Predictive Inversion in Cross-Network Intrusion Detection: Which Flows to Label When Confidence Cannot Be Trusted

Thanh Duc Vu, X. C., L. G. Nguyen · Zenodo (CERN European Organization for Nuclear Research) · 2026

Preprint of a manuscript under review. Machine-learned network intrusion detectors routinely report near-perfect in-domain scores, yet deploying one on a network it has never seen can invert the very signal that adaptive methods rely on. This work formalizes predictive inversion — a deployment regime in which the ordering induced by a source detector is negatively associated with the target labels, measured as a target AUROC below 0.5 — and introduces a leakage-free evaluation protocol for the standardized NetFlow-v2 benchmark family that removes identifier and port shortcuts and fits all normalization on the source only. Under this protocol, detectors with in-domain AUROC near 0.99 fall to target AUROC between 0.26 and 0.82 across six directed source-target pairs, with two pairs inverted. The study then asks which target flows an analyst should label to repair the detector under a budget of a few dozen labels, and establishes that the family a label-selection rule belongs to, not its sophistication, determines whether repair succeeds. Confidence-based uncertainty sampling degrades below the no-adaptation baseline on inverted pairs, whereas selection driven by the geometry of the target distribution repairs collapsed detectors with 10-20 labels. A calibration analysis identifies the mechanism. Experimental results and analysis code are archived separately (see Related works).

Read the paper · More papers on PaperTik