Skip to content

Few-Shot Learning for Network Intrusion Detection: Methods, Datasets, and Performance

Arxiv September 11, 2026

Anomaly-based network intrusion detection systems (NIDS) are an important first line of defense. However, training NIDS for new attack types is challenging, because labeled attack data are rarely available. Few-shot learning (FSL) addresses this problem by learning from few samples. However, the approaches and evaluation settings, that have been investigated so far, vary widely. This work systematically reviews FSL approaches for NIDS published from 2022 to 2026. We conduct a systematic literature review with PRISMA 2020-like reporting to ACM Digital Library, IEEE Xplore, and Scopus. From a set of 1,358 initial records, we retain 21 studies after screening, deduplication, and quality filtering. We classify the applied FSL approaches, datasets, and experimental parameters and compare reported performance. Meta-learning and convolutional neural networks are the most common approaches, with 8 and 10 studies, respectively. Most studies evaluate five or fewer samples per class, although settings vary. CIC-IDS2017 and CSE-CIC-IDS2018 are the most frequently used datasets. Missing parameters and source code limit reproducibility and direct comparison between approaches.

Network intrusion detection systems [ 23 ] (NIDS) identify attacks that cross network boundaries, complement host-based defenses, and provide control points in heterogeneous environments [ 3 ] . As today’s attackers increasingly use generative AI [ 17 ] to modify payloads, alter protocol interactions, and tailor attacks to specific systems [ 2 ] , NIDS must adapt quickly to new attacks.

Signature-based detection cannot recognize attacks for which no rule exists, and anomaly-based approaches raise alerts without identifying the attack type [ 23 , 3 ] . Supervised, learning-based NIDS close this gap by generalizing from labeled traffic; however, they require labeled samples of every attack class they are expected to recognize. For novel attacks, such labels are scarce, while benign traffic dominates the available data [ 15 ] . Few-shot learning [ 45 ] (FSL) addresses exactly this situation by learning new classes from a small number of labeled samples, making it a natural fit for intrusion detection under label scarcity.

Driven by this promise, a growing body of studies has applied FSL to network intrusion detection in recent years. However, the field has not yet converged on common practices. There is no consensus on which FSL techniques or combinations perform best, nor on how they should be evaluated. Moreover, the meaning of “few” remains inconsistent, with recent studies using between one and 20 samples per class [ 51 , 53 ] . Studies differ in the number of samples per class, the number of classes, the datasets used, preprocessing steps, and reported metrics, and reporting practices vary widely. Without such common ground, reported results cannot be compared across studies and reproduction is difficult wherever parameters remain undisclosed. To structure the current landscape, we answer three research questions:

Which learning techniques are used for few-shot NIDS?

Which datasets are used to evaluate these approaches?

How are these approaches evaluated?

In this paper, we contribute a systematic literature review following [ 24 ] with a PRISMA 2020-like reporting [ 36 ] of recent studies on FSL for NIDS. We searched the ACM Digital Library, IEEE Xplore, and Scopus for peer-reviewed studies published between 2022 and 2026. Our returned 1,358 records, of which we retained 21 studies for detailed analysis after deduplication and filtering according to predefined criteria. For each study, we extract the applied learning technique, datasets, evaluation settings, and reported FSL parameters where available. We organize the studies by their main techniques and compare their reported results where possible.

Most reviewed studies combine multiple learning techniques (17 of 21), with CNNs (10 of 21) and meta-learning (8 of 21) being the most common. Among the 17 studies reporting k k , k = 5 k{=}5 is the most frequent setting. CIC-IDS2017 and CSE-CIC-IDS2018 are the most widely used datasets, appearing in 11 and 6 studies, respectively. Accuracy, precision, recall, and F1-score are the dominant evaluation metrics, with 15 studies reporting F1-scores. However, evaluation settings vary substantially: five studies omit k k , four omit the number of classes n n , and most provide no accessible source code. These gaps limit reproducibility and direct comparison.

has been surveyed extensively. Aldweesh et al. [ 4 ] provide a taxonomy of deep-learning approaches for anomaly-based IDS together with open issues. Maseer et al. [ 31 ] present a meta review of NIDS, finding deep learning approaches to perform better than traditional machine learning. Also, they criticize the use of out-of-date data sets. More recently, Lansky et al. [ 25 ] provide an in-depth review of IDS systems and their deep learning architectures. Ashraf and Masoodi [ 6 ] examine over 120 data sets used for intrusion detection with regard to attack types, temporal features and other categories. Few-shot learning was only once mentioned in [ 4 ] and [ 25 ] ; and not at all in [ 31 ] .

Few-Shot Learning Techniques

Coming from the other angle, few-shot learning itself has been systematized by Wang et al. [ 45 ] , who categorize FSL techniques by how prior knowledge is used to augment data, constrain the model, or guide the optimization algorithm. Song et al. [ 40 ] review over 200 recent FSL studies and demarcate few-shot learning from the related concepts of transfer learning and meta-learning. For the related problem of continuously arriving new classes, Zhou et al. [ 55 ] survey class-incremental learning. For the neighboring task of encrypted traffic classification, Yang et al. [ 50 ] survey few-shot approaches specifically. These studies are not primarily concerned with network intrusion, however, Yang et al. [ 50 ] are very close.

