TDTCE: generating adversarial instances against NIDS via diffusion model
Zhonghang Sui et al.
What the paper says
The integration of machine learning (ML), particularly deep learning (DL), in network intrusion detection systems (NIDSs) has witnessed exponential growth. Notably, these intelligent systems exhibit significant vulnerability to adversarial manipulations, especially in security-critical environments. A critical limitation of conventional adversarial generation approaches—predominantly relying on generative adversarial networks (GANs)—lies in their inability to produce diverse traffic patterns. This shortcoming allows detectors to quickly identify such instances after retraining. To bridge this gap, we propose an adversarial attack framework, TDTCE (Traffic Diffusion Models with Transformers against NIDS in Constrained Environments), which surpasses previous efforts in the following aspects: (i) Generative diversity. TDTCE utilizes a Transformer-based diffusion model to generate adversarial instances that more effectively deceive NIDSs; (ii) Practical feasibility. By restricting prior knowledge, gray-box and black-box attacks are conducted in real-world scenarios and a mapping function is utilized to adjust generated instances for adherence to traffic protocol standards. A comprehensive evaluation of TDTCE using extensive datasets demonstrates that the proposed framework achieves significant gains in adaptive pattern diversity with improvements of up to 79.4% over GAN-based approaches. The framework achieves a minimum detection rate of 9.16%, with an escape increase rate of 89.64%–16.52% higher than state-of-the-art baselines.
Evidence weight
Balanced mode · F 0.40 / M 0.15 / V 0.05 / R 0.40
| F · citation impact | 0.50 × 0.4 = 0.20 |
| M · momentum | 0.50 × 0.15 = 0.07 |
| V · venue signal | 0.50 × 0.05 = 0.03 |
| R · text relevance † | 0.50 × 0.4 = 0.20 |
† Text relevance is estimated at 0.50 on the detail page — for your query’s actual relevance score, open this paper from a search result.