A sensitivity-driven adversarial generation framework (AGF) that identifies and perturbs the most influential traffic features that affect the classifier’s decision boundary to generate statistically consistent adversarial samples with constrained perturbation magnitude is proposed.
Abstract
Network intrusion detection systems based on deep learning have shown strong performance in modeling complex traffic patterns. However, recent studies indicate that these models can be vulnerable to carefully crafted adversarial perturbations, in which small modifications to traffic features lead to incorrect classification. This work proposes a sensitivity-driven adversarial generation framework (AGF) that identifies and perturbs the most influential traffic features that affect the classifier’s decision boundary. The framework integrates feature-level sensitivity estimation, stochastic sensitivity-guided feature partitioning, and threshold-guided optimization to generate statistically consistent adversarial samples with constrained perturbation magnitude. Experimental evaluation on CIC-IDS2017, CIC-IDS2018, and CIC-DDoS2019 achieves attack success rates of 94.82%, 93.56%, and 92.71%, respectively, while maintaining low perturbation distortion, KL divergence values below 0.013, and protocol violation rates close to 1–2%. A comparative analysis against FGSM, PGD, C&W, BotDefender, VMFCVD, and Boundary attacks demonstrates improved evasion capability with smaller, more structured perturbations.
Deep reinforcement learning (DRL) enables adaptive intrusion detection in dynamic network environments but also exposes intrusion detection systems (IDS) to adversarial threats such as universal adversarial perturbations (UAPs), which apply a single input-agnostic perturbation to degrade detection performance across tr...
Hong-Sen Zhang, Lu Zhang, Ming-Jing Xu et al.· 0 citations
This study investigates the transferability of adversarial attacks across XGBoost and LightGBM models in IDS and uses Explainable AI (XAI) techniques to identify features that influence model decisions and shows that feature-importance patterns can be used to examine model vulnerability under adversarial perturbations.
Abdlelah Abdlatef, Marwa D. Abdulkareem, Duygu Çakır· International Journal of Inf...· 1 citation
The availability and consistency of online services remain vulnerable due to Distributed Denial of Service (DDoS) attacks. These attacks are evolving by adopting more complex strategies to evade traditional network security systems. Despite the effectiveness of machine learning models in detecting DDoS traffic, targete...
Makram Chehayeb, W. Fahs, Amina Rizk et al.· 0 citations
Machine learning-based network intrusion detection systems (ML-based NIDS) are vulnerable to adversarial evasion, where malicious samples are perturbed to evade detection and be misclassified as benign. Despite growing research on adversarial attacks and defenses for ML-based NIDS, comparative evaluations of multiple a...
A Kitchenham-informed systematic literature review methodology, this review synthesizes 186 studies published between 2018 and 2026 and develops a perturbation-realism taxonomy, ranging from feature-level manipulation to executable packet-level attacks, that clarifies when reported success corresponds to deployable ris...
Network intrusion detection is an important technical means to ensure cyberspace security. Many intrusion detection systems adopt artificial intelligence methods, and the Rectified Linear Unit (ReLU) activation function is widely used in deep learning‐based intrusion detection models. However, in the process of gener...
Xiaoyu Du, Jun Jiang, Pu Cheng et al.· Concurrency and Computation· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.