Even closer to our scope, Duan et al. [ 13 ] review few-shot learning for intrusion detection, covering data enrichment, graph embedding, and meta-learning approaches published up to 2021. Independent of our systematic , Winiecki et al. [ 46 ] evaluate selected FSL techniques, including a matching network with attention and prototyping, against classical baselines such as kNN and random forests for network intrusion detection.

In summary, existing surveys either address intrusion detection broadly without a few-shot focus, or, in the case of Duan et al. [ 13 ] , predate the rapid development of the field after 2021. To the best of our knowledge, no systematic review of few-shot learning for network intrusion detection exists since then. This work closes that gap by systematically reviewing studies published between 2022 and 2026, with a focus on the applied techniques, the datasets, and the evaluation settings, which together determine how comparable the reported results are.

We conduct a systematic literature review following [ 24 ] , with a PRISMA 2020-like reporting [ 36 ] . Our study selection process is illustrated in Figure 1 . We queried the ACM Digital Library [ 1 ] , IEEE Xplore [ 21 ] , and Scopus [ 7 ] . Each query combines intrusion detection and prevention terms ( intrusion detection , IDS , intrusion prevention , IDPS ) with few-shot and one-shot learning terms ( few shot learning , FSL , one-shot learning , one shot learning , OSL ), because OSL is contained in FSL. The broader term learning was included to capture studies not using these terms in the indexed metadata. The full queries are shown in the Appendix.

The returned 1034 (ACM), 183 (IEEE), and 141 (Scopus) records. We compared these 1358 studies against the eligibility criteria listed in Table 1 . In particular, we automatically filtered titles and abstracts for the terms intrusion , detection , shot , and learning , all of which had to match, leaving 162 studies. After deduplication, 124 studies remained. Of these, 34 were published in a venue meeting our quality criterion, i.e., a journal with an h 4 h_{4} -index of 53 or above as listed in the OOIR database [ 35 ] or a conference ranked B or better in the CORE ranking [ 20 ] . The h 4 h_{4} -index denotes the maximum number of a journal’s studies with at least that many citations within the last four years.

After automated filtering, we manually tested the remaining 34 studies for eligibility against the criteria listed in Table 1 , resulting in 21 studies being included in the review. Four of the excluded studies evaluated datasets predating 2007, six were not concerned with few-shot learning for network intrusion detection or reported no information it, one targeted zero-day attacks, which is out of scope, and one did not evaluate its approach conclusively. The remaining exclusion was a review, not a study; while it presents no novel approach itself, we reference it for context [ 9 ] .

For each included study, we extracted the applied learning techniques, the datasets used for evaluation, the evaluation setting (the number of classes n n and samples per class k k , where reported), and the reported performance. Most studies evaluate their approach on more than one dataset and report different subsets of metrics. For studies evaluating multiple settings, we report the performance of the 5-shot setting ( k = 5 k{=}5 ), as this is the most commonly evaluated setting. If no 5-shot experiment is reported, we use the study’s best-performing setting. All numbers are truncated after the third decimal place. The full per-dataset results at the selected setting, including accuracy, precision, recall, and F1-score, are given in the Appendix.

We structure the review by grouping studies according to their main FSL techniques. The set of techniques was derived from the corpus itself.

In a first pass over all included studies, we listed every learning technique applied, and then iteratively merged synonymous and subordinate techniques until ten categories remained that together cover every but one included studies. The categories are neither exclusive nor exhaustive. Most studies combine several FSL techniques. Table 2 lists the techniques per study and Figure 2 shows their co-occurrence and usage per year.

This section provides an overview of our review, lists the datasets and evaluation settings used, and then examines the FSL technique families in more detail.

Table 2 is the central artifact of this review: It provides an overview of the 21 included studies, along with the publication date, the learning techniques combined in each and the number of datasets evaluated. Full per-dataset results, including the evaluation parameters n n and k k , are provided in the Appendix.

Figure 2 summarizes the combinations of learning techniques and their temporal distribution. The left panel shows pairwise co-occurrences between techniques; diagonal entries indicate the total number of studies using each technique, while off-diagonal entries show how often two techniques are combined. CNNs (10 studies) and meta-learning (8 studies) are the most common, and their combination occurs most frequently (5 studies). Overall, 17 of the 21 studies combine at least two techniques. The right panel shows the number of studies using each technique per publication year as a heatmap, with darker cells indicating higher frequencies. CNNs are used throughout the reviewed period, while meta-learning is most frequent in 2026 and graph neural networks appear only in 2025–2026.

Figure 2 further shows that approaches for learning from few labeled samples (Meta-learning, MAML, FSCIL, and Twin NN) are more common than data-generation approaches for augmenting limited training data. The temporal distribution also shows a shift in focus. Meta-learning is absent in 2024 and appears only once in 2025 before increasing again in 2026. CNNs are used throughout 2023–2026, while Auto-Encoders appear only in 2023 and 2024 despite the strong performance reported by the respective studies.

