ADAPT-IDS: An Unsupervised Multi-Metric Framework forReliable Concept Drift Detection and Adaptive Intrusion Detectionin Evolving Network Streams

Read the full article

Listed in

This article is not in any list yet, why not save it to one of your lists.
Log in to save this article

Abstract

Intrusion detection systems (IDSs) deployed in evolving network environments face a persistentchallenge from concept drift, whereby changes in legitimate traffic characteristics and attackbehavior can progressively degrade detection performance. This paper presents ADAPT-IDS, anunsupervised multi-metric framework for concept drift detection and drift-triggered adaptive in-trusion detection in network traffic streams. The proposed framework combines Jensen–Shannondivergence, standardized distributional difference, statistical drift significance, and residualexceedance analysis into a weighted evidence-fusion mechanism. To improve robustness againsttransient fluctuations and isolated statistical anomalies, drift decisions are further regulatedusing minimum-effect constraints and a persistence-based confirmation strategy. Once persistentdrift is confirmed, a limited oracle-labeling mechanism and high-confidence benign sampleselection are used to construct a balanced replay buffer, enabling adaptive IDS retraining whileavoiding continuous manual annotation. The framework is evaluated using a chronologicallyordered network intrusion dataset comprising 2,097,150 instances and 63 numerical features,with 200,000 instances used for initial model development and 1,897,150 instances evaluatedprequentially as a streaming sequence. During evaluation, ADAPT-IDS generated 327 candidatedrift detections, of which 73 satisfied the persistence criterion and triggered adaptive modelupdates. The resulting adaptive IDS achieved 97.46% accuracy, 99.94% precision, 85.88%detection rate, 92.38% F1-score, 92.93% balanced accuracy, and an MCC of 0.912, with afalse-alarm rate of 0.0119%. Only 7.70% of the evaluation-stream instances were subjectedto oracle labeling, indicating the potential of the proposed drift-triggered adaptation strategyto substantially reduce annotation requirements. These results demonstrate the feasibility ofcombining unsupervised multi-metric drift monitoring with label-efficient adaptive retrainingfor intrusion detection under evolving network conditions.

Article activity feed