{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,22]],"date-time":"2026-07-22T15:21:04Z","timestamp":1784733664643,"version":"3.55.0"},"reference-count":39,"publisher":"MDPI AG","issue":"10","license":[{"start":{"date-parts":[[2025,10,4]],"date-time":"2025-10-04T00:00:00Z","timestamp":1759536000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["www.mdpi.com"],"crossmark-restriction":true},"short-container-title":["Future Internet"],"abstract":"<jats:p>In the face of ever-evolving cyber threats, modern intrusion detection systems (IDS) must achieve long-term adaptability without sacrificing performance on previously encountered attacks. Traditional IDS approaches often rely on static training assumptions, making them prone to forgetting old patterns, underperforming in label-scarce conditions, and struggling with imbalanced class distributions as new attacks emerge. To overcome these limitations, we present a continual learning framework tailored for adaptive intrusion detection. Unlike prior methods, our approach is designed to operate under real-world network conditions characterized by high-dimensional, sparse traffic data and task-agnostic learning sequences. The framework combines three core components: a clustering-based memory strategy that selectively retains informative historical samples using DP-Means; multi-level knowledge distillation that aligns current and previous model states at output and intermediate feature levels; and a meta-learning-driven class reweighting mechanism that dynamically adjusts to shifting attack distributions. Empirical evaluations on benchmark intrusion detection datasets demonstrate the framework\u2019s ability to maintain high detection accuracy while effectively mitigating forgetting. Notably, it delivers reliable performance in continually changing environments where the availability of labeled data is limited, making it well-suited for real-world cybersecurity systems.<\/jats:p>","DOI":"10.3390\/fi17100456","type":"journal-article","created":{"date-parts":[[2025,10,6]],"date-time":"2025-10-06T13:33:41Z","timestamp":1759757621000},"page":"456","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["Continual Learning for Intrusion Detection Under Evolving Network Threats"],"prefix":"10.3390","volume":"17","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7393-3683","authenticated-orcid":false,"given":"Chaoqun","family":"Guo","sequence":"first","affiliation":[{"name":"School of Software Engineering, Beijing Jiaotong University, Beijing 100044, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-5473-6547","authenticated-orcid":false,"given":"Xihan","family":"Li","sequence":"additional","affiliation":[{"name":"School of Software Engineering, Beijing Jiaotong University, Beijing 100044, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-2005-5647","authenticated-orcid":false,"given":"Jubao","family":"Cheng","sequence":"additional","affiliation":[{"name":"School of Software Engineering, Beijing Jiaotong University, Beijing 100044, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-5320-6276","authenticated-orcid":false,"given":"Shunjie","family":"Yang","sequence":"additional","affiliation":[{"name":"School of Software Engineering, Beijing Jiaotong University, Beijing 100044, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-3570-8709","authenticated-orcid":false,"given":"Huiquan","family":"Gong","sequence":"additional","affiliation":[{"name":"School of Software Engineering, Beijing Jiaotong University, Beijing 100044, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2025,10,4]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"2389","DOI":"10.1109\/TNSM.2023.3332284","article-title":"A few-shot class-incremental learning method for network intrusion detection","volume":"21","author":"Du","year":"2023","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"1185","DOI":"10.1038\/s42256-022-00568-3","article-title":"Three types of incremental learning","volume":"4","author":"Tuytelaars","year":"2022","journal-title":"Nat. Mach. Intell."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"56","DOI":"10.20544\/HORIZONS.B.04.1.17.P05","article-title":"An overview of the supervised machine learning methods","volume":"4","author":"Nasteski","year":"2017","journal-title":"Horizons B"},{"key":"ref_4","unstructured":"Zhu, X.J. (Semi-Supervised Learning Literature Survey: Technical Report, 2005). Semi-Supervised Learning Literature Survey: Technical Report."