MARATTO

article · Array

Snort-AFL: An explainable hybrid intrusion detection framework for imbalanced critical infrastructure networks using contrastive few-shot learning

2026Open accessNorth-West University

Abstract

Critical infrastructure sectors such as information technology, telecommunications, and energy depend on robust and adaptive network security solutions to ensure operational continuity and resilience against cyber threats. Intrusion Detection Systems (IDS) are essential in protecting these networks; however, existing IDS methods frequently suffer from inadequate detection accuracy and significant false positive rates, particularly in imbalanced network environments where normal traffic dominates. To counter these problems, this research proposed Snort Adaptive Few-Shot Learning (Snort-AFL), a Hybrid IDS designed to improve critical infrastructure networks' security. Snort-AFL integrates Snort’s rule-based signature detection with an attention-enhanced few-shot Long Short-Term Memory (LSTM) network, augmented by contrastive learning and focal loss. The system optimizes Snort’s signature matching using hashing and Radix Sort for efficient detection of known threats. Simultaneously, the attention-enhanced few-shot LSTM identifies previously unseen intrusions by leveraging critical temporal patterns in network traffic. The incorporation of focal loss addresses class imbalance by prioritizing minority class samples, improving the detection of rare but impactful attacks. This hybrid approach ensures low latency for known threats while enhancing the detection of new and intricate intrusions, offering a balanced solution for low false positives and high accuracy. Explainable AI was integrated to interpret the decision-making process of Snort-AFL. Experiments conducted on benchmark data (NSL-KDD, CSE-CIC-IDS2018, and IEC 60870-5-104) revealed Snort-AFL outperforms traditional IDS and existing hybrid techniques by achieving 99.0% and 96.2 accuracy and precision respectively while also performing better in terms of false negatives, F1-score, recall, detection time, accuracy, false positives, and throughput. By integrating signature-based precision with anomaly-based adaptability, Snort-AFL provides a comprehensive solution for protecting critical infrastructure against both known and emerging threats. This research constitutes an important development in intrusion detection, offering a workable and efficient approach for protecting critical infrastructure in imbalanced network environments.

Research topics

  • Network Security and Intrusion Detection
  • Anomaly Detection Techniques and Applications
  • Software System Performance and Reliability

Sustainable Development Goals

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.1016/j.array.2026.101160

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.