Reinforcement Learning for Intrusion Detection: More Model Longness and Fewer Update

J Jennifa · INTERANTIONAL JOURNAL OF SCIENTIFIC RESEARCH IN ENGINEERING AND MANAGEMENT · 2025

Abstract - In today’s dynamic cybersecurity landscape, Intrusion Detection Systems (IDS) must adapt to evolving threats without relying on frequent retraining or compromising performance. This project proposes a novel IDS framework that synergistically combines Convolutional Neural Networks (CNNs) with Reinforcement Learning (RL) to classify network traffic as normal or anomalous, while minimizing the frequency of model updates. The framework is deployed via an intuitive, Streamlit-based web interface that supports real-time predictions based on user-provided network feature inputs.A pre-trained scaler is employed to normalize the input features before classification by the CNN model. Simultaneously, a reinforcement learning agent dynamically adjusts detection policies through reward-based feedback, thereby prolonging the model’s operational lifespan and adaptability. To promote transparency and user trust, the system integrates LIME (Local Interpretable Model-Agnostic Explanations), providing interpretable, feature-level insights for each classification decision. Experimental evaluation reveals that the proposed system achieves high classification accuracy, maintains a low false positive rate, and demonstrates strong resilience over time—without the need for frequent retraining. This work delivers a scalable, explainable, and low-maintenance solution for intrusion detection, offering a robust asset for contemporary cybersecurity environments.

Read the paper · More papers on PaperTik