ADAPT-IDS: An Unsupervised Multi-Metric Framework forReliable Concept Drift Detection and Adaptive Intrusion Detectionin Evolving Network Streams

This article has 0 evaluations Published on
Read the full article Related papers
This article on Sciety

Abstract

Intrusion detection systems (IDSs) deployed in evolving network environments face a persistentchallenge from concept drift, whereby changes in legitimate traffic characteristics and attackbehavior can progressively degrade detection performance. This paper presents ADAPT-IDS, anunsupervised multi-metric framework for concept drift detection and drift-triggered adaptive in-trusion detection in network traffic streams. The proposed framework combines Jensen–Shannondivergence, standardized distributional difference, statistical drift significance, and residualexceedance analysis into a weighted evidence-fusion mechanism. To improve robustness againsttransient fluctuations and isolated statistical anomalies, drift decisions are further regulatedusing minimum-effect constraints and a persistence-based confirmation strategy. Once persistentdrift is confirmed, a limited oracle-labeling mechanism and high-confidence benign sampleselection are used to construct a balanced replay buffer, enabling adaptive IDS retraining whileavoiding continuous manual annotation. The framework is evaluated using a chronologicallyordered network intrusion dataset comprising 2,097,150 instances and 63 numerical features,with 200,000 instances used for initial model development and 1,897,150 instances evaluatedprequentially as a streaming sequence. During evaluation, ADAPT-IDS generated 327 candidatedrift detections, of which 73 satisfied the persistence criterion and triggered adaptive modelupdates. The resulting adaptive IDS achieved 97.46% accuracy, 99.94% precision, 85.88%detection rate, 92.38% F1-score, 92.93% balanced accuracy, and an MCC of 0.912, with afalse-alarm rate of 0.0119%. Only 7.70% of the evaluation-stream instances were subjectedto oracle labeling, indicating the potential of the proposed drift-triggered adaptation strategyto substantially reduce annotation requirements. These results demonstrate the feasibility ofcombining unsupervised multi-metric drift monitoring with label-efficient adaptive retrainingfor intrusion detection under evolving network conditions.

Related articles

Related articles are currently not available for this article.