Logo image
A Lightweight Agentic Self-Adaptive Intrusion Detection System for Flow-Based Network Traffic
Conference proceeding   Peer reviewed

A Lightweight Agentic Self-Adaptive Intrusion Detection System for Flow-Based Network Traffic

Mahmudul Islam Prakash, A B M Kamrul Islam Riad, Md Emran, Sajida Shabanali, Ishraq Karim, Tasnim Tawhid, Shafayet Jamil Hossain and Hossain Shahriar
Proceedings : annual International Computer Software and Applications Conference, pp.2563-2568
Annual Computers, Software, and Applications Conference (COMPSAC), 50th (Madrid, Spain, 07/07/2026–07/10/2026)
08/2026

Metrics

1 Record Views

Abstract

Adaptive Intrusion Detection Agentic AI Concept drift Flow-Based Detection Intrusion Detection Systems (IDS) Lightweight Models observe-decide-act loop Artificial Intelligence or Cybernetics Cybersecurity
Most intrusion detection systems (IDS) rely on static models trained on historical network data, making them susceptible to performance degradation as cyber threats evolve. This challenge, commonly referred to as concept drift, limits the effectiveness of conventional detection approaches in dynamic environments. This paper proposes a lightweight adaptive intrusion detection framework that integrates a simple classification model with an agentic feedback mechanism. Logistic regression is employed as the core classifier due to its efficiency and interpretability, while an autonomous controller continuously monitors key performance indicators, including false positive and false negative rates and prediction confidence. When performance degradation is detected, the system dynamically adjusts decision thresholds or performs lightweight retraining to maintain stability. The framework operates through an observe-decide-act loop, enabling autonomous adaptation without reliance on complex neural architectures. Experiments conducted on the CIC-IDS2017 dataset using time-segmented flows to simulate evolving attack patterns demonstrate that the proposed approach achieves improved stability compared to static and periodically updated models. These results highlight the effectiveness of simple, selfadaptive models for real-time, interpretable, and efficient intrusion detection.

Details

Logo image