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Shyaa, M.A., Zainol, Z., Abdullah, R., Anbar, M., Alzubaidi, L., and Santamar\u00eda, J. (2023). Enhanced intrusion detection with data stream classification and concept drift guided by the incremental learning genetic programming combiner. Sensors, 23.","DOI":"10.3390\/s23073736"},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"1851","DOI":"10.1109\/COMST.2019.2891891","article-title":"A survey on advanced persistent threats: Techniques, solutions, challenges, and research opportunities","volume":"21","author":"Alshamrani","year":"2019","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Bilge, L., and Dumitra\u015f, T. (2012, January 16\u201318). Before we knew it: An empirical study of zero-day attacks in the real world. Proceedings of the 2012 ACM Conference on Computer and Communications Security, Raleigh, NC, USA.","DOI":"10.1145\/2382196.2382284"},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"3521","DOI":"10.1073\/pnas.1611835114","article-title":"Overcoming catastrophic forgetting in neural networks","volume":"114","author":"Kirkpatrick","year":"2017","journal-title":"Proc. Natl. Acad. Sci. USA"},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Baysal, E., and Bay\u0131lm\u0131\u015f, C. (2025). Overcoming Class Imbalance in Incremental Learning Using an Elastic Weight Consolidation-Assisted Common Encoder Approach. Mathematics, 13.","DOI":"10.3390\/math13111887"},{"key":"ref_10","unstructured":"Zenke, F., Poole, B., and Ganguli, S. (2017, January 6\u201311). Continual learning through synaptic intelligence. Proceedings of the International Conference on Machine Learning, PMLR, Sydney, NSW, Australia."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Rebuffi, S.A., Kolesnikov, A., Sperl, G., and Lampert, C.H. (2017, January 21\u201326). icarl: Incremental classifier and representation learning. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Honolulu, HI, USA.","DOI":"10.1109\/CVPR.2017.587"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Prabhu, A., Torr, P.H., and Dokania, P.K. (2020, January 23\u201328). Gdumb: A simple approach that questions our progress in continual learning. Proceedings of the Computer Vision\u2014ECCV 2020: 16th European Conference, Glasgow, UK. Proceedings, Part II 16.","DOI":"10.1007\/978-3-030-58536-5_31"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"3865","DOI":"10.1007\/s13042-024-02486-9","article-title":"Exbcil: An exemplar-based class incremental learning for intrusion detection system","volume":"16","author":"Bhurani","year":"2025","journal-title":"Int. J. Mach. Learn. Cybern."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Xu, H., and Wang, Y. (2022, January 12\u201314). A continual few-shot learning method via meta-learning for intrusion detection. Proceedings of the 2022 IEEE 4th International Conference on Civil Aviation Safety and Information Technology (ICCASIT), Dali, China.","DOI":"10.1109\/ICCASIT55263.2022.9986665"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Wang, R., Fei, J., Zhang, R., Guo, M., Qi, Z., and Li, X. (2023). Drnet: Dynamic retraining for malicious traffic small-sample incremental learning. Electronics, 12.","DOI":"10.3390\/electronics12122668"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"869","DOI":"10.1109\/TMLCN.2024.3418756","article-title":"Incremental Adversarial Learning for Polymorphic Attack Detection","volume":"2","author":"Sabeel","year":"2024","journal-title":"IEEE Trans. Mach. Learn. Commun. Netw."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"2935","DOI":"10.1109\/TPAMI.2017.2773081","article-title":"Learning without forgetting","volume":"40","author":"Li","year":"2017","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Douillard, A., Cord, M., Ollion, C., Robert, T., and Valle, E. (2020, January 23\u201328). Podnet: Pooled outputs distillation for small-tasks incremental learning. Proceedings of the Computer Vision\u2013ECCV 2020: 16th European Conference, Glasgow, UK. Proceedings, Part XX 16.","DOI":"10.1007\/978-3-030-58565-5_6"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Smith, J., Balloch, J., Hsu, Y.C., and Kira, Z. (2021, January 18\u201322). Memory-Efficient Semi-Supervised Continual Learning: The World is its Own Replay Buffer. Proceedings of the 2021 International Joint Conference on Neural Networks (IJCNN), Shenzhen, China.","DOI":"10.1109\/IJCNN52387.2021.9534361"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Gao, J., Chai, S., Zhang, B., and Xia, Y. (2019). Research on network intrusion detection based on incremental extreme learning machine and adaptive principal component analysis. Energies, 12.","DOI":"10.3390\/en12071223"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Amalapuram, S.K., Tamma, B.R., and Channappayya, S.S. (2024, January 20\u201323). Spider: A semi-supervised continual learning-based network intrusion detection system. Proceedings of the IEEE INFOCOM 2024\u2014IEEE Conference on Computer Communications, Vancouver, BC, Canada.","DOI":"10.1109\/INFOCOM52122.2024.10621428"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"205","DOI":"10.1016\/j.procs.2022.03.029","article-title":"Intrusion detection systems using supervised machine learning techniques: A survey","volume":"201","author":"Abdallah","year":"2022","journal-title":"Procedia Comput. Sci."