Pith. sign in

REVIEW 1 cited by

Generative Active Adaptation for Drifting and Imbalanced Network Intrusion Detection

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2503.03022 v3 pith:XC6NJ2XC submitted 2025-03-04 cs.NI cs.CRcs.LG

classification cs.NIcs.CRcs.LG
keywords adaptationdetectiongenerativeintrusionactiveattackdatadataset
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Machine learning has shown promise in network intrusion detection systems, yet its performance often degrades due to concept drift and imbalanced data. These challenges are compounded by the labor-intensive process of labeling network traffic, especially when dealing with evolving and rare attack types, which makes preparing the right data for adaptation difficult. To address these issues, we propose a generative active adaptation framework that minimizes labeling effort while enhancing model robustness. Our approach employs density-aware dataset prior selection to identify the most informative samples for annotation, and leverages deep generative models to conditionally synthesize diverse samples, thereby augmenting the training set and mitigating the effects of concept drift. We evaluate our end-to-end framework \NetGuard on both simulated IDS data and a real-world ISP dataset, demonstrating significant improvements in intrusion detection performance. Our method boosts the overall F1-score from 0.60 (without adaptation) to 0.86. Rare attacks such as Infiltration, Web Attack, and FTP-BruteForce, which originally achieved F1 scores of 0.001, 0.04, and 0.00, improve to 0.30, 0.50, and 0.71, respectively, with generative active adaptation in the CIC-IDS 2018 dataset. Our framework effectively enhances rare attack detection while reducing labeling costs, making it a scalable and practical solution for intrusion detection.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. TabQueryBench: A Query-Centric Benchmark for Synthetic Tabular Data

    cs.DB 2026-07 accept novelty 7.0 of 10

    Across 49 datasets and 11 generators, distance-based fidelity overstates synthetic tabular quality: best query-centric score is only 0.75, with systematic failures on high-cardinality support, local conditionals, and ...

Pith tools