SPIDER: A Semi-Supervised Continual Learning-based Network Intrusion Detection System
Suresh Kumar Amalapuram, Bheemarjuna Reddy Tamma, Sumohana S. Channappayya
Abstract
Network intrusion detection (NID) aims to identify unusual network traffic patterns (distribution shifts) that require NID systems to evolve continuously. While prior art emphasizes fully supervised annotated data-intensive continual learning methods for NID, semi-supervised continual learning (SSCL) methods require only limited annotated data. However, the inherent class imbalance (CI) in network traffic can significantly impact the performance of SSCL approaches. Previous approaches to tackle CI issues require storing a subset of labeled training samples from all past tasks in the memory for an extended duration, potentially raising privacy concerns. The proposed Semisupervised Privacy-preserving Intrusion detection with Drift-aware continual LEaRning (SPIDER) is a novel method that combines gradient projection memory (GPM) with SSCL to handle CI effectively without the requirement to store labeled samples from all of the previous tasks. We assess SPIDER’s performance against baselines on six intrusion detection benchmarks formed over a short period and the Anoshift benchmark spanning ten years, which includes natural distribution shifts. Additionally, we validate our approach on standard continual learning image classification benchmarks known for frequent distribution shifts compared to NID benchmarks. SPIDER achieves comparable performance to fully supervised and semisupervised baseline methods, while requiring a maximum of 20% annotated data and reducing the total training time by 2X.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 85b501af-2d4c-4dd5-a8ab-1b1baf5bc9f3Related papers
- Augmented Memory Replay-based Continual Learning Approaches for Network Intrusion DetectionSuresh Kumar Amalapuram, Sumohana S. Channappayya, Bheemarjuna Reddy TammaNeurIPS 2023 · 42 citations
- Continual Learning with Strategic Selection and Forgetting for Network Intrusion DetectionXinchen Zhang, Running Zhao, Zhihan Jiang, Handi Chen et al.INFOCOM 2025 · 26 citations
- CND-IDS: Continual Novelty Detection for Intrusion Detection SystemsSean Fuhrman, Onat Güngör, Tajana RosingDAC 2025 · 9 citations
- Quantized Gradient Projection for Memory-Efficient Continual LearningDongjun Kim, Seohyeon Cha, Huancheng Chen, Chaining Wang et al.ICLR 2026
- RECALL: Replay-based Continual Learning in Semantic SegmentationAndrea Maracani, Umberto Michieli, Marco Toldo, Pietro ZanuttighICCV 2021 · 148 citations
