RES-DARE: Failure-Aware Expert Adaptation and Rollback-Safe Self-Repair for Intrusion Detection

📅 2026-07-02
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This work addresses the vulnerability of static intrusion detection systems in dynamic networks, where distribution shifts often lead to high-confidence misclassifications and silent failures. To overcome this, the authors propose a continual intrusion detection framework with fault awareness and rollback-safe self-repair capabilities. The approach employs a supervised contrastive encoder combined with HDBSCAN to identify uncertain or misclassified samples, triggering a fault-driven expert specialization mechanism. Integrated with the AEHM-v2 strategy, the framework enables collaborative, adaptive detection across multiple modules while mitigating catastrophic forgetting. Evaluated on CICIDS2017, UNSW-NB15, and TON_IoT datasets, the method achieves macro-F1 scores of 0.9850, 0.9736, and 0.9691, respectively. Under Gaussian noise perturbations, it maintains an Attack-F1 of 0.7920 and exhibits a remarkably low forgetting metric of 0.0015.
📝 Abstract
Intrusion detection systems are often trained under static benchmark conditions, although deployed network environments are affected by traffic drift, sensor noise, changing workloads, and evolving attack behaviour. Under such distribution shifts, static detectors may produce confident but incorrect predictions, leading to silent and unsafe failure modes. In this paper, RES-DARE (Recursive Evolving Specialists-Digital Adaptive Reasoning Engine) is proposed as a failure-aware continual intrusion detection framework with rollback-safe self-repair. Difficult, uncertain, and misclassified samples are treated as failure signals for expert specialisation rather than being discarded as noise. A supervised contrastive encoder, two-pass expert router, failure-buffer mechanism, HDBSCAN-based failure-region discovery, and trust-risk monitor are integrated to support adaptive IDS behaviour. AEHM-v2 is introduced as a rollback-safe repair mechanism, where candidate adaptations are provisionally activated and committed only when macro-F1 is preserved or improved while trust risk remains stable. Otherwise, the system is rolled back to its last validated state. RES-DARE is evaluated on CICIDS2017, UNSW-NB15, and TON\_IoT, achieving macro-F1 scores of 0.9850, 0.9736, and 0.9691, respectively. Under Gaussian feature corruption at strength 0.10, RES-DARE retains an Attack-F1 of 0.7920 on CICIDS2017 and achieves near-zero catastrophic forgetting with F = 0.0015. The results show that RES-DARE improves robustness, warning capability, and deployment safety under degraded conditions.
Problem

Research questions and friction points this paper is trying to address.

intrusion detection
distribution shift
silent failure
deployment safety
traffic drift
Innovation

Methods, ideas, or system contributions that make the work stand out.

failure-aware adaptation
rollback-safe self-repair
continual intrusion detection
supervised contrastive learning
trust-risk monitoring
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
R
Rahil Aftab
Department of Computer Science, Jamia Hamdard, New Delhi 110062, India
A
Anyash Prasad
Department of Computer Science, Kalinga Institute of Industrial Technology, Bhubaneswar, Odisha 751024, India
Soumya Mazumdar
Soumya Mazumdar
University of Canberra
Public health & geographyBuilt EnvironmentRefugee health equityGISGreenspace
V
Vineet Kumar Rakesh
Engineering Science, Homi Bhabha National Institute, Anushaktinagar, Mumbai 400094, Maharashtra, India; Computer and Informatics Group, Variable Energy Cyclotron Centre, 1/AF, Bidhannagar, Kolkata 700064, West Bengal, India
T
Tapas Samanta
Engineering Science, Homi Bhabha National Institute, Anushaktinagar, Mumbai 400094, Maharashtra, India; Computer and Informatics Group, Variable Energy Cyclotron Centre, 1/AF, Bidhannagar, Kolkata 700064, West Bengal, India