CND-IDS: Continual Novelty Detection for Intrusion Detection Systems
Sean Fuhrman, Onat Güngör, Tajana Rosing
Abstract
Intrusion detection systems (IDS) play a crucial role in IoT and network security by monitoring system data and alerting to suspicious activities. Machine learning (ML) has emerged as a promising solution for IDS, offering highly accurate intrusion detection. However, ML-IDS solutions often overlook two critical aspects needed to build reliable systems: continually changing data streams and a lack of attack labels. Streaming network traffic and associated cyber attacks are continually changing, which can degrade the performance of deployed ML models. Labeling attack data, such as zero-day attacks, in real-world intrusion scenarios may not be feasible, making the use of ML solutions that do not rely on attack labels necessary. To address both these challenges, we propose CND-IDS, a continual novelty detection IDS framework which consists of (i) a learning-based feature extractor that continuously updates new feature representations of the system data, and (ii) a novelty detector that identifies new cyber attacks by leveraging principal component analysis (PCA) reconstruction. Our results on realistic intrusion datasets show that CND-IDS achieves up to F-score improvement, and up to improved forward transfer over the SOTA unsupervised continual learning algorithm. Our code is available at https://github.com/Sean-Fuhrman/CND-IDS.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 211fe20c-8da7-4850-b0d8-e8f3530ec541Builds on1
Related papers
- Feature Selection for Network Intrusion DetectionCharles Westphal, Stephen Hailes, Mirco MusolesiKDD 2025 · 3 citations
- AOC-IDS: Autonomous Online Framework with Contrastive Learning for Intrusion DetectionXinchen Zhang, Running Zhao, Zhihan Jiang, Zhicong Sun et al.INFOCOM 2024 · 27 citations
- PANDORA: Lightweight Adversarial Defense for Edge IoT using Uncertainty-Aware Metric LearningAvinash Awasthi, Pritam Vediya, Hemant Miranka, Ramesh Babu Battula et al.NDSS 2026 · 1 citation
- Adaptive Clustering-based Malicious Traffic Classification at the Network EdgeAlec F. Diallo, Paul PatrasINFOCOM 2021 · 64 citations
- Realtime Robust Malicious Traffic Detection via Frequency Domain AnalysisChuanpu Fu, Qi Li, Meng Shen, Ke XuCCS 2021 · 194 citations
