A Lightweight Fine-Grained Malicious Request Detection Model Towards Smart Grid Cloud Services

To address the challenges in malicious request detection in smart grid cloud service scenarios, including the difficulty of effectively capturing the semantic relationships within payloads, the large parameter scale and high inference costs of pre-trained language models, an efficient and relatively lightweight, fine-grained malicious request detection model named DFEF-Net (DistilBERT-based FiLM-enhanced Expert Feature Network, DFEF-Net) is proposed. First, the model is based on the lightweight pre-trained language model DistilBERT and constructs 14-dimensional expert-based features to characterize the statistical information of request payloads, so as to strengthen its ability to represent request structural features and anomalous patterns. Second, the feature-wise linear modulation (FiLM) mechanism is introduced to adaptively modulate deep semantic features, effectively fusing semantic features with structural features. Finally, experiments on the proposed scheme are conducted on four public Web/HTTP attack datasets (HttpParams, HTTP CSIC 2010, FWAF, and SecureAI-SE). On these benchmarks, DFEF-Net achieves over 99% accuracy in binary attack detection on all four datasets. In multi-class attack identification, DFEF-Net reaches 99.27% macro-F1 on HttpParams and 97.00% on SecureAI-SE. RoBERTa slightly surpasses it on SecureAI-SE but drops to 59.53% macro-F1 on HttpParams, whereas DFEF-Net maintains balanced recognition across both datasets. Per-class analysis and multi-seed results further show relatively consistent fine-grained recognition across attack categories. Compared with BERT-based baseline models, DFEF-Net reduces model parameter count by approximately 39%, model size by 39%, FLOPs by 50%, and per-request inference latency by approximately 40–60% under the evaluated protocol. Consequently, the proposed approach offers a favorable trade-off among detection performance, computational cost, and fine-grained attack identification on the evaluated public Web/HTTP benchmarks, providing an efficient algorithmic basis for future evaluation in smart grid cloud services, while domain-specific validation on real smart-grid traffic remains necessary.

Authors

Institutions

Publication Details

Journal
Information
Published
2026-10-04
DOI
https://doi.org/10.3390/info17100980
Primary Topic
Network Security and Intrusion Detection
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
article

A Lightweight Fine-Grained Malicious Request Detection Model Towards Smart Grid Cloud Services

Xiaolin Gui, Gang Liu, Haopeng Shi, Ke Yang et al.
Information
Network Security and Intrusion Detection
article

A Lightweight Fine-Grained Malicious Request Detection Model Towards Smart Grid Cloud Services

Xiaolin Gui, Gang Liu, Haopeng Shi, Ke Yang, Chao Ma, Zhipeng Qu, Xuheng Wang, Xiang Li
article en

Abstract

To address the challenges in malicious request detection in smart grid cloud service scenarios, including the difficulty of effectively capturing the semantic relationships within payloads, the large parameter scale and high inference costs of pre-trained language models, an efficient and relatively lightweight, fine-grained malicious request detection model named DFEF-Net (DistilBERT-based FiLM-enhanced Expert Feature Network, DFEF-Net) is proposed. First, the model is based on the lightweight pre-trained language model DistilBERT and constructs 14-dimensional expert-based features to characterize the statistical information of request payloads, so as to strengthen its ability to represent request structural features and anomalous patterns. Second, the feature-wise linear modulation (FiLM) mechanism is introduced to adaptively modulate deep semantic features, effectively fusing semantic features with structural features. Finally, experiments on the proposed scheme are conducted on four public Web/HTTP attack datasets (HttpParams, HTTP CSIC 2010, FWAF, and SecureAI-SE). On these benchmarks, DFEF-Net achieves over 99% accuracy in binary attack detection on all four datasets. In multi-class attack identification, DFEF-Net reaches 99.27% macro-F1 on HttpParams and 97.00% on SecureAI-SE. RoBERTa slightly surpasses it on SecureAI-SE but drops to 59.53% macro-F1 on HttpParams, whereas DFEF-Net maintains balanced recognition across both datasets. Per-class analysis and multi-seed results further show relatively consistent fine-grained recognition across attack categories. Compared with BERT-based baseline models, DFEF-Net reduces model parameter count by approximately 39%, model size by 39%, FLOPs by 50%, and per-request inference latency by approximately 40–60% under the evaluated protocol. Consequently, the proposed approach offers a favorable trade-off among detection performance, computational cost, and fine-grained attack identification on the evaluated public Web/HTTP benchmarks, providing an efficient algorithmic basis for future evaluation in smart grid cloud services, while domain-specific validation on real smart-grid traffic remains necessary.

InformationVol. 17(10)
State Grid Corporation of China (China) (CN), Shanghai Electric (China) (CN), Xi'an Jiaotong University (CN)
Openalex Percentile: Top 9%
Network Security and Intrusion Detection
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.