TY - CHAP
T1 - Adaptive and uncertainty-aware intrusion detection with hybrid meta-learning under proxy-adversarial exposure
AU - Gnanaratna, Kulanika
AU - Nebel, Jean-Christophe
AU - Rahman, Farzana
AU - Omego, Obinna
PY - 2026/7/20
Y1 - 2026/7/20
N2 - Enterprise communication networks face adaptive and non-stationary cyber threats that can evade conventional intrusion detection systems (IDS). Static deep learning models achieve high benchmark accuracy but degrade under distribution shifts and adversarial exposure. We propose an uncertainty-aware IDS framework for flow-based monitoring that integrates multi-agent reinforcement learning (MARL), hybrid statistical–neural meta-learning, and explicit uncertainty quantification. An adaptive proxy adversary, a synthetic feature-space agent, co-evolves with the defender in a staged curriculum to generate challenging scenarios, without requiring fully realistic attack behaviour. When the defender’s confidence falls below a calibrated threshold, flows are deferred to a prototype-based meta-learner that performs few-shot adaptation to emerging attack patterns. A dedicated uncertainty estimator regulates deferral frequency to meet real-time constraints. Experiments on CIC-IDS2017 and CSE-CIC-IDS2018 show improved robustness under proxy-adversarial exposure and cross-dataset distribution shifts. While peak accuracy is slightly lower than static deep models, the framework achieves greater resilience, interpretable decision support, and millisecond-level latency, demonstrating practical readiness for deployment in enterprise networks.
AB - Enterprise communication networks face adaptive and non-stationary cyber threats that can evade conventional intrusion detection systems (IDS). Static deep learning models achieve high benchmark accuracy but degrade under distribution shifts and adversarial exposure. We propose an uncertainty-aware IDS framework for flow-based monitoring that integrates multi-agent reinforcement learning (MARL), hybrid statistical–neural meta-learning, and explicit uncertainty quantification. An adaptive proxy adversary, a synthetic feature-space agent, co-evolves with the defender in a staged curriculum to generate challenging scenarios, without requiring fully realistic attack behaviour. When the defender’s confidence falls below a calibrated threshold, flows are deferred to a prototype-based meta-learner that performs few-shot adaptation to emerging attack patterns. A dedicated uncertainty estimator regulates deferral frequency to meet real-time constraints. Experiments on CIC-IDS2017 and CSE-CIC-IDS2018 show improved robustness under proxy-adversarial exposure and cross-dataset distribution shifts. While peak accuracy is slightly lower than static deep models, the framework achieves greater resilience, interpretable decision support, and millisecond-level latency, demonstrating practical readiness for deployment in enterprise networks.
U2 - 10.1007/978-3-032-32767-3_4
DO - 10.1007/978-3-032-32767-3_4
M3 - Chapter
VL - Part II
T3 - Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering
SP - 74
EP - 88
BT - Security and Privacy in Communication Networks
PB - Springer
CY - Cham
T2 - 22nd EAI International Conference
Y2 - 21 July 2026 through 24 July 2026
ER -