arXiv cs.AIOctober 7, 2026
Multi-Level Distributional Entropy from Flow Summary Statistics for Explainable Network Intrusion Detection
Excerpt
arXiv:2606.29797v2 Announce Type: replace-cross Abstract: Machine learning network intrusion detection systems (IDS) operate on aggregate flow statistics that discard the distributional structure of traffic, and although information-theoretic measures capture that structure, established entropy estimators require raw packet sequences that pre-aggregated flow datasets do not contain. No prior method derives entropy from the summary statistics those records already hold. We introduce Multi-Level D