To characterize the empirical basis of the reviewed studies, we examine the datasets used for evaluation. We consider both their frequency of use and their overlap across studies, as common datasets provide the main basis for comparing reported results. Table 3 summarizes how often which dataset was used in a study; the appendix contains all details.

CIC-IDS2017 [ 38 ] and CSE-CIC-IDS2018 [ 39 ] were by far the most popular choices (11 and 6 uses), followed by USTC-TFC2016 [ 44 ] and UNSW-NB15 [ 34 ] (5 and 1 uses). Additionally, CIC-IDS2017, CSE-CIC-IDS2018 and UNSW-NB15 were used in other datasets (FSIDS-IoT(-v2), prefixed NF-[dataset](-v2)), adding between two and five uses depending on the counting method. Each study evaluated a median of three datasets. At the same time, the long tail of single-use datasets means that many results cannot be compared against any other study.

4.3 Evaluation and Performance

We examine the evaluation settings reported by the included studies. Figure 3 summarizes the n n -way and k k -shot configurations. Only 16 of the 21 studies explicitly specify k k . Of these, 12 evaluate settings with five or fewer samples per class. The most common setting is k = 5 k{=}5 . The number of classes is typically between five and eight, with values ranging from two to 18. Five studies do not report k k and five do not report n n , limiting reproducibility and comparability.

Regarding reported performance, 15 of the 21 studies provide an F1-score. Their best reported F1-scores range from 0.700 to 0.999, and 12 of these 15 studies achieve at least 0.900 on one dataset. Five studies [ 51 , 48 , 37 , 52 , 5 ] report particularly high performance F 1 ≈ 0.96 F_{1}\approx 0.96 , A ​ c ​ c ≈ 0.96 Acc\approx 0.96 , F 1 ≈ 0.97 F_{1}\approx 0.97 , P ​ r ​ e ​ c ​ i ​ s ​ i ​ o ​ n ≈ 0.98 Precision\approx 0.98 , P ​ r ​ e ​ c ​ i ​ s ​ i ​ o ​ n = 0.996 Precision=0.996 ).

However, these results are difficult to compare directly, even when using the same dataset. Among the six studies reporting an F1-score on CIC-IDS2017, values range from 0.673 to 0.995. Similar variation appears within individual studies: Ayesha et al. [ 10 ] report F1-scores between 0.596 and 0.980 across three datasets, while Tong and Zhang [ 42 ] report 0.913 on NSL-KDD and 0.997 on CSE-CIC-IDS2018 without specifying k k . These differences indicate that dataset choice and evaluation settings substantially affect the reported performance and limit comparisons between techniques.

4.4 Technique-Level Analysis

This subsection examines the main learning techniques in detail. For each technique family, we introduce its application in few-shot intrusion detection, describe how it is used in the studies, and summarize the reported results.

trains an outer optimization loop over many small tasks so that the resulting model adapts to new classes from only a few labeled samples; the MAML framework [ 14 ] is the most common instantiation, used by four of the eight meta-learning studies. Inner learning rates of α = 0.01 \alpha=0.01 and meta-learning rates β = 0.001 \beta=0.001 where reported. Two MAML studies pair the framework with a CNN as the inner model. Lu et al. [ 27 ] convert flows into 3-channel images and optimize the CNN through MAML in a 5-way setting, while Zhang et al. [ 54 ] move detection to fog devices and extend MAML with multi-step loss optimization and a learn-to-forget mechanism. Wu et al. [ 47 ] pseudo-label formerly unlabeled data via negative learning and use bagging against class imbalance. Easing the few-shot problem itself, Lu et al. [ 28 ] generate training samples with a denoising diffusion model [ 19 ] enhanced by a drift loss. The remaining meta-learning studies constructed other frameworks: Miao et al. [ 32 ] train twin 3D-CNNs to find and handle out-of-distribution classes through prototype distances, Sun et al. [ 41 ] combine capsule networks to extract spatial and temporal features, as well as attention-based prototypes, and Xu et al. [ 49 ] use bidirectional matching between labels and flows via cosine similarity and a random walk. The results within this family vary widely: where F1-scores are reported, they range from 0.915 [ 54 ] to 0.996 [ 5 ] . Meanwhile, the MAML-using studies are located in a narrower band between 0.915 and 0.960. Meta-learning is elegant, but appears hard to get right in practice.

