Class imbalance in network intrusion detection makes minority attack classes particularly challenging to identify. To address this issue, we proposed META-VAEGAN-DNN, a novel intrusion detection framework that integrated meta-learning with a variational autoencoder generative adversarial network (VAE-GAN). A META-VAEGAN-based augmentation model was first developed to alleviate class imbalance, followed by a differentiated sample processing strategy with a progressive quality filtering mechanism designed to enhance the generation of minority-class instances. The augmented data were then classified using a deep neural network (DNN) enhanced with channel attention and multi-layer residual connections. Experiments on the NSL-KDD dataset demonstrate that META-VAEGAN-DNN achieves 89% accuracy, 90% F1-score, and 98% AUC. Notably, the precision and recall of the U2R class reach 98% and 99%, respectively, while those of the R2L class reach 99% and 73%, substantially outperforming conventional methods. These results highlight the effectiveness of META-VAEGAN-DNN in improving the detection of minority attack categories and enhancing overall intrusion detection performance. Supplementary validation on the CIC-IDS-2017 dataset further demonstrates the generalizability of the model.
HeJ X, WangX D, SongY F, et al. Network intrusion detection based on conditional Wasserstein variational autoencoder with generative adversarial network and one-dimensional convolutional neural networks[J]. Applied Intelligence, 2023, 53(10): 12416-12436 .
[2]
WangS, WangZ L, ZhouT, et al. THREATRACE: detecting and tracing host-based threats in node level through provenance graph learning[J]. IEEE Transactions on Information Forensics and Security, 2022, 17: 3972-3987.
YanHaitao, ZhangZhiyi, ZhuXiaoming, et al. Network intrusion detection based on WOA-XGBoost model[J]. Computer Measurement & Control, 2023, 31(3): 127-133. (in Chinese)
[5]
HamidY, SugumaranM. A t-SNE based non linear dimension reduction for network intrusion detection[J]. International Journal of Information Technology, 2020, 12(1): 125-134.
LiuGuangrui, ZhangWeizhe, LiXinjie. Data contamination defense method for intelligent network intrusion detection systems based on edge examples[J]. Journal of Computer Research and Development, 2022, 59(10): 2348-2361. (in Chinese)
[8]
LiuZ H, LiuS Q, ZhangJ. An industrial intrusion detection method based on hybrid convolutional neural networks with improved TCN[J]. Computers, Materials & Continua, 2024, 78(1): 411-433.
[9]
ImranaY, XiangY, AliL, et al.CNN-GRU-FF: a double-layer feature fusion-based network intrusion detection system using convolutional neural network and gated recurrent units[J].Complex & Intelligent Systems, 2024, 10(3): 3353-3370.
[10]
ChaléM, CoxB, WeirJ, et al.Constrained optimization based adversarial example generation for transfer attacks in network intrusion detection systems[J]. Optimization Letters, 2024, 18(9): 2169-2188.
FengYingyin, ShiZhibin.Network intrusion detection based on CNN on unbalanced data[J]. Journal of North University of China(Natural Science Edition),2021, 42(4): 318-324. (in Chinese)
WangHuazhong, TianZilei. Intrusion detection method of ICS based on improved CGAN algorithm[J]. Netinfo Security, 2023, 23(1): 36-43. (in Chinese)
[15]
YangY, LiuX Y, WangD L, et al. A CE-GAN based approach to address data imbalance in network intrusion detection systems[J]. Scientific Reports, 2025, 15: 7916.
[16]
KangF Y, FengT, LinJ Q.VAE-GAN-guided cross-class generation: a class imbalance data augmentation method for network intrusion detection[J]. Electronics, 2025, 14(11): 2103.
[17]
YuanL X, YuS Y, YangZ B, et al. A data balancing approach based on generative adversarial network[J]. Future Generation Computer Systems, 2023, 141: 768-776.
YangA, LuC, LiJ, et al. Application of meta-learning in cyberspace security: a survey[J]. Digital Communications and Networks, 2023, 9(1): 67-78.
