The Internet of Things (IoT) has dramatically expanded global connectivity, with billions of heterogeneous devices generating massive volumes of network traffic. This growth has significantly enlarged the attack surface for cyber threats, particularly synthetic unknown attacks that exploit vulnerabilities not yet captured in existing signature databases. Traditional intrusion detection systems (IDS), which rely on known attack signatures, fail to detect such novel threats. This study proposes a comprehensive Adversarial Machine Learning (AML) framework designed to detect synthetic unknown attacks in IoT networks through the integration of three complementary techniques: Generative Adversarial Networks (GANs) for synthesizing realistic attack samples, Adversarial Autoencoders (AAEs) for robust low-dimensional feature extraction, and Deep Neural Networks (DNNs) for real-time anomaly classification. The framework was evaluated on a controlled synthetic IoT dataset comprising 250,000 traffic samples. Results demonstrate detection accuracy of 94.8%, precision of 93.1%, recall of 92.7%, and F1-score of 92.9%, substantially outperforming signature-based IDS (63.5%), SVM (87.2%), and Random Forest (90.1%). The framework maintained detection rates of 90.2%, 87.5%, and 85.3% under FGSM, PGD, and Carlini-Wagner adversarial perturbations, respectively. Scalability testing across datasets up to 4 million samples confirmed sustained performance with inference latency below 0.021 seconds per sample. The proposed framework represents a scalable, adversarially resilient approach to IoT intrusion detection, with limitations regarding real-world generalization openly acknowledged.
A hybrid detection framework is proposed that integrates a Random Forest classifier with an unsupervised anomaly detection model based on a deep autoencoder combined through a Logistic Regression metaclassifier that addresses the gap in single-model detectors that either rely on fixed decision boundaries that struggle with gradually evolving stealthy FDIA patterns or on anomaly detection that lacks strong discriminative power in separating subtle adversarial deviations from normal operational variability.
A. Albarrak, Fuad A. Ghaleb, Sultan Noman Qasem et al.· Italian National Conference...· 0 citations
A deep Q-learning (DQL) framework that integrates K-means clustering directly into the RL action space, enabling adaptive state representation and improved generalization to unseen traffic patterns is proposed.
Lana Kamla Ahmed, Kayhan Zrar Ghafoor· Indonesian Journal of Electr...· 0 citations
A constraint-aware adversarially robust Internet of Things (IoT) traffic classification system with protocol validity, device behavior consistency, and manifold-aware training and evaluation is presented, demonstrating improved robustness, realism, and deployability compared to existing approaches.
This survey provides a structured review of generative AI and FL techniques for IDS and categorizes generative AI applications in IDS according to model families and task objectives, covering autoencoder-based models, Generative Adversarial Networks (GANs), diffusion models, and Large Language Models (LLMs).
Jiefei Liu, A. S. Tayeen, Pratyay Kumar et al.· 1 citation
Across all five algorithms, boosting methods showed a small but consistent advantage over bagging methods, and detection was effective for every MITM technique considered, with SSL stripping proving the most difficult to identify.
Yasser AbdelSatar, Fatma El-Zahraa Mohamed, Shimaa AbdelNasser et al.· Engineering Systems and Inte...· 0 citations
Experimental results indicate that CNN-based NIDS are more vulnerable to adversarial attacks than ANN-based models, with adversarial examples successfully transferring across architectures, highlighting the critical risks associated with adversarial transferability.
Aasim Zafar, Shazra Wali, Sheikh Burhan Ul Haque· International Journal of Inf...· 0 citations