Convolutional neural networks

(CNN) serve as the feature extractor of choice across the included studies: beyond the four studies discussed here, six more use CNNs as FSL technique (see Table 2 ). Tong and Zhang [ 42 ] combine attention, a customized CNN, an Auto-Encoder and an adversarial discriminator into a self-supervised NIDS. Zhang et al. [ 53 ] pre-train and prune a CNN on general traffic. Then, they fine-tune it in a teacher-student twin setup, yielding a lightweight model. Their extensive parameter reporting is a positive example among the included studies. Xu et al. [ 48 ] fuse two modalities, namely grayscale images of packets handled by a CNN and statistical flow features handled by a transformer. Self-attention fusion worked best. Learned features are then preserved through transfer learning. In addition to OSL, Mirsadeghi et al. [ 33 ] utilize sampling and generation (SMOTE [ 8 ] , GANs [ 16 ] ) and weighted random forests in the software defined networking (SDN) domain. Regarding OSL, they use a twin CNN, which was outperformed by the weighted random forest regarding precision on some classes. CNNs bring in mixed results, but overall better than Meta-Learning approaches. Especially [ 48 ] and [ 52 ] achieve very good results on popular data sets, making them easily comparable.

Graph Neural Networks

(Graph NN) represent flows or hosts as nodes and their interactions as edges, allowing models to exploit the topology of attacks. Asante and Abass [ 5 ] combine adversarial graph contrastive learning with meta-learning on heterogeneous behavior graphs, achieving the best reported precision and F1-score of the included studies (0.996 on IoT-23). Qiu et al. [ 37 ] trace the inconsistent outcomes of earlier GNNs such as E-GraphSAGE [ 26 ] back to entangled feature distributions in the graph construction and address this with a five-stage model that disentangles graph representations. Invariants are captured by a projection-based few-shot model. Mao et al. [ 29 ] distribute contrastive and classification tasks over federated clients sharing only model weights. Graph approaches perform above average, with F 1 F_{1} -score ranging from 0.868 to 0.996. All three evaluate on datasets rarely used by other studies, which limits comparability.

Few-Shot Class-Incremental Learning

(FSCIL) addresses so-called catastrophic forgetting by adding new classes over time as they appear from few samples. Du et al. [ 12 ] reuse the encoder part of an Auto-Encoder trained on flow-based images within a vision-transformer architecture [ 11 ] and add session-trained projection layers, fusing them. Yin et al. [ 52 ] employ FSL to fine-tune a pre-trained CNN. This FSL is done by constructing a prototypical network using cosine similarity and a CosFace margin [ 43 ] , mitigating new attack types through an incremental few-shot process with a specialized loss. Although Yin et al. report no F1-score, their precision of 0.978 is among the best in the included studies.

learn compressed representations of traffic, either for reconstruction"=based pre-training or for generating new samples. Hang et al. [ 18 ] pre-train a masked Auto-Encoder on unlabeled traffic and then replace the decoder with a linear classifier for fine-tuning using FSL. Ayesha et al. [ 10 ] chain self-supervised learning with FSL using an Auto-Encoder and contrastive learning and last a kNN classifier. Auto-Encoders also appear as learning technique in two other studies [ 42 , 12 ] . This approach, combined with other techniques seems a promising attempt at few-shot learning.

Adapting from the field of natural language processing, Ye et al. [ 51 ] propose a text-based workflow based on Dirichlet generative learning, augmenting their few samples with synthetic ones based on semantics. Martinez-Lopez et al. [ 30 ] show that fusing four distance metrics (Chebyshev, Cosine, Euclidean, Wasserstein) outperforms single-metric prototypical few-shot learning. They use these prototypes to generate new datapoints. Jamshidi et al. [ 22 ] base their IoT defense on edge devices. They first construct an anomaly-detection, testing various ML techniques. After a detection, an LLM API call is issued, using the LLM to triage the incident. It is the only one among our included studies, that was built around an LLM.

This review set out to answer three research questions. Regarding RQ1 (learning technique), the field is dominated by meta-learning (8 of 21 studies) and convolutional neural networks (10 of 21), which are rarely used in isolation: 17 of 21 studies combine at least two techniques, most frequently meta-learning with CNNs (5 studies). Regarding RQ2 (datasets), CIC-IDS2017 and CSE-CIC-IDS2018 have emerged as de facto benchmark datasets (11 and 6 uses), and the reviewed studies evaluate on a median of three datasets each; at the same time, the long tail of single-use datasets means that many studies cannot be compared against any other. Regarding RQ3 (evaluation setting), most studies evaluate five or fewer samples per class, with k = 5 k=5 being the most common setting among the studies reporting k k , and 15 of 21 studies report an F 1 F_{1} -score. Reporting is incomplete in a relevant of studies: five omit k k , five omit n n , and most provide neither accessible source code nor full hyperparameters.

5.1 Interpretation and Implications

Our results support four main observations. First, the most widespread techniques (meta-learning with CNNs or builds on MAML) do not yield the strongest results, whereas graph neural networks and Auto-Encoder-based combinations achieve the highest reported scores. Second, technique adoption appears trend-driven: Auto-Encoders vanish from our set of studies after 2024 despite strong results, and graph neural networks emerge only in 2025–2026. Third, datasets shape reported performance at least as much as techniques on CIC-IDS2017 alone, reported F 1 F_{1} -scores range from 0.673 to 0.995 although the convergence on this benchmark family provides a partial basis for comparison.

