Skip to content
Conference

Diffu Vader: Validity-Constrained Discrete Diffusion for Flow-Level NIDS Red Teaming

Jul 2026 · International Conference on Computer, Information and Telecommunication Systems · pp. 1-8 · 0 citations · 28 references

Abstract

Machine-learning-based network intrusion detection systems (NIDS) are increasingly evaluated with synthetic adversarial traffic, yet reported evasion rates often do not distinguish between structurally infeasible flow records and feasible network behavior. In generative NIDS research, synthetic data is more often used for augmentation than for validity-constrained adversarial generation. DiffuVader addresses this gap with a family-conditioned discrete diffusion model over a structured four-token state space. Generated samples require no gradient, query-feedback, or surrogate access and are evaluated against frozen detectors using valid evasion rate (VER), which credits only structurally valid, family-plausible samples. Evaluation uses the network-layer partition of the O-RAN testbed corpus NetsLab5GORAN-IDD under a session-disjoint chronological split with five sampling-seed uncertainty estimates. DiffuVader achieves 99.99% validity and plausibility while matching weighted replay in full-token distributional fidelity without direct row replay. A token-marginal control shows that token support alone is insufficient and learned cross-group structure is required for valid flow recovery. Per-family and duplicate analyses separate detector blindness from generator capability. Despite replay-scale fidelity, valid evasion is not reducible to exact decoded-row replay. Offline hardening exposes a trade-off between attack robustness and generated-benign calibration.

View source

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.