AGENTIC AI FOR CONTINUOUS CONCEPT-DRIFT MONITORING AND AUTONOMOUS RETRAINING IN MACHINE-LEARNING-BASED INTRUSION DETECTION SYSTEMS: A PROPOSED FRAMEWORK FOR EXPLAINABLE, LEAKAGE-SAFE MODEL LIFECYCLE MANAGEMENT IN NETWORK SECURITY

Authors

  • Muqaddas Abbas
  • Muhammad Fasihuddin
  • *Muhammad Bilal Akbar

Abstract

IDSs based on machine learning usually perform very well on the benchmark against which they were trained, but then start to get worse when deployed in production. Attacker behavior evolves, legitimate traffic patterns shift with new applications and user habits, and the statistical assumptions baked into a classifier at training time slowly stop holding — a problem known as concept drift. The usual fixes are blunt: retrain on a fixed schedule whether or not anything has actually changed, or bolt on a statistical drift detector that can say something shifted but not what shifted, why, or whether it is safe to retrain on the data that triggered the alarm. This paper proposes an agentic AI framework that closes that gap. A small team of cooperating agents continuously watches statistical drift signals from a deployed intrusion detection model, reasons over that evidence using an LLM to distinguish ordinary traffic evolution from a possible adversarial probing campaign, curates a retraining batch under the same leakage-safe preprocessing discipline the model was originally trained with, retrains only when justified, and validates the candidate model against held-out and canary traffic before it is ever promoted to production — all of it logged into an auditable trail rather than acting as an unaccountable black box. It explains the architecture, provides a description of how each agent's choice would be graded, and explicitly spells out failures this design will be protected from, such as drift created by an attacker specifically for the purpose of poisoning the retraining loop.

 

Downloads

Published

2026-03-17

How to Cite

Muqaddas Abbas, Muhammad Fasihuddin, & *Muhammad Bilal Akbar. (2026). AGENTIC AI FOR CONTINUOUS CONCEPT-DRIFT MONITORING AND AUTONOMOUS RETRAINING IN MACHINE-LEARNING-BASED INTRUSION DETECTION SYSTEMS: A PROPOSED FRAMEWORK FOR EXPLAINABLE, LEAKAGE-SAFE MODEL LIFECYCLE MANAGEMENT IN NETWORK SECURITY. Spectrum of Engineering Sciences, 4(3), 5796–5802. Retrieved from https://www.thesesjournal.com/index.php/1/article/view/3803