For practitioners, CNN-based approaches evaluated on the de facto benchmark datasets currently offer the best comparability and hence the most reliable basis for adoption decisions. For researchers, our findings argue for a shared evaluation protocol: fixed n n -way/ k k -shot settings on common datasets, a defined metric set covering at least accuracy, precision, recall, and F 1 F_{1} -score, and mandatory disclosure of code and hyperparameters.

Our venue-based quality filter (a journal h 4 h_{4} -index of at least 53 according to [ 35 ] , or a conference ranked B or better in the CORE ranking) was necessary to keep the screening feasible. We acknowledge, however, that citation-based metrics vary considerably between research communities, so relevant work published in newer or lower-ranked venues may have been missed.

Screening, eligibility decisions, data extraction, and the design of the queries were carried out by one researcher. Although all decisions are documented through PRISMA-like reporting, which makes them traceable, a second reviewer would have reduced the subjectivity.

Finally, our synthesis is limited by the primary studies themselves: missing parameters and unavailable source code prevented us from verifying reported numbers, so our performance comparison relies on self-reported results obtained under heterogeneous settings.

Two directions for future work follow directly from our findings. First, a benchmark study that re-implements representative approaches from each technique family and evaluates them under a unified protocol with fixed n n and k k , common datasets, identical preprocessing, and a full metric set. This would turn the indications observed here into verifiable rankings. Publishing such a benchmark as a community artifact, together with a reporting checklist for few-shot NIDS studies, would directly address the reproducibility gaps identified above. Second, generalization across datasets remains essentially untested: none of our included studies trains and evaluates on disjoint datasets, so the robustness of these approaches to unseen network environments is unknown.

Few-shot learning addresses a central obstacle to learning-based intrusion detection: the scarcity of labeled attack data. In this work, we systematically reviewed recent few-shot learning approaches for NIDS using records retrieved from the ACM Digital Library, IEEE Xplore, and Scopus. Starting from 1,358 records published between 2022 and August 2026, we retained 21 peer-reviewed studies and analyzed their learning techniques, datasets, and evaluation settings.

Our analysis shows a field dominated by convolutional neural networks and meta-learning, typically combined with other techniques. The datasets CIC-IDS2017 and CSE-CIC-IDS2018 have emerged as de facto benchmarks and provide a partial basis for comparison. However, heterogeneous evaluation settings, incomplete parameter reporting, and largely unavailable source code still limit direct comparison and independent verification of reported results.

For few-shot NIDS to mature into deployable defenses, the community needs shared evaluation protocols and stronger reproducibility practices. We therefore advocate fixed n-way/k-shot settings on common datasets, consistent reporting of evaluation parameters and metrics, and the disclosure of source code and hyperparameters. A unified, openly reproducible benchmark, ideally complemented by cross-dataset evaluation, would be the most valuable step for assessing both performance and generalization.

Data availability statement

The data and scripts required to reproduce our results are available at .

The authors acknowledge the financial support by the Federal Ministry of Research, Technology and Space of Germany and by Sächsische Staatsministerium für Wissenschaft, Kultur und Tourismus in the programme Center of Excellence for AI-research „Center for Scalable Data Analytics and Artificial Intelligence Dresden/Leipzig“, project identification number: ScaDS.AI

[1] ACM ACM digital library . Note: Last accessed on Aug 9 2026 External Links: Link Cited by: §3 .

[2] M. Ahmed and Q. Abdullah (2025) Network intrusion detection systems: machine learning-based attack and remedy strategies – a review . Al-Salam Journal for Engineering and Technology . External Links: Link Cited by: §1 .

[3] M. Ahmed, A. Mahmood, and J. Hu (2016) A survey of network anomaly detection techniques . J. Netw. Comput. Appl. 60 , pp. 19–31 . External Links: Link Cited by: §1 , §1 .

[4] A. Aldweesh, A. Derhab, and A. Z. Emam (2020) Deep learning approaches for anomaly-based intrusion detection systems: a survey, taxonomy, and open issues . Knowledge-Based Systems 189 , pp. 105124 . External Links: Document Cited by: §2 .

[5] I. O. Asante and F. Abass (2026) Robust few-shot malware detection in iot via adversarial contrastive learning on heterogeneous behavior graphs . IEEE Internet of Things Journal ( ), pp. 1–1 . External Links: Document Cited by: Table 2 , Figure 3 , §4.3 , §4.4 , §4.4 , Table 5 .

[6] W. Ashraf and F. S. Masoodi (2026) A survey of intrusion detection datasets for communication networks . Discover Computing 29 . External Links: Document Cited by: §2 .

[7] E. B.V. Scopus . Note: Last accessed on Aug 11 2026 External Links: Link Cited by: §3 .

[8] N. V. Chawla, K. W. Bowyer, L. O. Hall, and W. P. Kegelmeyer (2002) SMOTE: synthetic minority over-sampling technique . Journal of artificial intelligence research 16 , pp. 321–357 . External Links: Document Cited by: §4.4 .

[9] H. Chen, F. Qamar, G. Guo, M. H. u. Rehman, and S. N. H. S. Abdullah (2026) Graph neural networks for iomt intrusion detection: modeling architectures, learning paradigms, and deployment challenges . IEEE Internet of Things Journal 13 ( 16 ), pp. 38313–38347 . External Links: Document Cited by: §3 .

