Retrieval-augmented parameter-training-free intrusion detection for artificial intelligence of things using dual re-ranking and large language model inference
Haifeng Lv, Yong DingAbstract
Intrusion detection systems (IDS) are pivotal for safeguarding artificial intelligence of things (AIoT)-enabled smart societies, where intensive interactions among IoT devices and AI services create expanding attack surfaces. However, conventional supervised IDS approaches depend heavily on large labeled datasets and often lack adaptability to emerging attacks. To overcome these limitations, we propose a unified intrusion detection system with dual re-ranking and large language model inference (UIDS-DRLLM), a parameter-training-free, retrieval-augmented framework for AIoT environments . UIDS-DRLLM introduces a dual re-ranking strategy that combines large language model (LLM)-based semantic similarity, correlation-weighted IoT feature analysis, and Elasticsearch retrieval to identify relevant historical threat patterns without model retraining. Based on the retrieved few-shot context, a prompt-driven LLM inference module performs interpretable attack classification through expert-like reasoning. Furthermore, a dynamic weighted aggregation mechanism adaptively integrates multi-source outputs to improve robustness across heterogeneous IoT scenarios. Experiments on NSL-KDD and UNSW-NB15 show that UIDS-DRLLM achieves competitive accuracy of 0.896 and 0.916, respectively, outperforming baseline methods. Its parameter-training-free and few-shot learning design reduce annotation and computational costs, while LLM-driven reasoning enhances explainability and trustworthiness. By addressing key challenges in IoT security—scalability, adaptability, and explainability—UIDS-DRLLM provides a scalable, adaptive, and interpretable solution for securing AIoT ecosystems against evolving cyber threats.