<p>The rapid expansion of Internet of Things (IoT) technologies has significantly increased the digital attack surface, exposing modern networks to sophisticated cyber threats, particularly zero-day attacks that exploit previously undisclosed vulnerabilities. Conventional intrusion detection systems (IDSs), especially signature-based approaches, rely heavily on predefined attack patterns and large labeled datasets, which limits their effectiveness in identifying emerging and previously unseen attacks. To address this limitation, meta-learning has recently emerged as a promising paradigm for enabling intrusion detection under data-scarce conditions. However, the comparative evaluation of gradient-based and metric-based meta-learning approaches remains relatively underexplored in the domain of intrusion detection. In this study, the potential of meta-learning for zero-day intrusion detection is explored through the evaluation of two representative strategies within a few-shot learning framework: a gradient-based approach based on Model-Agnostic Meta-Learning (MAML), which enables rapid adaptation to new attack types, and a metric-based approach using Prototypical Networks, in which classification is performed within a learned embedding space. For additional comparative analysis, a Siamese network-based Fully Connected Network (FC-Net) is implemented as a baseline model. The framework evaluation is conducted using three diverse and realistic benchmark datasets, including CICIDS2017, CICIoT2023, and an augmented CIC-UNSW-NB15 dataset. Zero-day attack scenarios are simulated under multiclass classification settings to reflect practical deployment environments. Experimental results demonstrate that the MAML-based model consistently achieves superior performance across all datasets, obtaining 96.67% accuracy and 97.54% recall on CICIDS2017, 92.87% accuracy and 92.99% recall on CICIoT2023, and 83.20% accuracy and 83.50% recall on CIC-UNSW-NB15. These findings highlight the effectiveness of gradient-based meta-learning for rapid adaptation to previously unseen attacks and demonstrate its potential for developing intelligent IDSs capable of addressing evolving zero-day threats across heterogeneous network environments.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Evaluating meta-learning strategies for zero-day intrusion detection under data scarcity

  • Nouman Ijaz,
  • Sana Ullah Jan,
  • Insoo Koo

摘要

The rapid expansion of Internet of Things (IoT) technologies has significantly increased the digital attack surface, exposing modern networks to sophisticated cyber threats, particularly zero-day attacks that exploit previously undisclosed vulnerabilities. Conventional intrusion detection systems (IDSs), especially signature-based approaches, rely heavily on predefined attack patterns and large labeled datasets, which limits their effectiveness in identifying emerging and previously unseen attacks. To address this limitation, meta-learning has recently emerged as a promising paradigm for enabling intrusion detection under data-scarce conditions. However, the comparative evaluation of gradient-based and metric-based meta-learning approaches remains relatively underexplored in the domain of intrusion detection. In this study, the potential of meta-learning for zero-day intrusion detection is explored through the evaluation of two representative strategies within a few-shot learning framework: a gradient-based approach based on Model-Agnostic Meta-Learning (MAML), which enables rapid adaptation to new attack types, and a metric-based approach using Prototypical Networks, in which classification is performed within a learned embedding space. For additional comparative analysis, a Siamese network-based Fully Connected Network (FC-Net) is implemented as a baseline model. The framework evaluation is conducted using three diverse and realistic benchmark datasets, including CICIDS2017, CICIoT2023, and an augmented CIC-UNSW-NB15 dataset. Zero-day attack scenarios are simulated under multiclass classification settings to reflect practical deployment environments. Experimental results demonstrate that the MAML-based model consistently achieves superior performance across all datasets, obtaining 96.67% accuracy and 97.54% recall on CICIDS2017, 92.87% accuracy and 92.99% recall on CICIoT2023, and 83.20% accuracy and 83.50% recall on CIC-UNSW-NB15. These findings highlight the effectiveness of gradient-based meta-learning for rapid adaptation to previously unseen attacks and demonstrate its potential for developing intelligent IDSs capable of addressing evolving zero-day threats across heterogeneous network environments.