---
格式版本: 2
标题: "A Deployment-Oriented and Resource-Efficient Neuro-Symbolic Framework for Explainable DDoS Detection in Operational Technology Networks"
原文链接: "https://arxiv.org/abs/2608.16769"
发布日期: "2026-08-17"
发布时间校准状态: "found"
发布时间需复核: "否"
发布时间来源: "rule:local:strict_original_body"
发布时间证据: "**\\[v1\\]** Mon, 17 Aug 2026 16:18:15 UTC (3,452 KB)"
发布时间校准原因: "规则确认唯一严格发布时间，来源 local:strict_original_body"
发布时间校准置信度: "high"
发布时间候选数量: 18
发布时间严格候选数量: 6
发布时间原页读取状态: "source template page reused from URL open"
发布时间未找到原因: ""
发布时间校准时间: "2026-08-20T15:59:17+08:00"
发布时间仲裁状态: "skipped"
发布时间仲裁尝试次数: 0
发布时间仲裁耗时毫秒: 0
发现时间: "2026-08-20T15:54:04+08:00"
入库时间: "2026-08-20T07:59:17.575Z"
来源平台: "arXiv 学术论文搜索"
搜索渠道: "source_template"
搜索词: "https://arxiv.org/search/?query=inference%20networking&searchtype=all"
匹配关键词:
  - "deployment"
  - "latency"
相关厂家:
  []
相关专家:
  []
内容类型: "网页"
抓取工具: "Free Fetch + Defuddle"
清洗工具: "Defuddle Markdown + Defuddle/Readability 正文提取"
原始附件:
  []
AI优质: "否"
AI打分: 4
AI分档: "非优质"
AI质检状态: "不通过"
AI打分理由: "该arXiv论文为OT网络DDoS检测研究，与超节点/AI Rack/机柜级AI基础设施、供电散热互连等主题完全无关，无相关厂商或专家，不归档。"
AI质检模型: "ali-deepseek-v4-flash"
AI质检时间: "2026-08-20T16:05:11+08:00"
AI主题相关性: 0
AI来源权威性: 2
AI新颖性: 0
AI技术细节: 0
AI商业部署信号: 0
AI完整性: 2
AI摘要: "该研究提出一个面向部署的神经符号DDoS检测框架，融合GRU神经网络与浅层决策树，在OT网络资源受限环境下实现可解释检测。"
AI摘要模型: "ali-deepseek-v4-flash"
AI摘要时间: "2026-09-07T03:25:40.981Z"
采集批次: "2026年8月20日14点19分32秒"
采集批次ID: "20260820-141932-079"
去重键: "https://arxiv.org/abs/2608.16769"
---

## Computer Science > Cryptography and Security

## Title:A Deployment-Oriented and Resource-Efficient Neuro-Symbolic Framework for Explainable DDoS Detection in Operational Technology Networks

[View PDF](https://arxiv.org/pdf/2608.16769) [HTML (experimental)](https://arxiv.org/html/2608.16769v1)

> Abstract:Operational technology (OT) environments, including programmable logic controllers (PLCs), industrial control systems (ICS), and supervisory control and data acquisition (SCADA) systems, are increasingly targeted by distributed denial-of-service (DDoS) attacks. This paper presents a neuro-symbolic framework specifically designed for robust DDoS detection in these resource-constrained environments. The framework fuses a gated recurrent unit (GRU) neural network with a shallow decision tree as a symbolic component. The symbolic component alone provides a compact, interpretable rule set, while the fusion combines the strengths of both paradigms. The hybrid model is evaluated on three real-world benchmark DDoS datasets: CIC-DDoS2019, Edge-IIoTset, and CICIoT23. A unified comprehensive preprocessing pipeline including label mapping, numerical feature selection, robust scaling, and class balancing is applied. The fusion weight alpha and decision threshold are jointly optimised on validation data to maximise F1-score. The hybrid model attains 99.04% accuracy (MCC 0.97) on CIC-DDoS2019 and 98.61% accuracy (MCC 0.76) on CICIoT23, in both cases reducing the FNR below that of the pure-neural and pure-symbolic baselines; on the linearly separable Edge-IIoTset the shallow decision tree alone already reaches 100%, so this benchmark validates the preprocessing pipeline rather than the fusion. The principal gain of the fusion is a lower FNR at a controlled false-positive cost, which matters in operational technology, where a missed attack is more damaging than a false alarm. Model-only inference latency is sub-millisecond (0.58-0.79 milliseconds per sample) on a standard central processing unit; including on-device flow-feature extraction, the end-to-end path remains within a single-digit-millisecond budget, which is compatible with OT control-loop timing.

| Comments: |  |
| --- | --- |
| Subjects: | Cryptography and Security (cs.CR) |
| Cite as: | [arXiv:2608.16769](https://arxiv.org/abs/2608.16769) \[cs.CR\] |
|  | (or [arXiv:2608.16769v1](https://arxiv.org/abs/2608.16769v1) \[cs.CR\] for this version) |
|  | [https://doi.org/10.48550/arXiv.2608.16769](https://doi.org/10.48550/arXiv.2608.16769) |

## Submission history

From: Mohamed Chahine Ghanem Dr \[[view email](https://arxiv.org/show-email/2d755339/2608.16769)\]  
**\[v1\]** Mon, 17 Aug 2026 16:18:15 UTC (3,452 KB)

[Which authors of this paper are endorsers?](https://arxiv.org/auth/show-endorsers/2608.16769) | Disable MathJax ([What is MathJax?](https://info.arxiv.org/help/mathjax.html))
