IJITCS Vol. 18, No. 4, 8 Aug. 2026
Cover page and Table of Contents: PDF (size: 2310KB)
PDF (2310KB), PP.170-198
Views: 0 Downloads: 0
Adversarial Attacks, Network Security, Intrusion Detection, Deep Learning, Machine Learning
Network Intrusion Detection Systems (NIDS) play a vital role in modern cybersecurity by leveraging artificial intelligence (AI) in particular deep learning (DL) and machine learning (ML) to detect and mitigate malicious activities. However, these AI-driven systems are highly vulnerable to adversarial attacks, where small, imperceptible perturbations in input data can deceive models and significantly reduce detection accuracy. This raises critical concerns about the security and reliability of intrusion detection, especially in real-world scenarios where attackers exploit adversarial transferability to bypass defenses. This research investigates the threat posed by black-box adversarial attacks via surrogate models, focusing on the ability of adversarial examples to transfer across different architectures. This study simulates real-world adversarial threats, demonstrating how attacks crafted on one model can effectively deceive another, compromising NIDS security. A comparative study is conducted on two widely used AI models: an Artificial Neural Network (ANN) and a Convolutional Neural Network (CNN), both trained on the CICIDS 2019 dataset. The study evaluates the robustness of these models against two gradient-based adversarial attack methods, Fast Gradient Sign Method (FGSM) and Projected Gradient Descent (PGD), to determine their susceptibility under black box adversarial conditions. Experimental results indicate that CNN-based NIDS are more vulnerable to adversarial attacks than ANN-based models, with adversarial examples successfully transferring across architectures. These findings highlight the critical risks associated with adversarial transferability, underscoring the need for enhanced security measures to strengthen AI-driven intrusion detection systems against evolving cyber threats.
Aasim Zafar, Shazra Wali, Sheikh Burhan ul Haque, "Adversarial Transferability in AI-based Network Intrusion Detection: A Comparative Study of ANN and CNN Models", International Journal of Information Technology and Computer Science(IJITCS), Vol.18, No.4, pp.170-198, 2026. DOI:10.5815/ijitcs.2026.04.11
[1]R.N. Anaedevha, A.G. Trofimov, "Improved Robust Adversarial Model against Evasion Attacks on Intrusion Detection Systems", Optical Memory and Neural Networks, Vol.33, No.4, pp.S414–S423, 2024. DOI:10.3103/s1060992x24700681
[2]Khushnaseeb Roshan, Aasim Zafar, "A Novel DLbased Model to Defend Network Intrusion Detection System against Adversarial Attacks", 2022 4th International Conference on Advances in Computing, Communication Control and Networking (ICAC3N), pp.2043-2048, 2023. DOI:10.1109/ICAC3N56670.2022.10112520
[3]D. Han, Z. Wang, Y. Zhong, W. Chen, J. Yang, S. Lu, X. Shi, X. Yin, "Evaluating and improving adversarial robustness of Machine Learning-Based Network Intrusion detectors", IEEE Journal on Selected Areas in Communications, Vol.39, No.8, pp.2632–2647, 2021. DOI:10.1109/jsac.2021.3087242
[4]G. Kocher, G. Kumar, "Machine learning and DL methods for intrusion detection systems: recent developments and challenges", Soft Computing, Vol.25, No.13, pp.9731–9763, 2021. DOI:10.1007/s00500-021-05893-0
[5]C. Zhang, X. Costa-Perez, P. Patras, "Adversarial attacks against Deep learning-Based Network Intrusion detection systems and defense mechanisms", IEEE/ACM Transactions on Networking, Vol.30, No.3, pp.1294–1311, 2022. DOI:10.1109/tnet.2021.3137084
[6]Hesamodin Mohammadian, "An adversarial attack framework for DL-based NIDS", Master Thesis, University of New Brunswick, pp.1-115, 2022.
[7]Aasim Zafar, Tarab Malik, and Sheikh Burhan Ul Haque, "Comparative Analysis of Black-Box Targeted Adversarial Attacks on DL-Based NIDS: A Study of C&W and JSMA using CICDDoS2019," International Journal of Computer Networks & Communications (IJCNC), vol. 18, no. 1, pp. 101-119, January 2026. DOI: 10.5121/ijcnc.2026.18107.
[8]W. Villegas-Ch, A. Jaramillo-Alcázar, S. Luján-Mora, "Evaluating the Robustness of DLModels against Adversarial Attacks: An Analysis with FGSM, PGD and CW", Big Data and Cognitive Computing, Vol.8, No.1, pp.8, 2024. DOI:10.3390/bdcc8010008
[9]K. Roshan, A. Zafar, S.B.U. Haque, "Untargeted white-box adversarial attack with heuristic defence methods in real-time DL-based network intrusion detection system", Computer Communications, Vol.218, pp.97–113, 2023. DOI:10.1016/j.comcom.2023.09.030
[10]A. Alotaibi, M.A. Rassam, "Enhancing the Sustainability of Deep-Learning-Based Network Intrusion Detection Classifiers against Adversarial Attacks", Sustainability, Vol.15, No.12, pp.9801, 2023. DOI:10.3390/su15129801
[11]Sheikh Burhan Ul Haque, "A Fuzzy-based Frame Transformation to Mitigate the Impact of Adversarial Attacks in Deep Learning-based Real-time Video Surveillance Systems," Applied Soft Computing, Vol. 167, Art. No. 112440, 2024. DOI: 10.1016/j.asoc.2024.112440
[12]I. Sharafaldin, A.H. Lashkari, S. Hakak, A.A. Ghorbani, "Developing Realistic Distributed Denial of Service (DDoS) Attack Dataset and Taxonomy", 2019 International Carnahan Conference on Security Technology (ICCST), pp.1–8, 2019. DOI:10.1109/ccst.2019.8888419
[13]Z.K. Maseer, R. Yusof, N. Bahaman, S.A. Mostafa, C.F.M. Foozy, "Benchmarking of machine learning for anomaly based intrusion detection Systems in the CICIDS2017 dataset", IEEE Access, Vol.9, pp.22351–22370, 2021. DOI:10.1109/access.2021.3056614
[14]Canadian Institute for Cybersecurity, "CICDDoS2019 Dataset", University of New Brunswick, [Online], 2019.
