Continual Learning with Strategic Selection and Forgetting for Network Intrusion Detection
Xinchen Zhang, Running Zhao, Zhihan Jiang, Handi Chen, Yulong Ding, Edith C. H. Ngai, Shuang-Hua Yang
Abstract
Intrusion Detection Systems (IDS) are crucial for safeguarding digital infrastructure. In dynamic network environments, both threat landscapes and normal operational behaviors are constantly changing, resulting in concept drift. While continuous learning mitigates the adverse effects of concept drift, insufficient attention to drift patterns and excessive preservation of outdated knowledge can still hinder the IDS's adaptability. In this paper, we propose SSF (Strategic Selection and Forgetting), a novel continual learning method for IDS, providing continuous model updates with a constantly refreshed memory buffer. Our approach features a strategic sample selection algorithm to select representative new samples and a strategic forgetting mechanism to drop outdated samples. The proposed strategic sample selection algorithm prioritizes new samples that cause the ‘drifted’ pattern, enabling the model to better understand the evolving landscape. Additionally, we introduce strategic forgetting upon detecting significant drift by discarding outdated samples to free up memory, allowing the incorporation of more recent data. SSF captures evolving patterns effectively and ensures the model is aligned with the change of data patterns, significantly enhancing the IDS's adaptability to concept drift. The state-of-the-art performance of SSF on NSL-KDD and UNSW-NB15 datasets demonstrates its superior adaptability to concept drift for network intrusion detection.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7214b4ce-2877-4bab-a8c9-1b13abca7e3aCited by top-tier papers2
- Decompose to Understand, Fuse to Detect: Frequency-Decoupled Anomaly Detection for Encrypted Network TrafficXinglin Lian, Chengtai Cao, Ting Zhong, Yong Wang et al.INFOCOM 2026 · 8 citations
- Navigating the Latent Manifold: Proactive Concept Drift Adaptation for Resilient NIDSChao Zha, Zifeng Kang, Tian Liu, Dakun Shen et al.CCS 2026
Builds on8
- TESSERACT: Eliminating Experimental Bias in Malware Classification across Space and TimeFeargus Pendlebury, Fabio Pierazzi, Roberto Jordaney, Johannes Kinder et al.USENIX Security 2019 · 441 citations
- Throwing Darts in the Dark? Detecting Bots with Limited Data using Neural Data AugmentationSteve T. K. Jan, Qingying Hao, Tianrui Hu, Jiameng Pu et al.S&P 2020 · 88 citations
- FeCo: Boosting Intrusion Detection Capability in IoT Networks via Contrastive LearningNing Wang, Yimin Chen, Yang Hu, Wenjing Lou et al.INFOCOM 2022 · 36 citations
- Self-Evolved Dynamic Expansion Model for Task-Free Continual LearningFei Ye, Adrian G. BorsICCV 2023 · 28 citations
- AOC-IDS: Autonomous Online Framework with Contrastive Learning for Intrusion DetectionXinchen Zhang, Running Zhao, Zhihan Jiang, Zhicong Sun et al.INFOCOM 2024 · 27 citations
Related papers
- Predicting the Susceptibility of Examples to Catastrophic ForgettingGuy Hacohen, Tinne TuytelaarsICML 2025
- Augmented Memory Replay-based Continual Learning Approaches for Network Intrusion DetectionSuresh Kumar Amalapuram, Sumohana S. Channappayya, Bheemarjuna Reddy TammaNeurIPS 2023 · 42 citations
- ReCDA: Concept Drift Adaptation with Representation Enhancement for Network Intrusion DetectionShuo Yang, Xinran Zheng, Jinze Li, Jinfeng Xu et al.KDD 2024 · 9 citations
- SPIDER: A Semi-Supervised Continual Learning-based Network Intrusion Detection SystemSuresh Kumar Amalapuram, Bheemarjuna Reddy Tamma, Sumohana S. ChannappayyaINFOCOM 2024 · 25 citations
- Task-Free Continual Learning via Online Discrepancy Distance LearningFei Ye, Adrian G. BorsNeurIPS 2022 · 43 citations
