{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,21]],"date-time":"2026-05-21T02:07:14Z","timestamp":1779329234353,"version":"3.51.4"},"reference-count":32,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2026,5,21]],"date-time":"2026-05-21T00:00:00Z","timestamp":1779321600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2026,5,21]],"date-time":"2026-05-21T00:00:00Z","timestamp":1779321600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecurity"],"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>In current research on network intrusion detection systems (IDS), mainstream methods typically rely on large-scale, high-quality labeled datasets to train deep learning models, such as convolutional neural networks (CNNs), recurrent neural networks (RNNs), and their variants. These methods can achieve high detection accuracy and robustness under conditions where sufficient training data is available. However, during actual deployment, especially at the initial emergence of novel attacks or in specific scenarios, it is often difficult to collect sufficient and reliable labeled samples, leading to extremely small-sample conditions. Under extremely small-sample conditions, existing deep learning-based IDS methods experience significant degradation in both detection performance and generalization capability due to scarce training data or insufficient labeling quality. To address this problem, this paper proposes CogAugIDS, a cognitive model data augmentation-based IDS framework. CogAugIDS simulates human learning and decision-making processes to deeply understand and reason about extremely small-sample data, thereby generating more representative and diverse augmented samples. This approach enhances the training and detection performance of deep learning-based IDS methods under extremely small-sample conditions. Experimental results show that, when tested on the UNSW-NB15 dataset with only 10 samples per attack category, CogAugIDS achieves significantly better performance in multi-classification tasks compared to classical deep learning methods (CNN-BiLSTM, 1D-CNN, CNN-LSTM, LSTM). Specifically, CogAugIDS improves the accuracy of multi-classification tasks by approximately 5%\u20137% compared to classical deep learning-based IDS approaches. Furthermore, CogAugIDS demonstrates stronger robustness and generalization ability in resource-constrained environments. It effectively enhances detection accuracy even when faced with a very small number of training samples, and its adaptability to is superior to that of baseline deep learning-based IDS methods. These results validate the superiority of the CogAugIDS framework under extremely small-sample conditions and demonstrate its practical applicability in resource-limited IDS environments.<\/jats:p>","DOI":"10.1186\/s42400-025-00496-w","type":"journal-article","created":{"date-parts":[[2026,5,21]],"date-time":"2026-05-21T02:01:36Z","timestamp":1779328896000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Cogaugids: a cognitive model-based data augmentation framework for intrusion detection under extremely small sample conditions"],"prefix":"10.1186","volume":"9","author":[{"given":"Ruotong","family":"Zhang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaojian","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xuejun","family":"Yu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2026,5,21]]},"reference":[{"key":"496_CR1","volume":"38","author":"HC Altunay","year":"2023","unstructured":"Altunay HC, Albayrak Z (2023) A hybrid cnn+ lstm-based intrusion detection system for industrial iot networks. Eng Sci Technol Int J 38:101322","journal-title":"Eng Sci Technol Int J"},{"key":"496_CR2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cosrev.2024.100645","volume":"53","author":"O Elharrouss","year":"2024","unstructured":"Elharrouss O, Akbari Y, Almadeed N, Al-Maadeed S (2024) Backbones-review: Feature extractor networks for deep learning and deep reinforcement learning approaches in computer vision. Comput Sci Rev 53:100645","journal-title":"Comput Sci Rev"},{"key":"496_CR3","doi-asserted-by":"crossref","unstructured":"Li P, Wang Y, Li Q, Liu Z, Xu K, Ren J, Liu Z, Lin R (2023) Learning from limited heterogeneous training data: Meta-learning for unsupervised zero-day web attack detection across web domains. In Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security, pages 1020\u20131034","DOI":"10.1145\/3576915.3623123"},{"key":"496_CR4","doi-asserted-by":"crossref","unstructured":"Brigato L, Iocchi L (2021) A close look at deep learning with small data. In 2020 25th international conference on pattern recognition (ICPR), pages 2490\u20132497. IEEE","DOI":"10.1109\/ICPR48806.2021.9412492"},{"issue":"3","key":"496_CR5","doi-asserted-by":"publisher","first-page":"198","DOI":"10.1007\/s11063-024-11643-8","volume":"56","author":"J