Candidate Comparability Before Promotion: Conditional Validation in Adaptive Network Intrusion Detection

📅 2026-09-03
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
研究解决了自适应网络入侵检测系统中候选模型可比性问题,通过控制候选模型构建和证据量,使用多种更新策略及敏感性分析方法进行验证。
📝 Abstract
Adaptive network intrusion detection systems retrain classifiers after drift alarms, but an alarm detects change; it does not establish that a challenger should replace the deployed incumbent. Promotion is security-relevant because it changes the model responsible for subsequent attack detection, and evaluating it has a methodological problem: promotion conclusions may depend on how the challenger was constructed and on how much evidence supports it. We test that dependence on CICIDS2017, UNSW-NB15 and ToN-IoT with self-contained challenger pipelines, nested candidate-size controls, a common-harness comparison of nine update policies, and a final sensitivity confining every exact feature vector to one evaluation, training or probe role. Incumbent-owned frozen preprocessing amplified apparent promotion harm; with self-contained challenger pipelines the mean full-drift harm did not persist. Raising nominal candidate evidence from 512 to 2,000 samples per class improved promotion under pool-constructed progressive drift by +0.53, +1.67 and +0.38 balanced-accuracy points: positive and statistically resolved in all three benchmarks, but materially benchmark-dependent rather than homogeneous, and driven mainly by fewer false positives. Policy conclusions were partially robust: policy ordering changed with candidate comparability, no policy globally dominated, and earlier compatibility statements for a label-free estimator and a calibrated ensemble narrowed. Validation helped evidence-disadvantaged challengers but added no average benefit at parity. Thirteen replays on real, time-ordered traffic showed no net harm from always deploying. Challenger construction and evidence should be controlled, reported and interpreted explicitly when promotion is evaluated.
Problem

Research questions and friction points this paper is trying to address.

adaptive network intrusion detection
classifier retraining
drift alarm
challenger evaluation
promotion validation
Innovation

Methods, ideas, or system contributions that make the work stand out.

Adaptive Network Intrusion Detection
Challenger Validation
Candidate Evidence Control
False Positive Reduction
R
Roberto Fernández-Barrios
Faculty of Engineering, University of Deusto, Avda. de las Universidades, 24, 48007 Bilbao, Spain
I
Iker Pastor-López
Faculty of Engineering, University of Deusto, Avda. de las Universidades, 24, 48007 Bilbao, Spain
A
Amaia Pikatza-Huerga
Faculty of Engineering, University of Deusto, Avda. de las Universidades, 24, 48007 Bilbao, Spain
P
Pablo García Bringas
Faculty of Engineering, University of Deusto, Avda. de las Universidades, 24, 48007 Bilbao, Spain