[10] A. S. Dina, M. A. B. Siddique, and D. Manivannan (2023) FS3: few-shot and self-supervised framework for efficient intrusion detection in internet of things networks . In Proceedings of the 39th Annual Computer Security Applications Conference , ACSAC ’23 , pp. 138–149 . External Links: Document Cited by: Table 2 , Figure 3 , §4.3 , §4.4 , Table 5 .

[11] A. Dosovitskiy, L. Beyer, A. Kolesnikov, D. Weissenborn, X. Zhai, T. Unterthiner, M. Dehghani, M. Minderer, G. Heigold, S. Gelly, J. Uszkoreit, and N. Houlsby (2021) An image is worth 16x16 words: transformers for image recognition at scale . In International Conference on Learning Representations , External Links: Link Cited by: §4.4 .

[12] L. Du, Z. Gu, Y. Wang, L. Wang, and Y. Jia (2024) A few-shot class-incremental learning method for network intrusion detection . IEEE Transactions on Network and Service Management 21 ( 2 ), pp. 2389–2401 . External Links: Document Cited by: Table 2 , Figure 3 , §4.4 , §4.4 , Table 5 .

[13] R. Duan, D. Li, Q. Tong, T. Yang, X. Liu, and X. Liu (2021) A survey of few-shot learning: an effective method for intrusion detection . Security and Communication Networks 2021 ( 1 ), pp. 4259629 . External Links: Document Cited by: §2 , §2 .

[14] C. Finn, P. Abbeel, and S. Levine (2017) Model-agnostic meta-learning for fast adaptation of deep networks . In Proceedings of the 34th International Conference on Machine Learning - Volume 70 , ICML’17 , pp. 1126–1135 . External Links: Link Cited by: §4.4 .

[15] A. Garg (2026) A review of advancements in deep learning approaches for intrusion detection systems . Journal on Artificial Intelligence . External Links: Link Cited by: §1 .

[16] I. J. Goodfellow, J. Pouget-Abadie, M. Mirza, B. Xu, D. Warde-Farley, S. Ozair, A. Courville, and Y. Bengio (2014) Generative adversarial nets . In Advances in Neural Information Processing Systems , Vol. 27 , pp. . External Links: Link Cited by: §4.4 .

[17] M. Gupta, C. Akiri, K. Aryal, E. Parker, and L. Praharaj (2023) From chatgpt to threatgpt: impact of generative ai in cybersecurity and privacy . IEEE access 11 , pp. 80218–80245 . External Links: Document Cited by: §1 .

[18] Z. Hang, Y. Lu, Y. Wang, and Y. Xie (2023) Flow-mae: leveraging masked autoencoder for accurate, efficient and robust malicious traffic classification . In Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses , RAID ’23 , pp. 297–314 . External Links: ISBN 9798400707650 , Document Cited by: Table 2 , Figure 3 , §4.4 , Table 5 .

[19] J. Ho, A. Jain, and P. Abbeel (2020) Denoising diffusion probabilistic models . In Advances in Neural Information Processing Systems , Vol. 33 , pp. 6840–6851 . External Links: Link Cited by: §4.4 .

[20] ICORE ICORE conference rankings portal . Note: Last accessed on Aug 5, 2026 External Links: Link Cited by: §3 .

[21] IEEE IEEE xplore . Note: Last accessed on Aug 10 2026 External Links: Link Cited by: §3 .

[22] S. Jamshidi, O. A. Wahab, R. Herrero, F. Khomh, M. Bellaïche, S. Keivanpour, N. Shahabi, A. Nikanjam, and K. W. Nafi (2026) Think fast: real-time iot intrusion reasoning using ids and llms at the edge gateway . IEEE Internet of Things Journal 13 ( 8 ), pp. 15485–15513 . External Links: Document Cited by: Table 2 , Figure 3 , §4.4 , Table 5 .

[23] A. Khraisat, I. Gondal, P. Vamplew, and J. Kamruzzaman (2019) Survey of intrusion detection systems: techniques, datasets and challenges . Cybersecurity 2 . External Links: Link Cited by: §1 , §1 .

[24] B. Kitchenham and S. Charters (2007) Guidelines for performing systematic literature reviews in software engineering . EBSE Technical Report Technical Report EBSE-2007-01 , Keele University and University of Durham . Note: Version 2.3 External Links: Link Cited by: §1 , §3 .

[25] J. Lansky, S. Ali, M. Mohammadi, M. K. Majeed, S. H. T. Karim, S. Rashidi, M. Hosseinzadeh, and A. M. Rahmani (2021) Deep learning-based intrusion detection systems: a systematic review . IEEE Access 9 ( ), pp. 101574–101599 . External Links: Document Cited by: §2 .

[26] W. W. Lo, S. Layeghy, M. Sarhan, M. Gallagher, and M. Portmann (2022) E-graphsage: a graph neural network based intrusion detection system for iot . In NOMS 2022-2022 IEEE/IFIP Network Operations and Management Symposium , Vol. , pp. 1–9 . External Links: Document Cited by: §4.4 .

