{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,26]],"date-time":"2026-06-26T14:45:51Z","timestamp":1782485151123,"version":"3.54.5"},"reference-count":31,"publisher":"Springer Science and Business Media LLC","issue":"5","license":[{"start":{"date-parts":[[2026,3,25]],"date-time":"2026-03-25T00:00:00Z","timestamp":1774396800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2026,6,26]],"date-time":"2026-06-26T00:00:00Z","timestamp":1782432000000},"content-version":"vor","delay-in-days":93,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J. King Saud Univ. Comput. Inf. Sci."],"published-print":{"date-parts":[[2026,7]]},"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>The widespread deployment of IoT and heterogeneous networks poses significant challenges to traditional Network Intrusion Detection Systems (NIDS), especially in terms of cross-domain generalization and computational efficiency. To address these issues, we propose QuCAD-IDS, a lightweight cross-domain intrusion detection framework that integrates hierarchical contrastive autoencoding and queue-based adaptive distillation. First, a teacher model (HiMSR-CAE) is trained on a source domain using both reconstruction and attack-aware contrastive losses to learn transferable feature representations. Then, a queue-based contrastive distillation mechanism (QuCAD) transfers the structural knowledge of the teacher\u2019s embedding space to a compact GhostNet student network. Finally, Maximum Mean Discrepancy (MMD) alignment and target-domain fine-tuning adapt the model to heterogeneous target domains. Extensive experiments on the UNSW-NB15, NSL-KDD, and CIC-IDS2017 datasets show that QuCAD-IDS achieves detection accuracy (e.g., 99.70% F1 on NSL-KDD multi-class) and cross-domain adaptability, while reducing model parameters by \u00a098% and computational cost by two orders of magnitude. This work provides a practical, lightweight solution for deploying effective NIDS in edge and IoT environments.<\/jats:p>","DOI":"10.1007\/s44443-026-00688-5","type":"journal-article","created":{"date-parts":[[2026,3,25]],"date-time":"2026-03-25T05:15:24Z","timestamp":1774415724000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["QuCAD\u2013IDS: cross\u2013domain network intrusion detection via hierarchical contrastive autoencoding and queue-based adaptive distillation"],"prefix":"10.1007","volume":"38","author":[{"given":"Mingqi","family":"Wang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yu","family":"Yang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jinliang","family":"Yuan","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,3,25]]},"reference":[{"issue":"2","key":"688_CR1","doi-asserted-by":"publisher","first-page":"21263","DOI":"10.48084\/etasr.10128","volume":"15","author":"MA Ahmed","year":"2025","unstructured":"Ahmed MA, Alnatheer S (2025) Intrusion detection in a digital twin-enabled secure industrial internet of things environment for industrial sustainability. Eng Technol Appl Sci Res 15(2):21263\u201321269. https:\/\/doi.org\/10.48084\/etasr.10128","journal-title":"Eng Technol Appl Sci Res"},{"issue":"5","key":"688_CR2","doi-asserted-by":"publisher","first-page":"6062","DOI":"10.1109\/JIOT.2025.3525494","volume":"12","author":"UC Akuthota","year":"2025","unstructured":"Akuthota UC, Bhargava L (2025) Transformer-based intrusion detection for iot networks. IEEE Internet Things J 12(5):6062\u20136067. https:\/\/doi.org\/10.1109\/JIOT.2025.3525494","journal-title":"IEEE Internet Things J"},{"key":"688_CR3","doi-asserted-by":"publisher","unstructured":"Azimjonov J, Kim T (2023) Stochastic gradient descent classifier-based lightweight intrusion detection systems using the most efficient feature subsets of datasets. SSRN Electron J. https:\/\/doi.org\/10.2139\/ssrn.4378339","DOI":"10.2139\/ssrn.4378339"},{"key":"688_CR4","doi-asserted-by":"publisher","first-page":"107064","DOI":"10.1016\/j.neunet.2024.107064","volume":"184","author":"S Cai","year":"2025","unstructured":"Cai S, Zhao Y, Lyu J, Wang S, Hu Y, Cheng M, Zhang G (2025) Ddp-dar: Network intrusion detection based on denoising diffusion probabilistic