A Novel Semantic Driven Meta-Learning Model for Rare Attack Detection

Y. Annie Jerusha, S. P. Syed Ibrahim, Vijay Varadharajan · IEEE Access · 2025

Accurate network intrusion detection requires extracting relevant semantic features that minimise mis-classification and identify several kinds of attacks. Traditional models often struggle to identify uncertain traffic patterns, leading to reduced reliability. This work presents a Novel Semantic Driven Meta learning Model, a hybrid framework that systematically refines categorisation decisions and uses advanced learning techniques to improve the detection through a two-stage verification process. Our approach improves the intrusion detection by integrating an attention layer-based model for semantic feature extraction and the Simple Neural Attentive Meta-Learner (SNAIL) for detecting rare attack classes. The first phase employs machine learning classifiers to perform macro-classification, distinguishing between normal and attack traffic. To minimize the misclassification, an additional classifier verifies the class label using a refined subset of features. In the second phase, the SNAIL model performs micro-classification, thereby further differentiating the attack classes with high precision. This dual-phase strategy is particularly effective in addressing the challenge of detecting rare classes in highly imbalanced network intrusion datasets. Using the NSL-KDD, CSE-CIC-IDS 2018, and CIC-ToN-IoT datasets, we assess our model, showing its better performance in precisely detecting unusual attack types while preserving a low false alarm rate with semantic characteristics. The proposed model demonstrates a higher detection rate for most of the rare classes considered in our study compared to state-of-the-art methods.

Read the paper · More papers on PaperTik