A domain adaptation network intrusion detection algorithm based on class-balanced knowledge transfer and multi-structure domain alignment
Wang, Qian, liu, xiang, cheng, yifan, Cheng, Yongqiang and Zhang, Bing (2026) A domain adaptation network intrusion detection algorithm based on class-balanced knowledge transfer and multi-structure domain alignment. Cluster Computing, 29 (521). ISSN 1386-7857
| Item Type: | Article |
|---|
Abstract
In practical deployment, the performance of network intrusion detection systems is often degraded by class imbalance in training data and distribution shifts across different network environments. To address these challenges, a domain adaptation intrusion detection algorithm based on class-balanced knowledge transfer and multi-structure domain alignment is proposed in this paper. First, a class separation loss is proposed to mitigate the effect of class overlap caused by data imbalance processing on cross-domain knowledge transfer, and high-confidence pseudo-labels of the target domain are selected through a dynamic threshold for subsequent domain alignment. In addition, a multi-structure domain alignment method is proposed to reduce the discrepancy between the data distributions of the source domain and the target domain. The domain discrepancy is reduced from three aspects, including the overall feature distribution, inter-feature relationships, and class representations, thereby extracting domain-invariant features from the source domain and the target domain. Class prototypes are constructed using supervision information, and the relative relationships among different classes in the source domain and the target domain are aligned to reduce cross-domain discrepancies in class representations. Experiments are conducted on four public NIDS datasets under two cross-domain scenarios. In the cross-domain experiments from UNSW-NB15 to ToN-IoT and from NSL-KDD to BoT-IoT, the F1-score of the proposed algorithm reaches 89.73% and 84.10%, respectively, thereby verifying the effectiveness and superiority of the proposed algorithm.
Preview |
PDF
sn-article.pdf - Accepted Version Available under License Creative Commons Attribution. Download (1MB) | Preview |
More Information
| Depositing User: Yongqiang Cheng |
Identifiers
| Item ID: 20590 |
| Identification Number: 10.1007/s10586-026-06374-5 |
| ISSN: 1386-7857 |
| URI: https://sure.sunderland.ac.uk/id/eprint/20590 | Official URL: https://link.springer.com/article/10.1007/s10586-0... |
Users with ORCIDS
Catalogue record
| Date Deposited: 27 Jul 2026 08:27 |
| Last Modified: 27 Jul 2026 08:27 |
| Author: |
Yongqiang Cheng
|
| Author: | Qian Wang |
| Author: | xiang liu |
| Author: | yifan cheng |
| Author: | Bing Zhang |
University Divisions
Faculty of Business and Technology > School of Computer Science and EngineeringSubjects
Computing > CybersecurityComputing > Artificial Intelligence
Actions (login required)
![]() |
View Item (Repository Staff Only) |


Dimensions
Dimensions