[27] C. Lu, X. Wang, A. Yang, Y. Liu, and Z. Dong (2023) A few-shot-based model-agnostic meta-learning for intrusion detection in security of internet of things . IEEE Internet of Things Journal 10 ( 24 ), pp. 21309–21321 . External Links: Document Cited by: Table 2 , Figure 3 , §4.4 , Table 5 .

[28] Y. Lu, Y. Lu, Z. Wang, W. Wu, C. Ke, and S. Liu (2026) D-maml: a few-shot learning algorithm for intrusion detection based on meta-learning and diffusion models . IEEE Internet of Things Journal , pp. . External Links: Document Cited by: Table 2 , Figure 3 , §4.4 , Table 5 .

[29] Q. Mao, X. Lin, W. Xu, Y. Qi, X. Su, G. Li, and J. Li (2025) FeCoGraph: label-aware federated graph contrastive learning for few-shot network intrusion detection . IEEE Transactions on Information Forensics and Security 20 ( ), pp. 2266–2280 . External Links: Document Cited by: Table 2 , Figure 3 , §4.4 , Table 5 .

[30] F. Martinez-Lopez, L. Santana, M. Rahouti, A. Chehri, S. Al-Maliki, and G. Jeon (2026) Learning in multiple spaces: prototypical few-shot learning with metric fusion for -generation network security . IEEE Transactions on Network and Service Management 23 ( ), pp. 3156–3165 . External Links: Document Cited by: Table 2 , Figure 3 , §4.4 , Table 5 .

[31] Z. K. Maseer, Q. K. Kadhim, B. Al-Bander, R. Yusof, and A. Saif (2024) Meta-analysis and systematic review for anomaly network intrusion detection systems: detection methods, dataset, validation methodology, and challenges . IET Networks 13 ( 5-6 ), pp. 339–376 . External Links: Document Cited by: §2 .

[32] G. Miao, G. Wu, Z. Zhang, Y. Tong, and B. Lu (2023) SPN: a method of few-shot traffic classification with out-of-distribution detection based on siamese prototypical network . IEEE Access 11 ( ), pp. 114403–114414 . External Links: Document Cited by: Table 2 , Figure 3 , §4.4 , Table 5 .

[33] S. M. H. Mirsadeghi, H. Bahsi, R. Vaarandi, and W. Inoubli (2023) Learning from few cyber-attacks: addressing the class imbalance problem in machine learning-based intrusion detection in software-defined networking . IEEE Access 11 ( ), pp. 140428–140442 . External Links: Document Cited by: Table 2 , Figure 3 , §4.4 , Table 5 .

[34] N. Moustafa and J. Slay (2015) UNSW-NB15: a comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set) . In 2015 Military Communications and Information Systems Conference (MilCIS) , Vol. , pp. 1–6 . External Links: Document Cited by: §4.2 .

[35] A. Pacher The observatory of international research . Note: Last accessed on Aug 5, 2026 External Links: Link Cited by: §3 , §5.2 .

[36] M. J. Page, J. E. McKenzie, P. M. Bossuyt, I. Boutron, T. C. Hoffmann, C. D. Mulrow, L. Shamseer, J. M. Tetzlaff, E. A. Akl, S. E. Brennan, R. Chou, J. Glanville, J. M. Grimshaw, A. Hróbjartsson, M. M. Lalu, T. Li, E. W. Loder, E. Mayo-Wilson, S. McDonald, L. A. McGuinness, L. A. Stewart, J. Thomas, A. C. Tricco, V. A. Welch, P. Whiting, and D. Moher (2021) The prisma 2020 statement: an updated guideline for reporting systematic reviews . BMJ 372 . External Links: Document Cited by: §1 , §3 .

[37] C. Qiu, G. Nan, H. Xia, Z. Weng, X. Wang, M. Shen, X. Tao, and J. Liu (2025) Disentangled dynamic intrusion detection . IEEE Transactions on Pattern Analysis and Machine Intelligence 47 ( 11 ), pp. 10528–10545 . External Links: Document Cited by: Table 2 , Figure 3 , §4.3 , §4.4 , Table 5 .

[38] I. Sharafaldin, A. H. Lashkari, and A. A. Ghorbani (2018) Toward generating a new intrusion detection dataset and intrusion traffic characterization . In International Conference on Information Systems Security and Privacy , External Links: Link Cited by: §4.2 .

[39] I. Sharafaldin, A. H. Lashkari, and A. A. Ghorbani (2018) Toward generating a new intrusion detection dataset and intrusion traffic characterization . In International Conference on Information Systems Security and Privacy , External Links: Link Cited by: §4.2 .

[40] Y. Song, T. Wang, P. Cai, S. K. Mondal, and J. P. Sahoo (2023) A comprehensive survey of few-shot learning: evolution, applications, challenges, and opportunities . ACM Computing Surveys 55 ( 13s ), pp. 1–40 . External Links: Document , Link Cited by: §2 .