model and dual-attention residual network. Neural Netw 184:107064. https:\/\/doi.org\/10.1016\/j.neunet.2024.107064","journal-title":"Neural Netw"},{"issue":"10","key":"688_CR5","doi-asserted-by":"publisher","first-page":"2617","DOI":"10.1016\/j.cor.2004.03.019","volume":"32","author":"W-H Chen","year":"2005","unstructured":"Chen W-H, Hsu S-H, Shen H-P (2005) Application of svm and ann for intrusion detection. Comput Oper Res 32(10):2617\u20132634. https:\/\/doi.org\/10.1016\/j.cor.2004.03.019","journal-title":"Comput Oper Res"},{"issue":"9","key":"688_CR6","doi-asserted-by":"publisher","first-page":"5597","DOI":"10.1007\/s11227-019-02805-w","volume":"75","author":"H Choi","year":"2019","unstructured":"Choi H, Kim M, Lee G (2019) Kim W Unsupervised learning approach for network intrusion detection system using autoencoders. J Supercomput 75(9):5597\u20135621. https:\/\/doi.org\/10.1007\/s11227-019-02805-w","journal-title":"J Supercomput"},{"key":"688_CR7","doi-asserted-by":"publisher","first-page":"123027","DOI":"10.1016\/j.eswa.2023.123027","volume":"245","author":"R Devendiran","year":"2024","unstructured":"Devendiran R, Turukmane AV (2024) Dugat-lstm: Deep learning based network intrusion detection system using chaotic optimization strategy. Expert Syst Appl 245:123027. https:\/\/doi.org\/10.1016\/j.eswa.2023.123027","journal-title":"Expert Syst Appl"},{"key":"688_CR8","doi-asserted-by":"publisher","first-page":"58851","DOI":"10.1109\/ACCESS.2024.3389096","volume":"12","author":"S Elsayed","year":"2024","unstructured":"Elsayed S, Mohamed K (2024) Madkour MA A comparative study of using deep learning algorithms in network intrusion detection. IEEE Access 12:58851\u201358870. https:\/\/doi.org\/10.1109\/ACCESS.2024.3389096","journal-title":"IEEE Access"},{"key":"688_CR9","doi-asserted-by":"publisher","first-page":"3939895","DOI":"10.1155\/2023\/3939895","volume":"2023","author":"T Gaber","year":"2023","unstructured":"Gaber T, Awotunde JB, Folorunso SO, Ajagbe SA, Eldesouky E (2023) Industrial internet of things intrusion detection method using machine learning and optimization techniques. Wireless Commun Mobile Comput 2023:3939895. https:\/\/doi.org\/10.1155\/2023\/3939895","journal-title":"Wireless Commun Mobile Comput"},{"issue":"17","key":"688_CR10","doi-asserted-by":"publisher","first-page":"28566","DOI":"10.1109\/JIOT.2024.3403650","volume":"11","author":"Y Huo","year":"2024","unstructured":"Huo Y, Liang W, Chen J, Zhuang S (2024) Sun J Lightguard: A lightweight malicious traffic detection method for internet of things. IEEE Internet Things J 11(17):28566\u201328577. https:\/\/doi.org\/10.1109\/JIOT.2024.3403650","journal-title":"IEEE Internet Things J"},{"key":"688_CR11","doi-asserted-by":"publisher","first-page":"110626","DOI":"10.1016\/j.knosys.2023.110626","volume":"273","author":"S Layeghy","year":"2023","unstructured":"Layeghy S, Baktashmotlagh M (2023) Portmann M Di-nids: Domain invariant network intrusion detection system. Knowl-Based Syst 273:110626. https:\/\/doi.org\/10.1016\/j.knosys.2023.110626","journal-title":"Knowl-Based Syst"},{"key":"688_CR12","doi-asserted-by":"publisher","first-page":"124822","DOI":"10.1016\/j.eswa.2024.124822","volume":"257","author":"Z Li","year":"2024","unstructured":"Li Z (2024) Yao W A two stage lightweight approach for intrusion detection in internet of things. Expert Syst Appl 257:124822. https:\/\/doi.org\/10.1016\/j.eswa.2024.124822","journal-title":"Expert Syst Appl"},{"key":"688_CR13","doi-asserted-by":"publisher","unstructured":"Li J, Fang F, Mei K, Zhang G (2018) Multi-scale residual network for image super-resolution. In: Proceedings of the European Conference on Computer Vision (ECCV), pp 517\u2013532. https:\/\/doi.org\/10.1007\/978-3-030-01234-2-32","DOI":"10.1007\/978-3-030-01234-2-32"},{"key":"688_CR14","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2025.3545363","author":"K-D Lu","year":"2025","unstructured":"Lu K-D, Huang J-C, Zeng G-Q, Chen M-R, Geng G-G (2025) Weng J Multi-objective discrete extremal optimization of variable-length blocks-based cnn by joint nas and hpo for intrusion detection in iiot. IEEE Trans Dependable Secure Comput. https:\/\/doi.org\/10.1109\/TDSC.2025.3545363","journal-title":"IEEE Trans Dependable Secure Comput"},{"key":"688_CR15","doi-asserted-by":"publisher","unstructured":"Moustafa N, Slay J (2015) Unsw-nb15: a comprehensive data set for network intrusion detection systems (unsw-nb15 network data set). In: 2015 Military Communications and Information Systems Conference (MilCIS), pp 1\u20136. https:\/\/doi.org\/10.1109\/MilCIS.2015.7348942","DOI":"10.1109\/MilCIS.2015.7348942"},{"key":"688_CR16","doi-asserted-by":"crossref","unstructured":"Ressi D, Rossi S, Romanello R, Piazza C (2024) Ai-enhanced blockchain technology: A review of advancements and opportunities. J Netw Comput Appl (May) 225","DOI":"10.1016\/j.jnca.2024.103858"},{"issue":"5","key":"688_CR17","doi-asserted-by":"publisher","first-page":"5809","DOI":"10.1109\/TNSM.2024.3414305","volume":"21","author":"IM Sayem","year":"2024","unstructured":"Sayem IM, Sayed MI (2024) Saha S, Haque A Enids: A deep learning-based ensemble framework for network intrusion detection systems. IEEE Trans Netw Serv Manage 21(5):5809\u20135825. https:\/\/doi.org\/10.1109\/TNSM.2024.3414305","journal-title":"IEEE Trans Netw Serv Manage"},{"issue":"2018","key":"688_CR18","first-page":"108","volume":"1","author":"I Sharafaldin","year":"2018","unstructured":"Sharafaldin I, Lashkari AH, Ghorbani AA et al (2018) Toward generating a new intrusion detection dataset and intrusion traffic characterization. ICISSp 1(2018):108\u2013116","journal-title":"ICISSp"},{"issue":"1","key":"688_CR19","doi-asserted-by":"publisher","first-page":"33","DOI":"10.1186\/s40537-024-00886-w","volume":"11","author":"MA Talukder","year":"2024","unstructured":"Talukder MA, Islam MM, Uddin MA, Hasan KF, Sharmin S, Alyami SA, Moni MA (2024) Machine learning-based network intrusion detection for big and imbalanced data using oversampling, stacking feature embedding and feature extraction. J Big Data 11(1):33. https:\/\/doi.org\/10.1186\/s40537-024-00886-w","journal-title":"J Big Data"},{"key":"688_CR20","doi-asserted-by":"crossref","unstructured":"Tavallaee M, Bagheri E, Lu W, Ghorbani AA (2009) A detailed analysis of the kdd cup 99 data set. In: 2009 IEEE Symposium on computational intelligence for security and defense applications, pp 1\u20136. Ieee","DOI":"10.1109\/CISDA.2009.5356528"},{"key":"688_CR21","doi-asserted-by":"publisher","unstructured":"Wang L-H, Dai Q, Du T, Chen L-f (2024) Lightweight intrusion detection model based on cnn and knowledge distillation. Appl Soft Comput 165:112118. https:\/\/doi.org\/10.1016\/j.asoc.2024.112118","DOI":"10.1016\/j.asoc.2024.112118"},{"key":"688_CR22","doi-asserted-by":"publisher","first-page":"117671","DOI":"10.1016\/j.eswa.2022.117671","volume":"206","author":"Z Wang","year":"2022","unstructured":"Wang Z, Li Z, He D, Chan S (2022) A lightweight approach for network intrusion detection in industrial cyber-physical systems based on knowledge distillation and deep metric learning. Expert Syst Appl 206:117671. https:\/\/doi.org\/10.1016\/j.eswa.2022.117671","journal-title":"Expert Syst Appl"},{"issue":"11","key":"688_CR23","doi-asserted-by":"publisher","first-page":"16912","DOI":"10.1109\/JIOT.2025.3533092","volume":"12","author":"Z Wang","year":"2025","unstructured":"Wang Z, Zhou R, Yang S, He D (2025) Chan S A novel lightweight iot intrusion detection model based on self-knowledge distillation. IEEE Internet Things J 12(11):16912\u201316930. https:\/\/doi.org\/10.1109\/JIOT.2025.3533092","journal-title":"IEEE Internet Things J"},{"issue":"1","key":"688_CR24","doi-asserted-by":"publisher","first-page":"125","DOI":"10.1186\/s13677-024-00678-w","volume":"13","author":"C Wu","year":"2024","unstructured":"Wu C, Liu X, Ding K, Xin B, Lu J, Liu J (2024) Huang C Attack detection model for bcot based on contrastive variational autoencoder and metric learning. J Cloud Comput 13(1):125. https:\/\/doi.org\/10.1186\/s13677-024-00678-w","journal-title":"J Cloud Comput"},{"key":"688_CR25","doi-asserted-by":"publisher","first-page":"126632","DOI":"10.1016\/j.eswa.2024.126632","volume":"271","author":"X Wu","year":"2025","unstructured":"Wu