Skip to main navigation Skip to search Skip to main content

Adaptive and uncertainty-aware intrusion detection with hybrid meta-learning under proxy-adversarial exposure

Research output: Chapter in Book/Report/Conference proceedingChapterpeer-review

Abstract

Enterprise communication networks face adaptive and non-stationary cyber threats that can evade conventional intrusion detection systems (IDS). Static deep learning models achieve high benchmark accuracy but degrade under distribution shifts and adversarial exposure. We propose an uncertainty-aware IDS framework for flow-based monitoring that integrates multi-agent reinforcement learning (MARL), hybrid statistical–neural meta-learning, and explicit uncertainty quantification. An adaptive proxy adversary, a synthetic feature-space agent, co-evolves with the defender in a staged curriculum to generate challenging scenarios, without requiring fully realistic attack behaviour. When the defender’s confidence falls below a calibrated threshold, flows are deferred to a prototype-based meta-learner that performs few-shot adaptation to emerging attack patterns. A dedicated uncertainty estimator regulates deferral frequency to meet real-time constraints. Experiments on CIC-IDS2017 and CSE-CIC-IDS2018 show improved robustness under proxy-adversarial exposure and cross-dataset distribution shifts. While peak accuracy is slightly lower than static deep models, the framework achieves greater resilience, interpretable decision support, and millisecond-level latency, demonstrating practical readiness for deployment in enterprise networks.
Original languageEnglish
Title of host publicationSecurity and Privacy in Communication Networks
Subtitle of host publication22nd EAI International Conference, SecureComm 2026, Lancaster, UK, July 21–24, 2026, Proceedings
Place of PublicationCham
PublisherSpringer
Pages74-88
VolumePart II
DOIs
Publication statusE-pub ahead of print - 20 Jul 2026
Event22nd EAI International Conference: SecureComm 2026 - Lancaster, United Kingdom
Duration: 21 Jul 202624 Jul 2026

Publication series

NameLecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering
PublisherSpringer
Volume705
ISSN (Print)1867-8211
ISSN (Electronic)1867-822X

Conference

Conference22nd EAI International Conference
Country/TerritoryUnited Kingdom
CityLancaster
Period21/07/2624/07/26

Fingerprint

Dive into the research topics of 'Adaptive and uncertainty-aware intrusion detection with hybrid meta-learning under proxy-adversarial exposure'. Together they form a unique fingerprint.

Cite this