Close menu

SURE

Sunderland Repository records the research produced by the University of Sunderland including practice-based research and theses.

A domain adaptation network intrusion detection algorithm based on class-balanced knowledge transfer and multi-structure domain alignment

Wang, Qian, liu, xiang, cheng, yifan, Cheng, Yongqiang and Zhang, Bing (2026) A domain adaptation network intrusion detection algorithm based on class-balanced knowledge transfer and multi-structure domain alignment. Cluster Computing, 29 (521). ISSN 1386-7857

Item Type: Article

Abstract

In practical deployment, the performance of network intrusion detection systems is often degraded by class imbalance in training data and distribution shifts across different network environments. To address these challenges, a domain adaptation intrusion detection algorithm based on class-balanced knowledge transfer and multi-structure domain alignment is proposed in this paper. First, a class separation loss is proposed to mitigate the effect of class overlap caused by data imbalance processing on cross-domain knowledge transfer, and high-confidence pseudo-labels of the target domain are selected through a dynamic threshold for subsequent domain alignment. In addition, a multi-structure domain alignment method is proposed to reduce the discrepancy between the data distributions of the source domain and the target domain. The domain discrepancy is reduced from three aspects, including the overall feature distribution, inter-feature relationships, and class representations, thereby extracting domain-invariant features from the source domain and the target domain. Class prototypes are constructed using supervision information, and the relative relationships among different classes in the source domain and the target domain are aligned to reduce cross-domain discrepancies in class representations. Experiments are conducted on four public NIDS datasets under two cross-domain scenarios. In the cross-domain experiments from UNSW-NB15 to ToN-IoT and from NSL-KDD to BoT-IoT, the F1-score of the proposed algorithm reaches 89.73% and 84.10%, respectively, thereby verifying the effectiveness and superiority of the proposed algorithm.

[thumbnail of sn-article.pdf]
Preview
PDF
sn-article.pdf - Accepted Version
Available under License Creative Commons Attribution.

Download (1MB) | Preview

More Information

Depositing User: Yongqiang Cheng

Identifiers

Item ID: 20590
Identification Number: 10.1007/s10586-026-06374-5
ISSN: 1386-7857
URI: https://sure.sunderland.ac.uk/id/eprint/20590
Official URL: https://link.springer.com/article/10.1007/s10586-0...

Users with ORCIDS

ORCID for Yongqiang Cheng: ORCID iD orcid.org/0000-0001-7282-7638

Catalogue record

Date Deposited: 27 Jul 2026 08:27
Last Modified: 27 Jul 2026 08:27

Contributors

Author: Yongqiang Cheng ORCID iD
Author: Qian Wang
Author: xiang liu
Author: yifan cheng
Author: Bing Zhang

University Divisions

Faculty of Business and Technology > School of Computer Science and Engineering

Subjects

Computing > Cybersecurity
Computing > Artificial Intelligence

Actions (login required)

View Item (Repository Staff Only) View Item (Repository Staff Only)

Downloads per month over past year