Chen","year":"2024","unstructured":"Chen J, Wu P, Zhang X, Xu R, Liang J (2024) Add-vit: Cnn-transformer hybrid architecture for small data paradigm processing. Neural Process Lett 56(3):198","journal-title":"Neural Process Lett"},{"key":"496_CR6","doi-asserted-by":"crossref","unstructured":"Arsalan M, Mubeen M, Bilal M, Abbasi SF (2024) 1d-cnn-ids: 1d cnn-based intrusion detection system for iiot. In 2024 29th International Conference on Automation and Computing (ICAC), pages 1\u20134. IEEE","DOI":"10.1109\/ICAC61394.2024.10718772"},{"key":"496_CR7","doi-asserted-by":"crossref","unstructured":"Sinha J, Manollas M (2020) Efficient deep cnn-bilstm model for network intrusion detection. In Proceedings of the 2020 3rd International Conference on Artificial Intelligence and Pattern Recognition, pages 223\u2013231","DOI":"10.1145\/3430199.3430224"},{"key":"496_CR8","doi-asserted-by":"publisher","first-page":"62722","DOI":"10.1109\/ACCESS.2022.3176317","volume":"10","author":"I Ullah","year":"2022","unstructured":"Ullah I, Mahmoud QH (2022) Design and development of rnn anomaly detection model for iot networks. IEEE Access 10:62722\u201362750","journal-title":"IEEE Access"},{"issue":"6","key":"496_CR9","doi-asserted-by":"publisher","first-page":"1053","DOI":"10.3390\/electronics13061053","volume":"13","author":"S Yaras","year":"2024","unstructured":"Yaras S, Dener M (2024) Iot-based intrusion detection system using new hybrid deep learning algorithm. Electronics 13(6):1053","journal-title":"Electronics"},{"issue":"1","key":"496_CR10","doi-asserted-by":"publisher","first-page":"121","DOI":"10.1007\/s00779-019-01332-y","volume":"25","author":"J Lee","year":"2021","unstructured":"Lee J, Park K (2021) Gan-based imbalanced data intrusion detection system. Pers Ubiquit Comput 25(1):121\u2013128","journal-title":"Pers Ubiquit Comput"},{"key":"496_CR11","doi-asserted-by":"crossref","unstructured":"Fedoruk O, Klimaszewski K, Ogonowski A, Kruk M (2024) Additional look into gan-based augmentation for deep learning covid-19 image classification. arXiv preprint arXiv:2401.14705","DOI":"10.1063\/5.0203379"},{"key":"496_CR12","doi-asserted-by":"publisher","first-page":"41525","DOI":"10.1109\/ACCESS.2019.2895334","volume":"7","author":"R Vinayakumar","year":"2019","unstructured":"Vinayakumar R, Alazab M, Soman KP, Poornachandran P, Al-Nemrat A, Venkatraman S (2019) Deep learning approach for intelligent intrusion detection system. IEEE access 7:41525\u201341550","journal-title":"IEEE access"},{"key":"496_CR13","unstructured":"Zhu X, Ghahramani Z, Lafferty JD (2003) Semi-supervised learning using gaussian fields and harmonic functions. In Proceedings of the 20th International conference on Machine learning (ICML-03), pages 912\u2013919"},{"key":"496_CR14","unstructured":"Lotfi S, Modirrousta M, Shashaani S, Shoorehdeli MA (2022) Network intrusion detection with limited labeled data using self-supervision. arXiv preprint arXiv:2209.03147"},{"key":"496_CR15","first-page":"9486949","volume":"1","author":"Z Wang","year":"2021","unstructured":"Wang Z, Li Z, Wang J (2021) Li D (2021) Network intrusion detection model based on improved byol self-supervised learning. Security and Commun Networks 1:9486949","journal-title":"Security and Commun Networks"},{"key":"496_CR16","doi-asserted-by":"publisher","first-page":"321","DOI":"10.1613\/jair.953","volume":"16","author":"NV Chawla","year":"2002","unstructured":"Chawla NV, Bowyer KW, Hall LO, Kegelmeyer WP (2002) Smote: synthetic minority over-sampling technique. J Artif Intell Res 16:321\u2013357","journal-title":"J Artif Intell Res"},{"key":"496_CR17","doi-asserted-by":"crossref","unstructured":"He H, Bai Y, Garcia EA, Li S. (2008) Adasyn: Adaptive synthetic sampling approach for imbalanced learning. In 2008 IEEE international joint conference on neural networks (IEEE world congress on computational intelligence), pages 1322\u20131328. Ieee","DOI":"10.1109\/IJCNN.2008.4633969"},{"key":"496_CR18","unstructured":"Kingma DP, Welling M, et al (2013) Auto-encoding variational bayes"},{"key":"496_CR19","first-page":"165","volume-title":"Cognitively-inspired inference for malware task identification","author":"E Nunes","year":"2020","unstructured":"Nunes E, Buto C, Shakarian P, Lebiere C, Bennati S, Thomson R (2020) Cognitively-inspired inference for malware task identification. Social Media Analytics, Open Source Intelligence and Cyber Crime, pp 165\u2013194"},{"issue":"2","key":"496_CR20","doi-asserted-by":"publisher","first-page":"141","DOI":"10.1016\/j.cogsys.2006.07.004","volume":"10","author":"P Langley","year":"2009","unstructured":"Langley P, Laird JE, Rogers S (2009) Cognitive architectures: Research issues and challenges. Cogn Syst Res 10(2):141\u2013160","journal-title":"Cogn