{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,15]],"date-time":"2026-05-15T03:15:39Z","timestamp":1778814939771,"version":"3.51.4"},"reference-count":43,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Ad Hoc Networks"],"published-print":{"date-parts":[[2026,9]]},"DOI":"10.1016\/j.adhoc.2026.104291","type":"journal-article","created":{"date-parts":[[2026,5,9]],"date-time":"2026-05-09T15:39:27Z","timestamp":1778341167000},"page":"104291","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["NINMix-KD: Statistical moment matching knowledge distillation for edge resource-constrained network intrusion detection"],"prefix":"10.1016","volume":"190","author":[{"given":"Mu","family":"Lin","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Damin","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ji","family":"Zhao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuhan","family":"Yang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"78","reference":[{"key":"10.1016\/j.adhoc.2026.104291_b1","doi-asserted-by":"crossref","DOI":"10.1016\/j.cosrev.2024.100631","article-title":"AI techniques for IoT-based DDoS attack detection: Taxonomies, comprehensive review and research challenges","volume":"52","author":"Bala","year":"2024","journal-title":"Comput. Sci. Rev."},{"key":"10.1016\/j.adhoc.2026.104291_b2","article-title":"DAME-IoV: Dynamic adaptive multi-edge authentication protocol with post-quantum security for Internet of Vehicles","volume":"54","author":"Rasheed","year":"2025","journal-title":"Veh. Commun."},{"issue":"4","key":"10.1016\/j.adhoc.2026.104291_b3","doi-asserted-by":"crossref","first-page":"2351","DOI":"10.1109\/COMST.2021.3106669","article-title":"A survey of honeypots and honeynets for internet of things, industrial internet of things, and cyber-physical systems","volume":"23","author":"Franco","year":"2021","journal-title":"IEEE Commun. Surv. & Tutorials"},{"key":"10.1016\/j.adhoc.2026.104291_b4","doi-asserted-by":"crossref","DOI":"10.1016\/j.engappai.2025.112130","article-title":"Malicious detection and trust calculation using residual recurrent neural network for trust with quality of service-aware multicast routing in mobile Ad-Hoc network system","volume":"161","author":"Sarangi","year":"2025","journal-title":"Eng. Appl. Artif. Intell."},{"key":"10.1016\/j.adhoc.2026.104291_b5","doi-asserted-by":"crossref","first-page":"3277","DOI":"10.1109\/TIFS.2023.3278449","article-title":"Survivability analysis of IoT systems under resource exhausting attacks","volume":"18","author":"Pietrantuono","year":"2023","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.adhoc.2026.104291_b6","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2021.102352","article-title":"Hardening machine learning denial of service (DoS) defences against adversarial attacks in IoT smart home networks","volume":"108","author":"Anthi","year":"2021","journal-title":"Comput. Secur."},{"key":"10.1016\/j.adhoc.2026.104291_b7","doi-asserted-by":"crossref","DOI":"10.1016\/j.iot.2024.101336","article-title":"A novel deep learning-based intrusion detection system for IoT DDoS security","volume":"28","author":"Hizal","year":"2024","journal-title":"Internet Things"},{"key":"10.1016\/j.adhoc.2026.104291_b8","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2025.104392","article-title":"FC-Trans: Deep learning methods for network intrusion detection in big data environments","volume":"154","author":"Zhu","year":"2025","journal-title":"Comput. Secur."},{"key":"10.1016\/j.adhoc.2026.104291_b9","doi-asserted-by":"crossref","DOI":"10.1016\/j.knosys.2025.114436","article-title":"Multi-class intrusion detection system for in-vehicle networks using few-shot learning and convolutional anomaly transformer network","volume":"330","author":"Duy","year":"2025","journal-title":"Knowl.