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Chen, C., Gong, Y., and Tian, Y. (2008, January 12\u201315). Semi-supervised learning methods for network intrusion detection. Proceedings of the 2008 IEEE International Conference on Systems, Man and Cybernetics, Singapore.","DOI":"10.1109\/ICSMC.2008.4811688"},{"key":"ref_24","first-page":"596","article-title":"Fixmatch: Simplifying semi-supervised learning with consistency and confidence","volume":"33","author":"Sohn","year":"2020","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref_25","unstructured":"Lee, D.H. (2013, January 16\u201321). Pseudo-label: The simple and efficient semi-supervised learning method for deep neural networks. Proceedings of the Workshop on Challenges in Representation Learning, ICML, Atlanta, GA, USA."},{"key":"ref_26","first-page":"6256","article-title":"Unsupervised data augmentation for consistency training","volume":"33","author":"Xie","year":"2020","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref_27","first-page":"1195","article-title":"Mean teachers are better role models: Weight-averaged consistency targets improve semi-supervised deep learning results","volume":"30","author":"Tarvainen","year":"2017","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref_28","first-page":"5049","article-title":"Mixmatch: A holistic approach to semi-supervised learning","volume":"32","author":"Berthelot","year":"2019","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref_29","unstructured":"Chen, T., Kornblith, S., Norouzi, M., and Hinton, G. (2020, January 13\u201318). A simple framework for contrastive learning of visual representations. Proceedings of the International Conference on Machine Learning, PmLR, Online."},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Lechat, A., Herbin, S., and Jurie, F. (2021, January 22\u201325). Pseudo-labeling for class incremental learning. Proceedings of the BMVC 2021: The British Machine Vision Conference, Online.","DOI":"10.5244\/C.35.363"},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Cermelli, F., Fontanel, D., Tavera, A., Ciccone, M., and Caputo, B. (2022, January 18\u201324). Incremental learning in semantic segmentation from image labels. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, New Orleans, LA, USA.","DOI":"10.1109\/CVPR52688.2022.00433"},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Cui, Y., Jia, M., Lin, T.Y., Song, Y., and Belongie, S. (2019, January 15\u201320). Class-balanced loss based on effective number of samples. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Long Beach, CA, USA.","DOI":"10.1109\/CVPR.2019.00949"},{"key":"ref_33","first-page":"1567","article-title":"Learning imbalanced datasets with label-distribution-aware margin loss","volume":"32","author":"Cao","year":"2019","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Moustafa, N., and Slay, J. (2015, January 10\u201312). UNSW-NB15: A comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set). Proceedings of the 2015 Military Communications and Information Systems Conference (MilCIS), Canberra, ACT, Australia.","DOI":"10.1109\/MilCIS.2015.7348942"},{"key":"ref_35","first-page":"108","article-title":"Toward generating a new intrusion detection dataset and intrusion traffic characterization","volume":"1","author":"Sharafaldin","year":"2018","journal-title":"ICISSp"},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"485","DOI":"10.1109\/JIOT.2021.3085194","article-title":"ToN_IoT: The Role of Heterogeneity and the Need for Standardization of Features and Attack Types in IoT Network Intrusion Data Sets","volume":"9","author":"Booij","year":"2022","journal-title":"IEEE Internet Things J."},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"779","DOI":"10.1016\/j.future.2019.05.041","article-title":"Towards the development of realistic botnet dataset in the internet of things for network forensic analytics: Bot-iot dataset","volume":"100","author":"Koroniotis","year":"2019","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_38","unstructured":"Belouadah, E., and Popescu, A. (November, January 27). Il2m: Class incremental learning with dual memory. Proceedings of the IEEE\/CVF International Conference on Computer Vision, Seoul, Republic of Korea."},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Lechat, A., Herbin, S., and Jurie, F. (2021, January 10\u201315). Semi-supervised class incremental learning. Proceedings of the 2020 25th International Conference on Pattern Recognition (ICPR), Milan, Italy.","DOI":"10.1109\/ICPR48806.2021.9413225"}],"container-title":["Future Internet"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-5903\/17\/10\/456\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,6]],"date-time":"2025-10-06T13:52:09Z","timestamp":1759758729000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-5903\/17\/10\/456"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,4]]},"references-count":39,"journal-issue":{"issue":"10","published-online":{"date-parts":[[2025,10]]}},"alternative-id":["fi17100456"],"URL":"https:\/\/doi.org\/10.3390\/fi17100456","relation":{},"ISSN":["1999-5903"],"issn-type":[{"value":"1999-5903","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,10,4]]}}}