[20]
HabeckM, HasenpflugM, KodgirwarS, et al. Geodesic slice sampling on the sphere[PP/OL].Vl.arXiv(2023-01-19)[2025-09-05].
[21]
CholakoskaA, ShushlevskaM, TodorovZ, et al. Analysis of machine learning classification techniques for anomaly detection with NSL-KDD data set[M]//Data Science and Intelligent Systems. Cham: Springer International Publishing, 2021: 258-267.
[22]
SharafaldinI, LashkariA H, GhorbaniA A. Toward generating a new intrusion detection dataset and intrusion traffic characterization[C]//Proceedings of the 4th International Conference on Information Systems Security and Privacy, 2018: 108-116.
[23]
TavallaeeM, BagheriE, LuW, et al.A detailed analysis of the KDD CUP 99 data set[C]//IEEE Symposium on Computational Intelligence for Security & Defense Applications, 2009: 1-6.
[24]
AbdelkhalekA, MashalyM. Addressing the class imbalance problem in network intrusion detection systems using data resampling and deep learning[J]. The Journal of Supercomputing, 2023, 79(10): 10611-10644.
[25]
ShanmugamV, Razavi-FarR, HallajiE.Addressing class imbalance in intrusion detection: A comprehensive evaluation of machine learning approaches[J]. Electronics, 2024, 14(1): 69.
YuChanghong, XuKonghao, ZhangZe, et al. Improving network intrusion detection methods in isolated forests based on split points[J]. Computer Engineering, 2024, 50(6): 148-156. (in Chinese)
[28]
Díaz-CotoS, Corral-BlancoN O, Martínez-CamblorP. Two-stage receiver operating-characteristic curve estimator for cohort studies[J]. The International Journal of Biostatistics, 2021, 17(1): 117-137.
[29]
HuangH Y, WangY F, RudinC, et al. Towards a comprehensive evaluation of dimension reduction methods for transcriptomic data visualization[J]. Communications Biology, 2022, 5(1): 719.
[30]
WongvorachanT, HeS, BulutO.A comparison of undersampling, oversampling, and smote methods for dealing with imbalanced classification in educational data mining[J]. Information, 2023, 14(1): 54.
JohnsonJ M, KhoshgoftaarT M.Survey on deep learning with class imbalance[J]. Journal of Big Data, 2019, 6(1): 27.
[33]
HeH, BaiY, GarciaE A, et al.ADASYN: adaptive synthetic sampling approach for imbalanced learning[C]//2008 IEEE International Joint Conference on Neural Networks (IEEE World Congress on Computational Intelligence), 2008: 1322-1328.
HuangYingchun, XingXiuqi. Networkintrusion detection method based on fusion of CNN-GRU and transformer[J]. Fire Control and Command Control, 2025, 50(6): 21-27. (in Chinese)
WeiMingjun, YanXuwen, JiZhanlin, et al. Research on intrusion detection based on CNN and LightGBM[J]. Journal of Zhengzhou University (Natural Science Edition), 2023, 55(6): 35-40. (in Chinese)
HeJiaxing, WangXiaodan, SongYafei, et al. CWGAN-DNN: An intrusion detection method based on conditional wasserstein generative adversarial network[J]. Journal of Air Force Engineering University (Natural Science Edition), 2021, 22(5): 67-74. (in Chinese)
[41]
LiH T, WangR M, DongW Y, et al. Semi-supervised network traffic anomaly detection method based on GRU[J]. Computer Science, 2023, 50(3): 380-390.
[42]
CavilleE, LoW W, LayeghyS, et al. Anomal-E: a self-supervised network intrusion detection system based on graph neural networks[J]. Knowledge-Based Systems, 2022, 258: 110030.
LiCongcong, YuanZilong, TengGuifa. Research on deep learning-based spatio-temporal feature fusion network intrusion detection model[J]. Journal of Information Security Research, 2025, 11(2): 122-129. (in Chinese)