Prototype-Based Transferability Analysis for Few-Shot Domain Adaptation in Cross-Domain Intrusion Detection
Few-shot domain adaptation (FSDA) has become an important approach for cross-domain intrusion detection by enabling models to leverage limited labeled target data under distribution shifts. Although numerous adaptation methods have been proposed, their effectiveness often varies considerably across transfer scenarios, leading to inconsistent performance across domains. This study investigates how prototype-based transferability can be used to characterize source–target compatibility prior to adaptation. To this end, a transferability-aware perspective on FSDA is presented by distinguishing between intra-domain separability, which characterizes the internal class structure of a domain, and cross-domain transferability, which reflects how effectively source-derived representations generalize to a target domain. Based on this distinction, a set of asymmetric transferability metrics is introduced to characterize prototype-based transferability from complementary perspectives. Across the evaluated transfer scenarios, stronger intra-domain separability did not necessarily coincide with better cross-domain transferability. Furthermore, the empirical results indicate that different adaptation strategies exhibit different behaviors across the examined transfer directions. Across the two evaluated transfer directions, the prototype-based transferability analysis and the few-shot adaptation results exhibit different behaviors. While target-only few-shot learning performs competitively in one transfer direction, prototype-based alignment methods provide larger improvements in the other, illustrating that adaptation performance reflects not only source–target compatibility but also intrinsic target-domain separability and the adaptation process itself. These observations provide an empirical perspective for interpreting the varying performance of existing FSDA methods and highlight the importance of considering transfer conditions when selecting adaptation strategies for cross-domain intrusion detection.