•  
  •  
 

Abstract

The use of Intrusion Detection Systems (IDS) is fundamental to the protection of contemporary networks which are increasingly vulnerable to sophisticated and evolving cyber-attacks and within environments that do not possess labeled data and where attacks are appearing for the first time. Often, previous IDS approaches are sub-performers as they generally rely on larger amounts of labeled data or static signature sets, especially in the context of zero-day attacks or rare events. This Systematic Literature Review (SLR) examines the deployment of Few-Shot Learning (FSL) as a novel approach to counter these limitations. This review offers a systematic review of over 50 relatively recent studies. It examines metric-based, meta-learning, transformer-based and federated FSL approaches with IDS. This review also focuses on models designed for FSL in IoT networks, cloud-based architectures and edge environments outlining hybrid approaches that incorporate FSL with generative models, reinforcement learning or causal inference. The review considers pivotal benchmark datasets such as NSL-KDD, CIC-IDS2017, BoT-IoT and TON-IoT and the empirical backdrop they provide to FSL-based IDS. Our conclusion indicates that FSL is a viable solution for improving detection accuracy for those attacks being considered zero-day while keeping low false positive rates especially when deployed with explainable AI systems and light-weight architecture into production. Finally, the review identifies prominent research obstacles and future trajectories: the need for standardized evaluation procedures, further cross-domain generalization and creating scalable, explainable IDS systems with FSL.

Keywords

Few-shot learning, Intrusion detection systems (IDS), Zero-day attacks, Emerging cyber threat, Meta-learning, Federated learning, IoT security, Anomaly detection

Article Type

Article

First Page

67

Last Page

85

Publication Date

6-30-2026

Share

COinS