X, Jin Z, Chen X, Zhou J (2025) Liu K Boosting incremental intrusion detection system with adversarial samples. Expert Syst Appl 271:126632. https:\/\/doi.org\/10.1016\/j.eswa.2024.126632","journal-title":"Expert Syst Appl"},{"key":"688_CR26","doi-asserted-by":"publisher","first-page":"110495","DOI":"10.1016\/j.comnet.2024.110495","volume":"248","author":"R Xu","year":"2024","unstructured":"Xu R, Wu G, Wang W, Gao X, He A, Zhang Z (2024) Applying self-supervised learning to network intrusion detection for network flows with graph neural network. Comput Netw 248:110495. https:\/\/doi.org\/10.1016\/j.comnet.2024.110495","journal-title":"Comput Netw"},{"key":"688_CR27","doi-asserted-by":"publisher","first-page":"112473","DOI":"10.1016\/j.knosys.2024.112473","volume":"304","author":"T Yang","year":"2024","unstructured":"Yang T, Chen J, Deng H, He B (2024) A lightweight intrusion detection algorithm for iot based on data purification and a separable convolution improved cnn. Knowl-Based Syst 304:112473. https:\/\/doi.org\/10.1016\/j.knosys.2024.112473","journal-title":"Knowl-Based Syst"},{"key":"688_CR28","doi-asserted-by":"publisher","first-page":"21954","DOI":"10.1109\/ACCESS.2017.2762418","volume":"5","author":"C-L Yin","year":"2017","unstructured":"Yin C-L, Zhu Y-F, Fei J-L, He X-Z (2017) A deep learning approach for intrusion detection using recurrent neural networks. IEEE Access 5:21954\u201321961. https:\/\/doi.org\/10.1109\/ACCESS.2017.2762418","journal-title":"IEEE Access"},{"key":"688_CR29","doi-asserted-by":"publisher","first-page":"125860","DOI":"10.1016\/j.eswa.2024.125860","volume":"265","author":"H Yu","year":"2025","unstructured":"Yu H, Zhang W, Kang C, Xue Y (2025) A feature selection algorithm for intrusion detection system based on the enhanced heuristic optimizer. Expert Syst Appl 265:125860. https:\/\/doi.org\/10.1016\/j.eswa.2024.125860","journal-title":"Expert Syst Appl"},{"issue":"4","key":"688_CR30","doi-asserted-by":"publisher","first-page":"4232","DOI":"10.1109\/TNSM.2022.3208940","volume":"19","author":"Y Yue","year":"2022","unstructured":"Yue Y, Chen X, Han Z, Zeng X (2022) Zhu Y Contrastive learning enhanced intrusion detection. IEEE Trans Netw Serv Manage 19(4):4232\u20134247. https:\/\/doi.org\/10.1109\/TNSM.2022.3208940","journal-title":"IEEE Trans Netw Serv Manage"},{"key":"688_CR31","doi-asserted-by":"publisher","unstructured":"Zhang X, Zhao R, Jiang Z, Sun Z, Ding Y, Ngai ECH, Yang S-H (2024) Aoc-ids: Autonomous online framework with contrastive learning for intrusion detection. In: IEEE INFOCOM 2024-IEEE conference on computer communications, pp 581\u2013590. https:\/\/doi.org\/10.48550\/arXiv.2402.01807","DOI":"10.48550\/arXiv.2402.01807"}],"container-title":["Journal of King Saud University Computer and Information Sciences"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s44443-026-00688-5","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s44443-026-00688-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s44443-026-00688-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,26]],"date-time":"2026-06-26T13:46:33Z","timestamp":1782481593000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s44443-026-00688-5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,3,25]]},"references-count":31,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2026,7]]}},"alternative-id":["688"],"URL":"https:\/\/doi.org\/10.1007\/s44443-026-00688-5","relation":{},"ISSN":["1319-1578","2213-1248"],"issn-type":[{"value":"1319-1578","type":"print"},{"value":"2213-1248","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,3,25]]},"assertion":[{"value":"20 January 2026","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"18 March 2026","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"25 March 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}},{"value":"This research did not involve human participants, animal subjects, or any private\/sensitive data collection. All experiments were conducted using publicly available benchmark datasets.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethical Approval"}}],"article-number":"266"}}