Machine-learning Network Intrusion Detection Systems (NIDSs) are increasingly used to detect network attacks, but they remain vulnerable to Adversarial Machine Learning (AML) attacks that subtly perturb traffic to cause misclassification. Understanding and testing these attacks is essential for deploying reliable NIDS in real networks. However, existing AML attack generators, often developed for other application domains, frequently violate network constraints or alter the malicious functionality of traffic, limiting their usefulness for realistic evaluation. To address these limitations, we propose Constraint-Projected Adversarial Attack (CPAD), a method that preserves both validity and maliciousness while inducing evasion. The main goal of CPAD is to allow cybersecurity analysts and practitioners to assess the robustness of their NIDSs against adversarially perturbed network attacks. CPAD partitions features into perturbable and non-perturbable sets, iteratively targets the most influential features, and projects perturbations back into the allowable distribution and constraint space so samples remain realistic and functional. Evaluated on Brute Force, DDoS, DoS, and Bot attacks using a deep model, CPAD produces realistic adversarial samples that retain attack characteristics and successfully evade detection, enabling more faithful robustness assessment of NIDSs.

CPAD: Constraint-Projected Adversarial Attack for Dependable Network Intrusion Detection / Ntako Koungni, M.K., Siracusa, D., Doriguzzi-Corin, R.. - (2025). (2025 3rd International Conference on Foundation and Large Language Models (FLLM) Vienna 25–28 November 2025) [10.1109/FLLM67465.2025.11391031].

CPAD: Constraint-Projected Adversarial Attack for Dependable Network Intrusion Detection

Michael Kevin Ntako Koungni;Domenico Siracusa;Roberto Doriguzzi-Corin
2025-01-01

Abstract

Machine-learning Network Intrusion Detection Systems (NIDSs) are increasingly used to detect network attacks, but they remain vulnerable to Adversarial Machine Learning (AML) attacks that subtly perturb traffic to cause misclassification. Understanding and testing these attacks is essential for deploying reliable NIDS in real networks. However, existing AML attack generators, often developed for other application domains, frequently violate network constraints or alter the malicious functionality of traffic, limiting their usefulness for realistic evaluation. To address these limitations, we propose Constraint-Projected Adversarial Attack (CPAD), a method that preserves both validity and maliciousness while inducing evasion. The main goal of CPAD is to allow cybersecurity analysts and practitioners to assess the robustness of their NIDSs against adversarially perturbed network attacks. CPAD partitions features into perturbable and non-perturbable sets, iteratively targets the most influential features, and projects perturbations back into the allowable distribution and constraint space so samples remain realistic and functional. Evaluated on Brute Force, DDoS, DoS, and Bot attacks using a deep model, CPAD produces realistic adversarial samples that retain attack characteristics and successfully evade detection, enabling more faithful robustness assessment of NIDSs.
2025
2025 3rd International Conference on Foundation and Large Language Models (FLLM)
345 E 47TH ST, NEW YORK, NY 10017 USA
IEEE (Institute of Electrical and Electronics Engineers)
979-8-3315-9409-1
Ntako Koungni, Michael Kevin; Siracusa, Domenico; Doriguzzi-Corin, Roberto
CPAD: Constraint-Projected Adversarial Attack for Dependable Network Intrusion Detection / Ntako Koungni, M.K., Siracusa, D., Doriguzzi-Corin, R.. - (2025). (2025 3rd International Conference on Foundation and Large Language Models (FLLM) Vienna 25–28 November 2025) [10.1109/FLLM67465.2025.11391031].
File in questo prodotto:
File Dimensione Formato  
KoungniCPAD2025[AAM].pdf

Solo gestori archivio

Descrizione: AAM
Tipologia: Post-print referato (Refereed author’s manuscript)
Licenza: Tutti i diritti riservati (All rights reserved)
Dimensione 4.61 MB
Formato Adobe PDF
4.61 MB Adobe PDF   Visualizza/Apri
KoungniCPAD2025[VoR].pdf

Solo gestori archivio

Tipologia: Versione editoriale (Publisher’s layout)
Licenza: Tutti i diritti riservati (All rights reserved)
Dimensione 1.13 MB
Formato Adobe PDF
1.13 MB Adobe PDF   Visualizza/Apri

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11572/473711
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
  • OpenAlex ND
social impact