Syst Res"},{"key":"496_CR21","doi-asserted-by":"crossref","unstructured":"Thomson R, Cranford E, Somers S, Lebiere C (2024) A novel approach to intrusion detection using a cognitively-inspired algorithm","DOI":"10.24251\/HICSS.2024.116"},{"key":"496_CR22","unstructured":"Lebiere C, Stewart T, West R (2009) Applying cognitive architectures to decision-making: How cognitive theory and the equivalence measure triumphed in the technion prediction tournament. In Proceedings of the Annual Meeting of the Cognitive Science Society, volume\u00a031"},{"key":"496_CR23","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102899","volume":"122","author":"J Yang","year":"2022","unstructured":"Yang J, Li H, Shao S, Zou F, Wu Y (2022) Fs-ids: A framework for intrusion detection based on few-shot learning. Computers & Security 122:102899","journal-title":"Computers & Security"},{"issue":"1","key":"496_CR24","doi-asserted-by":"publisher","first-page":"9848","DOI":"10.1038\/s41598-025-93185-0","volume":"15","author":"C Xu","year":"2025","unstructured":"Xu C, Zhang F, Yang Z, Zhou Z, Zheng Y (2025) A few-shot network intrusion detection method based on mutual centralized learning. Sci Rep 15(1):9848","journal-title":"Sci Rep"},{"issue":"1","key":"496_CR25","doi-asserted-by":"publisher","first-page":"21986","DOI":"10.1038\/s41598-025-05217-4","volume":"15","author":"C Xu","year":"2025","unstructured":"Xu C, Zhan Y, Wang Z, Yang J (2025) Multimodal fusion based few-shot network intrusion detection system. Sci Rep 15(1):21986","journal-title":"Sci Rep"},{"issue":"4","key":"496_CR26","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0284632","volume":"18","author":"H Sun","year":"2023","unstructured":"Sun H, Wan L, Liu M, Wang B (2023) Few-shot network intrusion detection based on prototypical capsule network with attention mechanism. PLoS ONE 18(4):e0284632","journal-title":"PLoS ONE"},{"issue":"22","key":"496_CR27","doi-asserted-by":"publisher","first-page":"4560","DOI":"10.3390\/electronics13224560","volume":"13","author":"J Bo","year":"2024","unstructured":"Bo J, Chen K, Li S, Gao P (2024) Boosting few-shot network intrusion detection with adaptive feature fusion mechanism. Electronics 13(22):4560","journal-title":"Electronics"},{"issue":"7","key":"496_CR28","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0327161","volume":"20","author":"C Xu","year":"2025","unstructured":"Xu C, Li D, Liu Z, Yang J, Shen Q, Tong N (2025) Few-shot network intrusion detection method based on multi-domain fusion and cross-attention. PLoS ONE 20(7):e0327161","journal-title":"PLoS ONE"},{"key":"496_CR29","unstructured":"Zhang He, Yu X, Ren P, Luo C, Min G (2019) Deep adversarial learning in intrusion detection: A data augmentation enhanced framework. arXiv preprint arXiv:1901.07949"},{"issue":"1","key":"496_CR30","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0317713","volume":"20","author":"C Xu","year":"2025","unstructured":"Xu C, Zhan Y, Chen G, Wang Z, Liu S, Hu W (2025) Elevated few-shot network intrusion detection via self-attention mechanisms and iterative refinement. PLoS ONE 20(1):e0317713","journal-title":"PLoS ONE"},{"issue":"22","key":"496_CR31","doi-asserted-by":"publisher","first-page":"4560","DOI":"10.3390\/electronics13224560","volume":"13","author":"J Bo","year":"2024","unstructured":"Bo J, Chen K, Li S, Gao P (2024) Boosting few-shot network intrusion detection with adaptive feature fusion mechanism. Electronics 13(22):4560","journal-title":"Electronics"},{"issue":"9","key":"496_CR32","doi-asserted-by":"publisher","first-page":"15140","DOI":"10.1109\/JIOT.2023.3342638","volume":"11","author":"C Wang","year":"2023","unstructured":"Wang C, Xu D, Li Z, Niyato D (2023) Effective intrusion detection in highly imbalanced iot networks with lightweight s2cgan-ids. IEEE Internet Things J 11(9):15140\u201315151","journal-title":"IEEE Internet Things J"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-025-00496-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-025-00496-w","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-025-00496-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,21]],"date-time":"2026-05-21T02:01:43Z","timestamp":1779328903000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1186\/s42400-025-00496-w"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,21]]},"references-count":32,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2026,12]]}},"alternative-id":["496"],"URL":"https:\/\/doi.org\/10.1186\/s42400-025-00496-w","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,5,21]]},"assertion":[{"value":"30 May 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"25 September 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"21 May 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"72"}}