STUDY / 02 · Demo ready
Attention-QELM-GWO IIoT lab
Independent implementation of an attention encoder with a fixed-weight extreme learning machine head and grey wolf hyperparameter search for IIoT intrusion detection, with a fidelity audit.
What decision is supported
Whether a network flow on an industrial IoT segment is normal traffic or one of fourteen attack classes, with particular attention to the rarest class, so that a security operator can prioritise alerts.
Who uses it
A security operations analyst reviewing alerts from an industrial network, and a researcher checking whether the published method can be re-derived from its description.
What data enters
Flow-level feature vectors. The published study used the Edge-IIoTset benchmark with 1,909,671 processed records, 15 classes and 48 retained features under a stratified 80/20 split. This repository ships only an authored synthetic fixture with the same shape.
What is computed
A learned feature embedding passed through multi-head attention, then a fixed random hidden layer whose weights use a trigonometric initialisation, then output weights solved in closed form by regularised least squares. A grey wolf search runs offline over hidden width, layer count, activation, regularisation and initialisation angle using 5-fold cross-validated macro-F1 on the training partition.
What action is suggested
A class label and a per-class score for each flow; flows scored as rare attacks are listed first for operator review. The lab makes no claim about deployment on live traffic.
What evidence supports it
| Metric | Dataset | Slice | Value | Label | Source |
|---|---|---|---|---|---|
| Accuracy | Edge-IIoTset | binary, held-out 20% | 0.995 | paper-reported | Table 6 |
| F1 | Edge-IIoTset | binary, held-out 20% | 0.994 | paper-reported | Table 6 |
| Accuracy | Edge-IIoTset | 15-class, held-out 20% | 0.989 | paper-reported | Table 7 |
| Macro-F1 | Edge-IIoTset | 15-class, held-out 20% | 0.986 | paper-reported | Table 7 |
| F1 (MITM class) | Edge-IIoTset | 15-class, held-out 20% | 0.942 | paper-reported | Table 8 |
All values are paper-reported. The quantum-inspired component is a classical trigonometric random-feature initialisation; no quantum hardware is involved and no quantum advantage is claimed by this account.
What fails or is uncertain
- The published encoder describes a 64-dimensional bottleneck reshaped into 8 tokens of 32 dimensions, which does not reshape; the reimplementation adds an explicit expansion and records this in its ambiguity log.
- The paper describes a single hidden layer in prose and a three-layer configuration in its final settings; the repository implements both and states which one each demo run uses.
- The regularisation term named L1 in the source enters the closed-form solution as a second ridge term; the repository keeps the paper's name and documents the discrepancy.
- The stratified random split does not respect time or device grouping, so shortcut features and near-duplicate flows are not ruled out by the published protocol.
- Two different Friedman test statistics appear in the source for the same comparison; neither is reproduced here.