The Next Frontier in Network Security: A Comprehensive Review on Few-Shot Learning for Intrusion Detection
Ayman Bamarshad, Morched Derbali, Tarig Mohamed Ahmed, Mutasem JarrahThe use of Intrusion Detection Systems (IDS) is fundamental to the protection of contemporary networks which are increasingly vulnerable to sophisticated and evolving cyber-attacks and within environments that do not possess labeled data and where attacks are appearing for the first time. Often, previous IDS approaches are sub-performers as they generally rely on larger amounts of labeled data or static signature sets, especially in the context of zero-day attacks or rare events. This Systematic Literature Review (SLR) examines the deployment of Few-Shot Learning (FSL) as a novel approach to counter these limitations. This review offers a systematic review of over 50 relatively recent studies. It examines metric-based, meta-learning, transformer-based and federated FSL approaches with IDS. This review also focuses on models designed for FSL in IoT networks, cloud-based architectures and edge environments outlining hybrid approaches that incorporate FSL with generative models, reinforcement learning or causal inference. The review considers pivotal benchmark datasets such as NSL-KDD, CIC-IDS2017, BoT-IoT and TON-IoT and the empirical backdrop they provide to FSL-based IDS. Our conclusion indicates that FSL is a viable solution for improving detection accuracy for those attacks being considered zero-day while keeping low false positive rates especially when deployed with explainable AI systems and light-weight architecture into production. Finally, the review identifies prominent research obstacles and future trajectories: the need for standardized evaluation procedures, further cross-domain generalization and creating scalable, explainable IDS systems with FSL.