-Based Syst."},{"key":"10.1016\/j.adhoc.2026.104291_b10","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2023.109982","article-title":"Res-TranBiLSTM: An intelligent approach for intrusion detection in the Internet of Things","volume":"235","author":"Wang","year":"2023","journal-title":"Comput. Netw."},{"key":"10.1016\/j.adhoc.2026.104291_b11","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2022.119330","article-title":"Implementation of intrusion detection model for DDoS attacks in Lightweight IoT Networks","volume":"215","author":"Khanday","year":"2023","journal-title":"Expert Syst. Appl."},{"key":"10.1016\/j.adhoc.2026.104291_b12","series-title":"2024 IEEE Wireless Communications and Networking Conference","first-page":"1","article-title":"Game-theoretic lightweight autoencoder design for intrusion detection","author":"Rheey","year":"2024"},{"issue":"4","key":"10.1016\/j.adhoc.2026.104291_b13","doi-asserted-by":"crossref","first-page":"6438","DOI":"10.1109\/JIOT.2023.3310794","article-title":"LKD-STNN: A lightweight malicious traffic detection method for internet of things based on knowledge distillation","volume":"11","author":"Zhu","year":"2024","journal-title":"IEEE Internet Things J."},{"key":"10.1016\/j.adhoc.2026.104291_b14","doi-asserted-by":"crossref","first-page":"6398","DOI":"10.1109\/TIFS.2025.3581117","article-title":"Efficient intrusion detection for in-vehicle networks using knowledge distillation from BERT to CNN-BiLSTM","volume":"20","author":"Li","year":"2025","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.adhoc.2026.104291_b15","article-title":"VINCENT: Cyber-threat detection through vision transformers and knowledge distillation","volume":"144","author":"Rose","year":"2024","journal-title":"Comput. Secur."},{"key":"10.1016\/j.adhoc.2026.104291_b16","series-title":"Distilling the knowledge in a neural network","author":"Hinton","year":"2015"},{"key":"10.1016\/j.adhoc.2026.104291_b17","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2022.117671","article-title":"A lightweight approach for network intrusion detection in industrial cyber-physical systems based on knowledge distillation and deep metric learning","volume":"206","author":"Wang","year":"2022","journal-title":"Expert Syst. Appl."},{"key":"10.1016\/j.adhoc.2026.104291_b18","article-title":"A lightweight IoT intrusion detection model based on improved BERT-of-Theseus","volume":"238","author":"Wang","year":"2024","journal-title":"Expert Syst. Appl."},{"key":"10.1016\/j.adhoc.2026.104291_b19","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103636","article-title":"Spatial-temporal knowledge distillation for lightweight network traffic anomaly detection","volume":"137","author":"Wang","year":"2024","journal-title":"Comput. Secur."},{"key":"10.1016\/j.adhoc.2026.104291_b20","doi-asserted-by":"crossref","DOI":"10.1016\/j.asoc.2024.112118","article-title":"Lightweight intrusion detection model based on CNN and knowledge distillation","volume":"165","author":"Wang","year":"2024","journal-title":"Appl. Soft Comput."},{"issue":"18","key":"10.1016\/j.adhoc.2026.104291_b21","doi-asserted-by":"crossref","first-page":"38509","DOI":"10.1109\/JIOT.2025.3586290","article-title":"TGDCLNet: Teacher-guided denoising contrastive learning network-based IoT network intrusion detection","volume":"12","author":"Yang","year":"2025","journal-title":"IEEE Internet Things J."},{"key":"10.1016\/j.adhoc.2026.104291_b22","doi-asserted-by":"crossref","DOI":"10.1016\/j.adhoc.2025.103869","article-title":"DTKD-IDS: A dual-teacher knowledge distillation intrusion detection model for the industrial internet of things","volume":"174","author":"Xie","year":"2025","journal-title":"Ad Hoc Networks"},{"issue":"4","key":"10.1016\/j.adhoc.2026.104291_b23","doi-asserted-by":"crossref","first-page":"12157","DOI":"10.1109\/TCE.2025.3601183","article-title":"Knowledge distillation for lightweight and explainable intrusion detection in resource-constrained consumer devices","volume":"71","author":"Umair","year":"2025","journal-title":"IEEE Trans. Consum. Electron."