A resilient hybrid defense mechanism aimed to mitigate the impact of two potent adversarial attacks: Fast Gradient Sign Method (FGSM) and Carlini&Wagner (C&W) attack is developed.
Abstract
It is crucial to safeguard computer networks from evolving network security threats and unknown cyberattacks. An essential tool for protecting computer networks against unknown cyber threats is Network Intrusion Detection System (NIDS). However, NIDS faces a major security concern due to its susceptibility to adversarial attacks. Adversarial attacks aim to deceive NIDS by crafting and injecting adversarial examples into the system. These adversarial inputs can deceive the NIDS into misclassifying benign network traffic as malicious. We developed a resilient hybrid defense mechanism aimed to mitigate the impact of two potent adversarial attacks: Fast Gradient Sign Method (FGSM) and Carlini&Wagner (C&W) attack. Our hybrid defense approach leverages the combined strength of two heuristic defense methods: Adversarial Training (AT) and Gaussian Data Augmentation (GDA). GDA provides multi-directional defense, while AT enhances NIDS robustness against specific adversarial vectors. Under pre-attack scenarios, NIDS demonstrated good accuracy and f1-score. However, in the post-attack scenario, its accuracy significantly dropped under FGSM and C&W attacks (0.2649 and 0.4961, respectively). Our proposed hybrid defense method effectively mitigated these adversarial threats, with post-defense accuracy of 96.57% and 89.20% for FGSM and C&W attacks. We evaluated the defense strategy across a range of epsilon and confidence noise factor values (ranging from 0.0001 to 0.0009). This research provides a good direction for future researchers in the emerging area of adversarial machine learning from a security perspective.
An extensive literature review on the adversarial attack methods, detection and defence techniques of critical network infrastructures and suggests the creation of multi-strategic, adaptive, and real-time adversarial threat management systems that can sustain themselves in a heterogeneous network environment.
F. Okoye, Aghaizu Herman Chijioke, Shamsudeen Mohammed S.B· International journal of re...· 0 citations
This study investigated the robustness of deep learning-based Network Intrusion Detection Systems (NIDS) against adversarial attacks by proposing a confidence-aware adaptive defense framework. The proposed approach integrates a baseline feedforward neural network, an adversarially trained robust model, and an adversarial detector to dynamically select the most appropriate prediction path based on detector confidence. Experimental evaluation under single-step, multi-step, and adaptive adversarial attack scenarios demonstrated that the framework significantly improves detection robustness while maintaining high classification accuracy on clean network traffic. The adaptive fusion strategy effectively mitigates the impact of adversarial perturbations, reducing misclassification rates and enhancing the reliability of intrusion detection in dynamic cybersecurity environments. These findings confirm that confidence-guided adaptive defense mechanisms provide a practical solution for strengthening the resilience of AI-driven NIDS against evolving attack strategies. However, the proposed framework was evaluated using controlled experimental settings and specific attack models, which may not fully represent the diversity of real-world cyber threats. Future work will focus on validating the framework in large-scale operational networks, extending it to advanced zero-day and adaptive attacks, and investigating lightweight deployment strategies for real-time edge and cloud-based cybersecurity applications.
Aastha Ahlawat, Anurag Goel· 2026 4th International Confe...· 0 citations
Experimental results indicate that CNN-based NIDS are more vulnerable to adversarial attacks than ANN-based models, with adversarial examples successfully transferring across architectures, highlighting the critical risks associated with adversarial transferability.
Aasim Zafar, Shazra Wali, S. B. U. Haque· International Journal of Inf...· 0 citations
A Kitchenham-informed systematic literature review methodology, this review synthesizes 186 studies published between 2018 and 2026 and develops a perturbation-realism taxonomy, ranging from feature-level manipulation to executable packet-level attacks, that clarifies when reported success corresponds to deployable risk.
The review explores the key adversarial attack classes: poisoning, evasion, model extraction, model extraction, model inversion, and membership inference and also white-box, black-box, and grey-box threat models.
Ujjwal Deshmukh· International Journal of Inn...· 0 citations
No single defense mechanism can provide complete protection against adversarial machine learning attacks, therefore, resilient AI-based cybersecurity requires a layered approach that protects data, features, models, inference processes, and the entire machine learning lifecycle.
Nwamini Bartholomew Tochukwu, C. Ezeaku-Ezeme· International journal of res...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.