Skip to main navigation Skip to search Skip to main content

A Semi-Supervised Meta-Negative-Learning Approach to Few-Shot Network Intrusion Detection in Internet of Things

  • Minyue Wu
  • , Ying Zheng*
  • , Yin Yang
  • , Jiachao Luo
  • , David Shan Hill Wong
  • *Corresponding author for this work
  • Huazhong University of Science and Technology
  • National Tsing Hua University

Research output: Contribution to journalArticlepeer-review

Abstract

The dynamic evolution of Internet of Things (IoT) threats necessitates reliable network intrusion detection (NID) systems. Such systems should not only respond to known security risks but also adapt effectively to emerging threats. However, practical deployments in novel IoT environments often suffer from significant data scarcity. In these cases, only a few labeled samples are available for training, which typically leads to poor performance. To address this challenge, we introduce a semi-supervised meta-negative-learning approach, termed SMILE, for few-shot NID using network traffic data. Our approach begins by pretraining a baseline NID model with historical attack data, followed by an improved negative learning (NL) strategy with uncertainty-aware pseudo-negative labels. Bagging sampling is further incorporated to dynamically balance pseudo-labeled data distributions and enhance tolerance to labeling errors. SMILE enables effective knowledge transfer from historical attacks to few-shot traffic streams. Experimental results on the CICIDS-2017 dataset demonstrate that SMILE significantly improves detection accuracy by 7.30%-16.65% across diverse classifier architectures in both five-shot and ten-shot scenarios, achieving a peak accuracy of 81.91%. Additional validation on the Edge-IIoT and IoT-23 datasets shows consistent improvements of 9.38% and 4.78%, reaching respective accuracies of 96.25% and 84.08% under ten-shot detection.

Original languageEnglish
Pages (from-to)12974-12987
Number of pages14
JournalIEEE Internet of Things Journal
Volume13
Issue number7
DOIs
Publication statusPublished - 1 Apr 2026

Keywords

  • Few-shot learning (FSL)
  • Internet of Things (IoT)
  • intrusion detection
  • negative learning (NL)
  • network security

Fingerprint

Dive into the research topics of 'A Semi-Supervised Meta-Negative-Learning Approach to Few-Shot Network Intrusion Detection in Internet of Things'. Together they form a unique fingerprint.

Cite this