Candidate Comparability Before Promotion: Conditional Validation in Adaptive Network Intrusion Detection
2026-09-07 12:00Science🔥 42.2 heat score
1sources
1days unfolding
42.2heat score
3mentions
SummaryAI generated
Regarding the issue of whether to replace the existing classifier in adaptive network intrusion detection systems upon receiving a “drift alert”, studies were conducted using the CICIDS2017, UNSW-NB15, and ToN-IoT datasets. The results showed that a drift alert alone was not sufficient to conclude that the incumbent classifier should be replaced. Continuing to use the existing frozen preprocessing would amplify the risk of spread; whereas when using a self-contained challenger pipeline, the average risk of full drift did not persist. By increasing the number of nominal candidate samples from 512 per class to 2,000, the balanced accuracy improved by 0.53, 1.67, and 0.38 points in the three benchmark tests, respectively. This result was statistically significant and mainly due to a reduction in false positives. Additionally, the conclusions regarding the spread strategy indicated that the comparability of candidates changed the strategy ranking, and there was no single globally dominant strategy.