Enhancing GNN-Based Network Intrusion Detection Systems through Memory-Replay Approach

Dinh-Hau Tran, Minho Park · 2025

Many recent studies have applied deep learning techniques to network intrusion detection systems (NIDS) to detect increasingly sophisticated cyberattacks. However, several limitations still exist when deploying these models in real-world network environments. Specifically, conventional deep learning models are often trained using a single dataset, typically assuming a static environment with unchanging data distribution. In reality, the data of the network system always change over time. This change causes deployed models to become obsolete, leading to performance degradation. Additionally, retraining these models with new datasets faces the challenge of catastrophic forgetting the loss of previous knowledge when learning new information. In this study, we introduce a novel framework that leverages the capabilities of the FN-GNN [1] model and memory-replay continual learning techniques to improve the performance and adaptability of NIDS. Continual learning enables the system to continuously learn and adapt to emerging attack scenarios while retaining previously acquired knowledge. Experimental results on benchmark datasets, CIC-IDS2017 and UNSW-NB15, show that the proposed method helps improve continuous learning ability while mitigating the problem of catastrophic forgetting.

Read the paper · More papers on PaperTik