IGPC-MSOS: A knowledge-preserving transfer learning framework with dynamic mode-switching for handling concept drift in network intrusion detection systems
Methaq A. Shyaa, Noor Farizah Ibrahim, Zurinahni Binti Zainol, Rosni Abdullah, Mohammed Anbar, Laith H. Alzubaidi · Knowledge-Based Systems · 2026
• IGPC-MSOS: a knowledge-preserving transfer learning framework for concept drift in network intrusion detection. • Mode switching mitigates catastrophic forgetting while adapting to concept drift. • A dual-trigger strategy combines drift detection with performance-based mode selection. • Achieves 99.5–100% recall across five IDS datasets with inference latency below 2 ms. • Delivers substantially faster inference than FlowTransformer and ATNN, while maintaining competitive accuracy. The rapid evolution of cyber threats poses significant challenges to Intrusion Detection Systems (IDS), particularly in dynamic environments affected by concept drift, where shifting attack behaviors degrade long-term detection performance. Existing adaptive IDS solutions often remain limited by fragmented drift-handling mechanisms, weak knowledge retention, and insufficient integration of complementary learning strategies, leaving exploitable blind spots. This paper introduces a unified adaptive IDS framework based on a mode-switching architecture that integrates Online Sequential Extreme Learning Machine (OSELM), Feature-Adaptive OSELM (FA-OSELM), and Knowledge-Preserving OSELM (KP-OSELM). The proposed Incremental Genetic Programming Combiner with Mode-Switching Online Sequential (IGPC-MSOS) method dynamically selects the most effective operational mode according to detected drift patterns and real-time performance feedback. Experimental evaluations across five benchmark datasets demonstrate that IGPC-MSOS consistently achieves 96%–100% recall, delivers competitive or superior F1-scores (0.96–0.9995), and reduces inference latency compared to the State-of-the-Art Approaches. These results confirm the strong adaptability, robustness, and real-time suitability of the proposed approach for intrusion detection in evolving and high-throughput network environments.