Towards Local Neuro-Symbolic AI in Network Intrusion Detection Systems
R. Saad (TU Delft - Electrical Engineering, Mathematics and Computer Science)
F.A. Kuipers – Mentor (TU Delft - Electrical Engineering, Mathematics and Computer Science)
A. Agiollo – Mentor (TU Delft - Electrical Engineering, Mathematics and Computer Science)
E. Bardhi – Mentor (TU Delft - Electrical Engineering, Mathematics and Computer Science)
S.E. Verwer – Graduation committee member (TU Delft - Electrical Engineering, Mathematics and Computer Science)
More Info
expand_more
Other than for strictly personal use, it is not permitted to download, forward or distribute the text or part of it, without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license such as Creative Commons.
Abstract
Network intrusion detection systems face demanding and often conflicting requirements: they must learn from the limited labelled attack data available in practice, maintain low false-alarm rates, remain interpretable enough for analysts to trust their alerts, and stay robust when their inputs are noisy or adversarially perturbed. Purely neural detectors rarely satisfy these requirements at once, while signature-based systems cannot detect behaviour they were not designed to recognise. This thesis investigates whether a neuro-symbolic approach can address these limitations jointly. Built on the neural probabilistic logic programming framework DeepProbLog, the proposed system couples a neural classifier with automatically mined symbolic rules within a single end-to-end differentiable model, so that symbolic reasoning informs learning, inference, and explanation. It is realised as packet-level, flow-level, and hybrid detectors and evaluated on several public intrusion detection datasets against neural, symbolic-only, and signature baselines. The results show that incorporating symbolic knowledge improves detection performance and reduces false alarms, most notably when labelled data is scarce, while the gain narrows once data is plentiful. The mined rules transfer across networks for attacks whose behaviour is defined broadly within the symbolic knowledge base, once their thresholds are calibrated to the target environment's own benign traffic. The coupling between the neural and symbolic components further acts as a configurable trade-off between clean-traffic precision and robustness under noise and adversarial perturbation. Finally, the symbolic layer produces faithful and stable explanations aligned with documented attack techniques, at a computational cost suited to practical deployment. Overall, this thesis demonstrates that integrating symbolic reasoning throughout a neural detection pipeline provides an effective and interpretable framework for network intrusion detection.