},{"issue":"11","key":"10.1016\/j.adhoc.2026.104291_b24","doi-asserted-by":"crossref","first-page":"8475","DOI":"10.1109\/TII.2025.3582375","article-title":"KD-BERT: A lightweight knowledge distillation bidirectional encoder representations from transformers for IoT network intrusion detection","volume":"21","author":"Cao","year":"2025","journal-title":"IEEE Trans. Ind. Informatics"},{"key":"10.1016\/j.adhoc.2026.104291_b25","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2025.130460","article-title":"Explainable resource-Aware IoT security model via knowledge distillation and adaptive loss function optimization","volume":"302","author":"Okey","year":"2026","journal-title":"Expert Syst. Appl."},{"key":"10.1016\/j.adhoc.2026.104291_b26","doi-asserted-by":"crossref","DOI":"10.1016\/j.neunet.2025.108267","article-title":"Multi-teacher knowledge distillation framework for lightweight anomaly detection","volume":"195","author":"Yousefimehr","year":"2026","journal-title":"Neural Netw."},{"key":"10.1016\/j.adhoc.2026.104291_b27","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2025.104417","article-title":"Transformer-based knowledge distillation for explainable intrusion detection system","volume":"154","author":"Al-Nomasy","year":"2025","journal-title":"Comput. Secur."},{"key":"10.1016\/j.adhoc.2026.104291_b28","series-title":"Network in network","author":"Lin","year":"2014"},{"key":"10.1016\/j.adhoc.2026.104291_b29","doi-asserted-by":"crossref","DOI":"10.1016\/j.neucom.2024.128998","article-title":"Depth-wise convolutions in vision transformers for efficient training on small datasets","volume":"617","author":"Zhang","year":"2025","journal-title":"Neurocomputing"},{"issue":"1","key":"10.1016\/j.adhoc.2026.104291_b30","doi-asserted-by":"crossref","first-page":"485","DOI":"10.1109\/JIOT.2021.3085194","article-title":"ToN_IoT: The role of heterogeneity and the need for standardization of features and attack types in IoT network intrusion data sets","volume":"9","author":"Booij","year":"2022","journal-title":"IEEE Internet Things J."},{"key":"10.1016\/j.adhoc.2026.104291_b31","doi-asserted-by":"crossref","DOI":"10.1016\/j.iot.2024.101209","article-title":"CICIoV2024: Advancing realistic IDS approaches against DoS and spoofing attack in IoV CAN bus","volume":"26","author":"Neto","year":"2024","journal-title":"Internet Things"},{"key":"10.1016\/j.adhoc.2026.104291_b32","doi-asserted-by":"crossref","first-page":"40281","DOI":"10.1109\/ACCESS.2022.3165809","article-title":"Edge-IIoTset: A new comprehensive realistic cyber security dataset of IoT and IIoT applications for centralized and federated learning","volume":"10","author":"Ferrag","year":"2022","journal-title":"IEEE Access"},{"issue":"5","key":"10.1016\/j.adhoc.2026.104291_b33","doi-asserted-by":"crossref","first-page":"3962","DOI":"10.1109\/JIOT.2021.3102056","article-title":"X-IIoTID: A connectivity-agnostic and device-agnostic intrusion data set for industrial internet of things","volume":"9","author":"Al-Hawawreh","year":"2022","journal-title":"IEEE Internet Things J."},{"key":"10.1016\/j.adhoc.2026.104291_b34","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2025.111963","article-title":"CAN-BiGRUBERT: Unveiling automotive vehicle intruders by profiling and characterizing anomalies in controller area network","volume":"276","author":"Sharmin","year":"2026","journal-title":"Comput. Netw."