Key points are not available for this paper at this time.
Network intrusion detection systems (NIDSs) deployed in dynamic environments face concept drift from evolving attacks and traffic patterns, causing model reliability to degrade over time. Continual learning (CL) offers an adaptive solution, yet many methods misalign drift detection, memory updating, and optimization: drift is often judged with low-dimensional statistics, while adaptation occurs in representation space, limiting consistency under buffer constraints. To address concept drift in non-stationary network traffic and catastrophic forgetting during online intrusion detection updates, we propose a continual-learning framework built upon SSF that combines feature-space Gaussian-kernel Maximum Mean Discrepancy (MMD) drift detection with gradient-matching coresets for memory admission. The proposed framework retains strategic forgetting and steady-state distillation while replacing low-dimensional drift tests with feature-space MMD and mask-based selection with gradient-matching coresets, thereby improving incremental updates under a limited memory budget. On NSL-KDD and UNSW-NB15 under a unified multi-seed streaming protocol, the proposed method improves detection performance and knowledge retention. Experimental results demonstrate that gradient-matching coreset selection is the primary contributor to the observed performance improvements, while the effectiveness of MMD-based drift scheduling and strategic forgetting depends on the underlying data distribution and drift-trigger threshold. The proposed framework employs batch-level MMD scheduling to coordinate memory admission and online optimization, providing a practical path toward robust continual intrusion detection.
Xu et al. (Fri,) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: