Diffu Vader: Validity-Constrained Discrete Diffusion for Flow-Level NIDS Red Teaming
Abstract
Machine-learning-based network intrusion detection systems (NIDS) are increasingly evaluated with synthetic adversarial traffic, yet reported evasion rates often do not distinguish between structurally infeasible flow records and feasible network behavior. In generative NIDS research, synthetic data is more often used for augmentation than for validity-constrained adversarial generation. DiffuVader addresses this gap with a family-conditioned discrete diffusion model over a structured four-token state space. Generated samples require no gradient, query-feedback, or surrogate access and are evaluated against frozen detectors using valid evasion rate (VER), which credits only structurally valid, family-plausible samples. Evaluation uses the network-layer partition of the O-RAN testbed corpus NetsLab5GORAN-IDD under a session-disjoint chronological split with five sampling-seed uncertainty estimates. DiffuVader achieves 99.99% validity and plausibility while matching weighted replay in full-token distributional fidelity without direct row replay. A token-marginal control shows that token support alone is insufficient and learned cross-group structure is required for valid flow recovery. Per-family and duplicate analyses separate detector blindness from generator capability. Despite replay-scale fidelity, valid evasion is not reducible to exact decoded-row replay. Offline hardening exposes a trade-off between attack robustness and generated-benign calibration.