[15]Sheikh Burhan Ul Haque, Aasim Zafar, "Robust Medical Diagnosis: A Novel Two-Phase Deep Learning Framework for Adversarial Proof Disease Detection in Radiology Images", Journal of Imaging Informatics in Medicine, Vol. 37, No. 1, pp. 308-338, 2024. DOI: 10.1007/s10278-023-00916-8
[16]S. Qiu, Q. Liu, S. Zhou, C. Wu, "Review of Artificial Intelligence Adversarial Attack and Defense Technologies", Applied Sciences, Vol.9, No.5, pp.909, 2019. DOI:10.3390/APP9050909
[17]J. Šircelj, D. Skočaj, "Accuracy-Perturbation Curves for Evaluation of Adversarial Attack and Defence Methods", 2020 25th International Conference on Pattern Recognition (ICPR), pp.6290-6297, 2021.
[18]Huda Ali Alatwi, Amjad Aldweesh, "Adversarial Black-Box attacks against network intrusion detection Systems: a survey", 2021 IEEE World AI IoT Congress (AIIoT), pp.34-40, 2021. DOI:10.1109/AIIoT52608.2021.9454214
[19]O. Ibitoye, R. Abou-Khamis, M.E. Shehaby, A. Matrawy, M.O. Shafiq, "The threat of adversarial attacks on machine learning in network Security -- a survey", arXiv:1911.02621, pp.1-15, 2019.
[20]S. Alahmed, Q. Alasad, M.M. Hammood, J.-S. Yuan, M. Alawad, "Mitigation of Black-Box attacks on Intrusion Detection Systems-Based ML", Computers, Vol.11, No.7, pp.115, 2022. DOI:10.3390/computers11070115
[21]P. Kumar, S. Rathore, "DLPerformance Evaluation Model for enhancing Network Intrusion Detection Systems", 2023 International Conference on Computer Communication and Informatics (ICCCI), pp.1-7, 2024. DOI:10.1109/ICAC3N60023.2023.10753184
[22]Elie Alhajjar, Paul Maxwell, Nathaniel Bastian, "Adversarial machine learning in Network Intrusion Detection Systems", Expert Systems with Applications, Vol.186, pp.115782, 2021. DOI:10.1016/j.eswa.2021.115782
[23]Sheikh Burhan Ul Haque, "Mitigating Adversarial Threats in Deep CT Image Diagnosis Models via a Dual-Stage Inference-Time Defense", Applied Soft Computing, Vol. 163, Art. No. 111909, 2024. DOI:10.1016/j.asoc.2024.111909.
[24]H. Mohammadian, A.H. Lashkari, A.A. Ghorbani, "Evaluating Deep learning-based NIDS in Adversarial Settings", Proceedings of the 8th International Conference on Information Systems Security and Privacy (ICISSP), pp.435-444, 2022. DOI:10.5220/0010867900003120
[25]Sheikh Burhan Ul Haque, Aasim Zafar, Sheikh Moeen ul haque, Sheikh Riyaz ul Haq, Mohassin Ahmad, "Securing AI in Healthcare: A Three-Layer Defense to Mitigate Adversarial Noise Impact in Radiology Imaging", Biomedical Signal Processing and Control, Vol. 109, Art. No. 107969, 2025. DOI:10.1016/j.bspc.2025.107969
[26]Md. Ahsan Ayub, William A. Johnson, Douglas A. Talbert, Ambareen Siraj, "Model Evasion Attack on Intrusion Detection Systems using Adversarial Machine Learning", 2020 54th Annual Conference on Information Sciences and Systems (CISS), pp.1-6, 2020. DOI:10.1109/COMSNETS48256.2020.9086268
[27]V. Kumar, K. Kumar, M. Singh, "Generating practical adversarial examples against learning-based network intrusion detection systems", Annals of Telecommunications, Vol.79, pp.1-14, 2024. DOI:10.1007/s12243-024-01021-9
[28]S. Sharma, Z. Chen, "A systematic study of adversarial attacks against network intrusion detection systems", Electronics, Vol.13, No.24, pp.5030, 2024. DOI:10.3390/electronics13245030
[29]M. elShehaby, A. Matrawy, "Adversarial Evasion Attacks Practicality in Networks: Testing the Impact of Dynamic learning", arXiv:2306.05494, pp.1-12, 2023.
[30]Mohammad Abood, Ghassan Majeed, "Enhancing Multi-Class DDoS Attack Classification using Machine Learning Techniques", Journal of Advanced Research in Applied Sciences