[41] H. Sun, L. Wan, M. Liu, and B. Wang (2023) Few-shot network intrusion detection based on prototypical capsule network with attention mechanism . PLoS ONE 18 ( 4 April ), pp. . External Links: Document Cited by: Table 2 , Figure 3 , §4.4 , Table 5 .

[42] J. Tong and Y. Zhang (2024) A real-time label-free self-supervised deep learning intrusion detection for handling new type and few-shot attacks in iot networks . IEEE Internet of Things Journal 11 ( 19 ), pp. 30769–30786 . External Links: Document Cited by: Table 2 , Figure 3 , §4.3 , §4.4 , §4.4 , Table 5 .

[43] H. Wang, Y. Wang, Z. Zhou, X. Ji, D. Gong, J. Zhou, Z. Li, and W. Liu (2018) CosFace: large margin cosine loss for deep face recognition . In 2018 IEEE/CVF Conference on Computer Vision and Pattern Recognition , Vol. , pp. 5265–5274 . External Links: Document Cited by: §4.4 .

[44] W. Wang, M. Zhu, X. Zeng, X. Ye, and Y. Sheng (2017) Malware traffic classification using convolutional neural network for representation learning . In 2017 International Conference on Information Networking (ICOIN) , Vol. , pp. 712–717 . External Links: Document Cited by: §4.2 .

[45] Y. Wang, Q. Yao, J. T. Kwok, and L. M. Ni (2020) Generalizing from a few examples: a survey on few-shot learning . ACM computing surveys (csur) 53 ( 3 ), pp. 1–34 . External Links: Document Cited by: §1 , §2 .

[46] E. Winiecki, M. Pawlicki, A. Pawlicka, R. Kozik, and M. Choraś (2025) Evaluation of selected few-shot learning methods in network intrusion detection . In Advanced Information Networking and Applications , pp. 10–20 . External Links: Document Cited by: §2 .

[47] M. Wu, Y. Zheng, Y. Yang, J. Luo, and D. S. Wong (2026) A semi-supervised meta-negative-learning approach to few-shot network intrusion detection in internet of things . IEEE Internet of Things Journal 13 ( 7 ), pp. 12974–12987 . External Links: Document Cited by: Table 2 , Figure 3 , §4.4 , Table 5 .

[48] C. Xu, Y. Zhan, Z. Wang, and J. Yang (2025) Multimodal fusion based few-shot network intrusion detection system . Scientific Reports 15 ( 1 ), pp. . External Links: Document Cited by: Table 2 , Figure 3 , §4.3 , §4.4 , Table 5 .

[49] C. Xu, F. Zhang, Z. Yang, Z. Zhou, and Y. Zheng (2025) A few-shot network intrusion detection method based on mutual centralized learning . Scientific Reports 15 ( 1 ), pp. . External Links: Document Cited by: Table 2 , Figure 3 , §4.4 , Table 5 .

[50] C. Yang, Z. Gu, J. Bai, Z. Li, G. Xiong, G. Gou, S. Yao, and X. Chen (2024) Few-shot encrypted traffic classification: a survey . In 2024 Asia-Pacific Conference on Image Processing, Electronics and Computers (IPEC) , pp. 646–652 . External Links: Document Cited by: §2 .

[51] T. Ye, G. Li, I. Ahmad, C. Zhang, X. Lin, and J. Li (2022) FLAG: few-shot latent dirichlet generative learning for semantic-aware traffic detection . IEEE Transactions on Network and Service Management 19 ( 1 ), pp. 73–88 . External Links: Document Cited by: §1 , Table 2 , Figure 3 , §4.3 , §4.4 , Table 5 .

[52] Z. Yin, W. Wang, Y. Cheng, Y. Liu, and X. Lu (2026) Efficient intrusion detection for edge network via multi-stage few-shot class-incremental learning . IEEE Transactions on Network Science and Engineering 13 ( ), pp. 4689–4706 . External Links: Document Cited by: Table 2 , Figure 3 , §4.3 , §4.4 , §4.4 , Table 5 .

[53] X. Zhang, Y. Wang, G. Han, and G. Gui (2025) Advanced few-shot network intrusion detection method using lightweight transfer learning . IEEE Internet of Things Journal 12 ( 22 ), pp. 48678–48688 . External Links: Document Cited by: §1 , Table 2 , Figure 3 , §4.4 , Table 5 .

[54] Y. Zhang, Y. Liu, Y. Wu, S. Zhao, and Z. Liu (2026) MAML-samiot: a cloud-fog computing and maml-based few-shot iot intrusion detection model . Computer Networks 275 , pp. . External Links: Document Cited by: Table 2 , Figure 3 , §4.4 , Table 5 .

[55] D. Zhou, Q. Wang, Z. Qi, H. Ye, D. Zhan, and Z. Liu (2024) Class-incremental learning: a survey . IEEE Transactions on Pattern Analysis and Machine Intelligence 46 ( 12 ), pp. 9851–9873 . External Links: Document Cited by: §2 .