},{"key":"10.1016\/j.adhoc.2026.104291_b35","doi-asserted-by":"crossref","first-page":"103","DOI":"10.1016\/j.aej.2025.06.015","article-title":"Leveraging ensemble learning with metaheuristic optimization algorithms for an intelligent cyberattack defense framework in an IoT environment","volume":"129","author":"Alkahtani","year":"2025","journal-title":"Alex. Eng. J."},{"issue":"16","key":"10.1016\/j.adhoc.2026.104291_b36","doi-asserted-by":"crossref","first-page":"26866","DOI":"10.1109\/JIOT.2023.3288544","article-title":"An intrusion detection system for edge-envisioned smart agriculture in extreme environment","volume":"11","author":"Javeed","year":"2024","journal-title":"IEEE Internet Things J."},{"key":"10.1016\/j.adhoc.2026.104291_b37","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2025.104393","article-title":"Multi-strategy RIME optimization algorithm for feature selection of network intrusion detection","volume":"153","author":"Wang","year":"2025","journal-title":"Comput. Secur."},{"key":"10.1016\/j.adhoc.2026.104291_b38","series-title":"2024 International Conference on IoT Based Control Networks and Intelligent Systems","first-page":"368","article-title":"Anomaly detection in IoV can bus traffic using variational autoencoder-LSTM with attention mechanism","author":"C","year":"2024"},{"key":"10.1016\/j.adhoc.2026.104291_b39","doi-asserted-by":"crossref","DOI":"10.1016\/j.jnca.2025.104389","article-title":"SIoV-IDS: SDN-enabled zero-trust framework for explainable intrusion detection in IoVs using variational autoencoders and EX-LSTM","volume":"245","author":"Laghari","year":"2026","journal-title":"J. Netw. Comput. Appl."},{"key":"10.1016\/j.adhoc.2026.104291_b40","doi-asserted-by":"crossref","DOI":"10.1016\/j.jnca.2024.103888","article-title":"Digital twin-driven secured edge-private cloud Industrial Internet of Things (IIoT) framework","volume":"226","author":"Al-Hawawreh","year":"2024","journal-title":"J. Netw. Comput. Appl."},{"key":"10.1016\/j.adhoc.2026.104291_b41","doi-asserted-by":"crossref","DOI":"10.1016\/j.future.2025.108296","article-title":"Knowledge distillation-based multi-optimization intrusion detection system","volume":"180","author":"Wang","year":"2026","journal-title":"Future Gener. Comput. Syst."},{"key":"10.1016\/j.adhoc.2026.104291_b42","doi-asserted-by":"crossref","DOI":"10.1016\/j.iot.2025.101597","article-title":"Memory feedback transformer based intrusion detection system for IoMT healthcare networks","volume":"32","author":"Shaikh","year":"2025","journal-title":"Internet Things"},{"key":"10.1016\/j.adhoc.2026.104291_b43","article-title":"A multilayered deep learning framework for cyber attack detection and mitigation in a heterogeneous IIoT ecosystem","volume":"96","author":"Iqbal","year":"2026","journal-title":"J. Inf. Secur. Appl."}],"container-title":["Ad Hoc Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1570870526001575?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1570870526001575?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,5,15]],"date-time":"2026-05-15T03:05:55Z","timestamp":1778814355000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S1570870526001575"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,9]]},"references-count":43,"alternative-id":["S1570870526001575"],"URL":"https:\/\/doi.org\/10.1016\/j.adhoc.2026.104291","relation":{},"ISSN":["1570-8705"],"issn-type":[{"value":"1570-8705","type":"print"}],"subject":[],"published":{"date-parts":[[2026,9]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"NINMix-KD: Statistical moment matching knowledge distillation for edge resource-constrained network intrusion detection","name":"articletitle","label":"Article Title"},{"value":"Ad Hoc Networks","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.adhoc.2026.104291","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier B.V. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"104291"}}