Bidirectional Cross-Dataset Generalization and Label-Efficient Adaptation for 5G Network Intrusion Detection

Authors

DOI:

https://doi.org/10.63318/waujpasv4i2_24

Keywords:

5G intrusion detection, Cross-dataset generalization, Dataset fingerprint, Domain shift, Label-efficient adaptation, Active learning, Open RAN security

Abstract

Machine-learning-based intrusion detection in 5G networks is often assessed using a single dataset, where strong test results may indicate regularities tied to that dataset rather than attack behavior that generalizes across settings. This study examines bidirectional cross-dataset generalization between 5G-NIDD and NetsLab-5GORAN-IDD through conservative semantic matching of denial-of-service, flooding, and scanning attacks. The assessment uses five-seed zero-shot transfer, a multivariate dataset-fingerprint audit, unsupervised correlation alignment, few-shot target adaptation, and class-blind target-label selection while varying attack prevalences in a controlled manner at 1%, 5%, and 10%. Zero-shot XGBoost performance was highly dependent on both the specific task and the direction of transfer. For matched aggregate tasks, balanced accuracy was 0.518 and 0.505 for application-layer denial-of-service, 0.807 and 0.500 for network/transport flooding, and 0.834 and 0.558 for scanning when transferring from 5G-NIDD to NetsLab and in the reverse direction, respectively. A dataset-source classifier reached balanced accuracy of 0.993 when using all 15 harmonized numerical features and maintained 0.993 after source-predictiveness-aware Top-6 filtering, indicating that dataset identity persisted across multivariate feature interactions. CORAL did not eliminate this fingerprint, whereas using limited target labels produced much larger improvements; in the exploratory adaptation experiment, the mean best gain with no more than 5% labeled target data was 0.346 balanced-accuracy points. Under deployment-like prevalence pressure, Random or Diversity-based querying provided the best overall strategy in 13 of 15 prevalence-budget conditions, while source-model uncertainty sampling was unstable. Overall, these findings indicate that realistic 5G intrusion detection depends on explicit cross-dataset evaluation and limited, target-specific supervision rather than on performance from a single dataset, feature filtering, or straightforward distribution alignment.

Downloads

Download data is not yet available.

Downloads

Published

2026-08-07

How to Cite

Abraheem, A., & Edhirig, A. (2026). Bidirectional Cross-Dataset Generalization and Label-Efficient Adaptation for 5G Network Intrusion Detection. Wadi Alshatti University Journal of Pure and Applied Sciences, 4(2), 200-214. https://doi.org/10.63318/waujpasv4i2_24