A Lightweight Fine-Grained Malicious Request Detection Model Towards Smart Grid Cloud Services
To address the challenges in malicious request detection in smart grid cloud service scenarios, including the difficulty of effectively capturing the semantic relationships within payloads, the large parameter scale and high inference costs of pre-trained language models, an efficient and relatively lightweight, fine-grained malicious request detection model named DFEF-Net (DistilBERT-based FiLM-enhanced Expert Feature Network, DFEF-Net) is proposed. First, the model is based on the lightweight pre-trained language model DistilBERT and constructs 14-dimensional expert-based features to characterize the statistical information of request payloads, so as to strengthen its ability to represent request structural features and anomalous patterns. Second, the feature-wise linear modulation (FiLM) mechanism is introduced to adaptively modulate deep semantic features, effectively fusing semantic features with structural features. Finally, experiments on the proposed scheme are conducted on four public Web/HTTP attack datasets (HttpParams, HTTP CSIC 2010, FWAF, and SecureAI-SE). On these benchmarks, DFEF-Net achieves over 99% accuracy in binary attack detection on all four datasets. In multi-class attack identification, DFEF-Net reaches 99.27% macro-F1 on HttpParams and 97.00% on SecureAI-SE. RoBERTa slightly surpasses it on SecureAI-SE but drops to 59.53% macro-F1 on HttpParams, whereas DFEF-Net maintains balanced recognition across both datasets. Per-class analysis and multi-seed results further show relatively consistent fine-grained recognition across attack categories. Compared with BERT-based baseline models, DFEF-Net reduces model parameter count by approximately 39%, model size by 39%, FLOPs by 50%, and per-request inference latency by approximately 40–60% under the evaluated protocol. Consequently, the proposed approach offers a favorable trade-off among detection performance, computational cost, and fine-grained attack identification on the evaluated public Web/HTTP benchmarks, providing an efficient algorithmic basis for future evaluation in smart grid cloud services, while domain-specific validation on real smart-grid traffic remains necessary.
Authors
- Xiaolin Gui (ORCID: https://orcid.org/0000-0003-4384-9891)
- Gang Liu (ORCID: https://orcid.org/0000-0003-4251-9647)
- Haopeng Shi
- Ke Yang
- Chao Ma
- Zhipeng Qu
- Xuheng Wang (ORCID: https://orcid.org/0009-0000-9140-2248)
- Xiang Li
Institutions
- State Grid Corporation of China (China) (CN)
- Shanghai Electric (China) (CN)
- Xi'an Jiaotong University (CN)
Publication Details
- Journal
- Information
- Published
- 2026-10-04
- DOI
- https://doi.org/10.3390/info17100980
- Primary Topic
- Network Security and Intrusion Detection
- Type
- article
- Field-Weighted Citation Impact
- 0.00