ADAPTIVE GAN-DRIVEN XGBOOST FRAMEWORK FOR REAL-TIME DETECTION OF EMERGING NETWORK INTRUSIONS
Abstract
Background The fast rate at which cyber threats are evolving brings a lot of challenges to the conventional signature-based intrusion detection systems (IDS) that do not always identify new or zero-day attacks. The paper introduces an AI-based, adaptable Network Intrusion Detection System (NIDS) which, using Generative Adversarial Networks (GANs) with XGBoost, will enhance the detection of known and novel cyberattacks. Objective The suggested framework is designed to process network traffic data by preprocessing network traffic data, realistically simulates the samples of synthetic attacks based on a feature-driven GAN, and uses XGBoost as a powerful feature selection and classification tool. The system decreases the false positives and increases the detection of rare and previously unseen attacks by managing class imbalance. Results Large-scale experiments, using benchmark network intrusion datasets, reveal the proposed approach to be much better than the conventional machine learning and deep learning-based IDS models with regards to accuracy, precision, recall and F1-score. In addition, the framework facilitates dynamic learning in changing patterns of network traffic to allow real-time monitoring in dynamic environments. Conclusion Data augmentation using GAN and explainable XGBoost classification is a scalable, interpretable, and practical intelligent network security solution. This research contributes to the work on the creation of active, AI-based intrusion detection systems that can react to cybersecurity threats that change rapidly.