Evaluating meta-learning strategies for zero-day intrusion detection under data scarcity
摘要
The rapid expansion of Internet of Things (IoT) technologies has significantly increased the digital attack surface, exposing modern networks to sophisticated cyber threats, particularly zero-day attacks that exploit previously undisclosed vulnerabilities. Conventional intrusion detection systems (IDSs), especially signature-based approaches, rely heavily on predefined attack patterns and large labeled datasets, which limits their effectiveness in identifying emerging and previously unseen attacks. To address this limitation, meta-learning has recently emerged as a promising paradigm for enabling intrusion detection under data-scarce conditions. However, the comparative evaluation of gradient-based and metric-based meta-learning approaches remains relatively underexplored in the domain of intrusion detection. In this study, the potential of meta-learning for zero-day intrusion detection is explored through the evaluation of two representative strategies within a few-shot learning framework: a gradient-based approach based on Model-Agnostic Meta-Learning (MAML), which enables rapid adaptation to new attack types, and a metric-based approach using Prototypical Networks, in which classification is performed within a learned embedding space. For additional comparative analysis, a Siamese network-based Fully Connected Network (FC-Net) is implemented as a baseline model. The framework evaluation is conducted using three diverse and realistic benchmark datasets, including CICIDS2017, CICIoT2023, and an augmented CIC-UNSW-NB15 dataset. Zero-day attack scenarios are simulated under multiclass classification settings to reflect practical deployment environments. Experimental results demonstrate that the MAML-based model consistently achieves superior performance across all datasets, obtaining 96.67% accuracy and 97.54% recall on CICIDS2017, 92.87% accuracy and 92.99% recall on CICIoT2023, and 83.20% accuracy and 83.50% recall on CIC-UNSW-NB15. These findings highlight the effectiveness of gradient-based meta-learning for rapid adaptation to previously unseen attacks and demonstrate its potential for developing intelligent IDSs capable of addressing evolving zero-day threats across heterogeneous network environments.