Miani, RSBernardo, GDGCassales, GWSenger, Hde Faria, ER2026-08-112026-08-112025-04-15Miani, R. S., Bernardo, G. D. G., Weigert Cassales, G., Senger, H., & de Faria, E. R. (2025). A survey of data stream-based intrusion detection systems. IEEE Access, 13, 72953-72983. https://doi.org/10.1109/ACCESS.2025.35611052169-3536https://hdl.handle.net/10289/18529Detecting malicious activities in network environments poses a challenge that attracts significant attention due to its complexity and importance. Advances in the field have led to the development of several algorithms that approach the problem under the view of a data stream machine learning task. This task involves a set of steps: data collection or choice of public datasets, data pre-processing, data reduction, development or application of data mining techniques, and evaluation methodology. However, these steps must address the inherent issues of dynamic environments such as data streams and intrusion detection systems. These issues include, but are not limited to, the continuous influx of data, changes in both normal and attack class distributions, the emergence of new attack types, and the scarcity of labeled data examples to update the decision models. This survey provides an overview of intrusion detection systems (IDS) using data stream machine learning techniques, characterizing the literature approaches according to the classic steps of the data mining task. In addition, we discuss recommendations for practical IDS development and highlight datasets and tools that can aid in detecting malicious behavior. Finally, we outline potential avenues for future research and open questions in the field.enAttribution 4.0 Internationalhttp://creativecommons.org/licenses/by/4.0/computer scienceA survey of data stream-based intrusion detection systemsJournal Article10.1109/ACCESS.2025.35611052169-35364605 Data Management and Data Science46 Information and Computing Sciences4611 Machine Learning40 Engineering46 Information and computing sciences