp. 139003-139028 · 0 citations · 40 references

TL;DR

With its lightweight design, HEDM-KD effectively mitigates the impact of class imbalance and demonstrates potential for improving detection robustness in resource-constrained scenarios.

Abstract

Network intrusion detection is critical for system security, particularly the accurate identification of rare and irregular attack samples. Class imbalance remains a major challenge, as the predominance of normal traffic can bias decision boundaries toward majority classes and degrade minority-attack detection. Traditional knowledge distillation approaches rely on large pre-trained teacher models, which incur high computational costs and offer limited adaptability to dynamic uncertainty differences between teacher and student models under imbalanced conditions. To address these issues, we propose HEDM-KD, a parallel heterogeneous ensemble knowledge distillation framework based on CNNs. The framework first constructs multiple heterogeneous subsets via bootstrap sampling and applies diverse imbalance-handling strategies to enhance data diversity. A dynamic mutual learning mechanism then enables synchronous training across branches: in each training round, the branch with the highest validation F1-score is selected as the teacher, and its convolutional weights are transferred to the remaining student branches. An entropy-driven dynamic weighting strategy further adaptively balances the hard-label loss and distillation loss according to model output uncertainty, improving robustness under imbalanced distributions. Finally, multi-branch hard voting enhances classification stability. Extensive experiments on CarHacking, CIC-IoV2024, UNSW-NB15, and CICIDS2017 show that HEDM-KD achieves competitive performance against single resampling methods, conventional knowledge distillation variants, and models including AdaBoost, ResNet18, TFTKD, and DFF-DA in terms of accuracy, precision, recall, and F1-score. Notably, it maintains strong detection capability on the highly imbalanced UNSW-NB15 dataset while attaining near-perfect metrics on CarHacking, CIC-IoV2024, and CICIDS2017. With its lightweight design, HEDM-KD effectively mitigates the impact of class imbalance and demonstrates potential for improving detection robustness in resource-constrained scenarios.

Read PDF

Similar papers

Open access Aug 2026

HADS-Net: A Hybrid Attention-Based Deep Security Network for Network Intrusion Detection

The principal contribution of this work is architectural and diagnostic rather than a performance improvement: it documents that combining feature-wise attention with out-of-fold stacked generalization does not, in this setting, outperform a plain multi-layer perceptron, while incurring the highest memory footprint of...

Mahima Khanna, V. Murthy, Siva Ramavarapu et al. · 0 citations
Open access Sep 2026

A Hybrid SMOTE-CTGAN and VAE-LSTM Framework for Interpretable Intrusion Detection in Imbalanced Network Traffic

The increasing sophistication of cyber threats and severe class imbalance in network traffic continue to challenge traditional intrusion detection systems. This study proposes a hybrid framework that integrates SMOTE and CTGAN for minority-class augmentation, a Bidirectional Long Short-Term Memory (Bi-LSTM) network for...

Felicia Maake, Justice Nkoana, V. Baloyi et al. · 0 citations
Open access Aug 2026

Investigating Contrastive Learning for Conditional Variational Autoencoders in Network Intrusion Detection

Class imbalance, where majority-class samples vastly outnumber minority-class samples, remains a persistent challenge in network intrusion detection systems (NIDS), often causing classifiers to overlook rare but critical attack types while yielding misleadingly optimistic performance metrics. Synthetic data generation...

H. Dinh, W. Zong, Yang-Wai Chow et al. · 0 citations
Open access Aug 2026

An Enhanced Hybrid Deep Learning Model for Anomaly-Based Intrusion Detection in the CICIDS2017 Web Attack Traffic

An enhanced hybrid deep learning architecture that combines one-dimensional convolutional layers, bidirectional long short-term memory units, and a multi-head self-attention mechanism for detecting web attacks in network-flow data is proposed.

Israa Shihab Ahmed, Wasan Alaa Hussain, Z. H. Rasool · 0 citations
Open access 2026

A Novel Entropy-Based Framework for Hybrid Sampling in Imbalanced Learning

: Imbalanced data remain a critical challenge in classification, as skewed distributions bias models toward majority classes and diminish sensitivity to minority classes, which are often the most critical. To address this issue, this paper proposes the Information Filtered Hybrid Algorithm (IF-HA), a novel entropy-base...

Ren-Jieh Kuo, Muhammad Rizki, F. E. Zulvia et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.