Pith. sign in

REVIEW 2 cited by

IDSGAN: Generative Adversarial Networks for Attack Generation against Intrusion Detection

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1809.02077 v5 pith:WN6CG7WT submitted 2018-09-06 cs.CR cs.AI

classification cs.CRcs.AI
keywords detectionadversarialattacksystemtrafficintrusionmaliciousattacks
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

As an essential tool in security, the intrusion detection system bears the responsibility of the defense to network attacks performed by malicious traffic. Nowadays, with the help of machine learning algorithms, intrusion detection systems develop rapidly. However, the robustness of this system is questionable when it faces adversarial attacks. For the robustness of detection systems, more potential attack approaches are under research. In this paper, a framework of the generative adversarial networks, called IDSGAN, is proposed to generate the adversarial malicious traffic records aiming to attack intrusion detection systems by deceiving and evading the detection. Given that the internal structure and parameters of the detection system are unknown to attackers, the adversarial attack examples perform the black-box attacks against the detection system. IDSGAN leverages a generator to transform original malicious traffic records into adversarial malicious ones. A discriminator classifies traffic examples and dynamically learns the real-time black-box detection system. More significantly, the restricted modification mechanism is designed for the adversarial generation to preserve original attack functionalities of adversarial traffic records. The effectiveness of the model is indicated by attacking multiple algorithm-based detection models with different attack categories. The robustness is verified by changing the number of the modified features. A comparative experiment with adversarial attack baselines demonstrates the superiority of our model.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Constrained Network Adversarial Attacks: Validity, Robustness, and Transferability

    cs.CR 2025-05 reject novelty 4.0 of 10

    On NSL-KDD, between 19.7% and 76.2% of adversarial examples from common attacks violate the paper's network constraints, and filtering them to feasible inputs sharply lowers measured attack severity on several classifiers.

  2. On the Veracity of Cyber Intrusion Alerts Synthesized by Generative Adversarial Networks

    cs.LG 2019-08 reject novelty 4.0 of 10

    WGAN-GP with a mutual-information constraint can approximate marginal histograms of per-target NIDS alerts, but the evidence that it improves rare-alert generation is confounded and internally inconsistent.

Pith tools