International Journal of Advanced Technology and Engineering Exploration ISSN (Print): 2394-5443    ISSN (Online): 2394-7454 Volume-13 Issue-140 July-2026
  1. 4923
    Citations
  2. 2.8
    CiteScore
Behavioral instability in anomaly-based intrusion detection systems under concept drift: blindness from to sensitivity inflation

Mohammad M. Rasheed1 and Mustafa Muwafak Alobaedy2

Government College of Engineering,University of Information Technology and Communications,Baghdad, 10013,Iraq1
Centre for Image and Vision Computing,Multimedia University, Persiaran Multimedia, Cyberjaya, 63100,Selangor,Malaysia2
Corresponding Author : Mohammad M. Rasheed

Recieved : 26-March-2026; Revised : 19-July-2026; Accepted : 21-July-2026

Abstract

Anomaly-based intrusion detection systems (IDS) are commonly evaluated under the assumption that network traffic remains stationary over time. However, in real-world deployments, they are continuously exposed to concept drift. Such drift can allow aggregate performance metrics, such as the F1-score, to remain apparently acceptable while concealing significant changes in detector behaviour. Rather than determining whether concept drift degrades overall performance, this study aims to characterize its impact on anomaly detection over time and identify distinct behavioural failure modes. To achieve this, three benchmark intrusion detection datasets, CIC-IoT-2023, Edge-industrial IoT (Edge-IIoTset), and UNSW-NB15, representing diverse class distributions are evaluated using a unified temporal evaluation framework. The results demonstrate that concept drift does not produce a uniform pattern of performance degradation. Instead, it leads to distinct behavioural outcomes, including total blindness, sensitivity inflation, and relatively stable detection. Across all experimental settings, the isolation forest (IF) consistently exhibited the greatest behavioural instability. On the Edge-IIoTset dataset, its recall remained close to zero, whereas the Gaussian mixture model (GMM) and autoencoder (AE) achieved near-perfect detection in attack-containing segments. These findings suggest that aggregate performance metrics alone can obscure operationally significant failure modes and that temporal behavioural evaluation provides a more realistic and deployment-oriented assessment of IDS reliability in dynamic cybersecurity environments.

Keywords

Concept drift, Intrusion detection system (IDS), Anomaly-based intrusion detection, Isolation forest (IF), Temporal evaluation, Behavioral analysis.

Cite this article

Rasheed MM, Alobaedy MM. Behavioral instability in anomaly-based intrusion detection systems under concept drift: blindness from to sensitivity inflation. International Journal of Advanced Technology and Engineering Exploration. 2026;13(140):275-302. DOI : 10.19101/IJATEE.2026.131340379

References
[1]
Thakkar A, Lohiya R. A review on challenges and future research directions for machine learning-based intrusion detection system. Archives of Computational Methods in Engineering. 2023; 30(7):4245-69.
[2]
Morshedi R, Matinkhah SM. A comprehensive review of deep learning techniques for anomaly detection in IoT networks: methods, challenges, and datasets. Engineering Reports. 2025; 7(9):1-29.
[3]
Mallidi SK, Ramisetty RR. Optimizing intrusion detection for IoT: a systematic review of machine learning and deep learning approaches with feature selection and data balancing. Wiley Interdisciplinary Reviews: Data Mining and Knowledge Discovery. 2025; 15(2): e70008.
[4]
Sommer R, Paxson V. Outside the closed world: on using machine learning for network intrusion detection. In symposium on security and privacy 2010 (pp. 305-16). IEEE.
[5]
Arp D, Quiring E, Pendlebury F, Warnecke A, Pierazzi F, Wressnegger C, et al. Dos and don'ts of machine learning in computer security. In 31st USENIX security symposium 2022 (pp. 3971-88).
[6]
Gama J, Žliobaitė I, Bifet A, Pechenizkiy M, Bouchachia A. A survey on concept drift adaptation. ACM Computing Surveys. 2014; 46(4):1-37.
[7]
Shyaa MA, Ibrahim NF, Zainol Z, Abdullah R, Anbar M, Alzubaidi L. Evolving cybersecurity frontiers: a comprehensive survey on concept drift and feature dynamics aware machine and deep learning in intrusion detection systems. Engineering Applications of Artificial Intelligence. 2024; 137:1-34.
[8]
Jordaney R, Sharad K, Dash SK, Wang Z, Papini D, Nouretdinov I, et al. Transcend: detecting concept drift in malware classification models. In 26th USENIX security symposium 2017 (pp. 625-42).
[9]
Pendlebury F, Pierazzi F, Jordaney R, Kinder J, Cavallaro L. {TESSERACT}: eliminating experimental bias in malware classification across space and time. In 28th USENIX security symposium 2019 (pp. 729-46).
[10]
Andresini G, Pendlebury F, Pierazzi F, Loglisci C, Appice A, Cavallaro L. Insomnia: towards concept-drift robustness in network intrusion detection. In proceedings of the 14th ACM workshop on artificial intelligence and security 2021 (pp. 111-22). ACM.
[11]
Yang S, Zheng X, Li J, Xu J, Wang X, Ngai EC. Recda: concept drift adaptation with representation enhancement for network intrusion detection. In proceedings of the 30th ACM SIGKDD conference on knowledge discovery and data mining 2024 (pp. 3818-28). ACM.
[12]
Rasheed MM, Faaeq MK. Behavioral detection of scanning worm in cyber defense. In proceedings of the future technologies conference 2018 (pp. 214-25). Cham: Springer International Publishing.
[13]
Gama J, Medas P, Castillo G, Rodrigues P. Learning with drift detection. In Brazilian symposium on artificial intelligence 2004 (pp. 286-95). Berlin, Heidelberg: Springer Berlin Heidelberg.
[14]
Chu R, Jin P, Qiao H, Feng Q. Intrusion detection in the IoT data streams using concept drift localization. AIMS Mathematics. 2023; 9(1):1535-61.
[15]
Shyaa MA, Zainol Z, Abdullah R, Anbar M, Alzubaidi L, Santamaría J. Enhanced intrusion detection with data stream classification and concept drift guided by the incremental learning genetic programming combiner. Sensors. 2023; 23(7):1-34.
[16]
Xu L, Ding X, Peng H, Zhao D, Li X. ADTCD: an adaptive anomaly detection approach toward concept drift in IoT. IEEE Internet of Things Journal. 2023; 10(18):15931-42.
[17]
Mohale VZ, Obagbuwa IC. Evaluating machine learning-based intrusion detection systems with explainable AI: enhancing transparency and interpretability. Frontiers in Computer Science. 2025; 7:1-23.
[18]
Hashim A, Rasheed M, Abdullah S. Analysis of bluetooth low energy based indoor localization system using machine learning algorithms. Journal of Engineering Science and Technology. 2021; 16(4):2816-24.
[19]
Barbero F, Pendlebury F, Pierazzi F, Cavallaro L. Transcending transcend: revisiting malware classification in the presence of concept drift. In IEEE symposium on security and privacy (SP) 2022 (pp. 805-23). IEEE.
[20]
Haque A, Soliman H. A transformer-based autoencoder with isolation forest and XGBoost for malfunction and intrusion detection in wireless sensor networks for forest fire prediction. Future Internet. 2025; 17(4):1-12.
[21]
Bifet A, Gavalda R. Learning from time-changing data with adaptive windowing. In proceedings of the SIAM international conference on data mining 2007 (pp. 443-8). Society for Industrial and Applied Mathematics.
[22]
Bagui SS, Khan MP, Valmyr C, Bagui SC, Mink D. Model retraining upon concept drift detection in network traffic big data. Future Internet. 2025; 17(8):1-24.
[23]
Hussein SA, Répás SR. A hybrid intrusion detection framework using deep autoencoder and machine learning models. AI. 2026; 7(2):1-31.
[24]
Bachar M, Khiat A, El GK. Hybrid autoencoder and isolation forest for IoT anomaly detection with a novel model. Engineering, Technology & Applied Science Research. 2026; 16(1):31123-9.
[25]
Seth S, Chahal KK, Singh G. Concept drift–based intrusion detection for evolving data stream classification in ids: approaches and comparative study. The Computer Journal. 2024; 67(7):2529-47.
[26]
Horchulhack P, Viegas EK, Lopez MA. A stream learning intrusion detection system for concept drifting network traffic. In 6th cyber security in networking conference (CSNet) 2022 (pp. 1-7). IEEE.
[27]
Wahab OA. Intrusion detection in the IoT under data and concept drifts: online deep learning approach. IEEE Internet of Things Journal. 2022; 9(20):19706-16.
[28]
Neto EC, Dadkhah S, Ferreira R, Zohourian A, Lu R, Ghorbani AA. CICIoT2023: a real-time dataset and benchmark for large-scale attacks in IoT environment. Sensors. 2023; 23(13):1-26.
[29]
Ferrag MA, Friha O, Hamouda D, Maglaras L, Janicke H. Edge-IIoTset: a new comprehensive realistic cyber security dataset of IoT and IIoT applications for centralized and federated learning. IEEE Access. 2022; 10:40281-306.
[30]
Moustafa N, Slay J. UNSW-NB15: a comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set). In military communications and information systems conference (MilCIS) 2015 (pp. 1-6). IEEE.
[31]
Liu FT, Ting KM, Zhou ZH. Isolation forest. In eighth international conference on data mining 2008 (pp. 413-22). IEEE.
[32]
Reynolds DA. Gaussian mixture models. Encyclopedia of Biometrics. 2009; 741(659-63):3.
[33]
Youden WJ. Index for rating diagnostic tests. Cancer. 1950; 3(1):32-5.