Enhancing Network Intrusion Detection Systems: A Multi-Layer Ensemble Approach to Mitigate Adversarial Attacks

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Soltani, Nasim, Nejadshamsi, Shayan, Houda, Zakaria Abou El, Khoury, Raphael, Costa, Kelton A. P., Falk, Tiago H., Avila, Anderson R.
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915852266242048
author Soltani, Nasim
Nejadshamsi, Shayan
Houda, Zakaria Abou El
Khoury, Raphael
Costa, Kelton A. P.
Falk, Tiago H.
Avila, Anderson R.
author_facet Soltani, Nasim
Nejadshamsi, Shayan
Houda, Zakaria Abou El
Khoury, Raphael
Costa, Kelton A. P.
Falk, Tiago H.
Avila, Anderson R.
contents Adversarial examples can represent a serious threat to machine learning (ML) algorithms. If used to manipulate the behaviour of ML-based Network Intrusion Detection Systems (NIDS), they can jeopardize network security. In this work, we aim to mitigate such risks by increasing the robustness of NIDS towards adversarial attacks. To that end, we explore two adversarial methods for generating malicious network traffic. The first method is based on Generative Adversarial Networks (GAN) and the second one is the Fast Gradient Sign Method (FGSM). The adversarial examples generated by these methods are then used to evaluate a novel multilayer defense mechanism, specifically designed to mitigate the vulnerability of ML-based NIDS. Our solution consists of one layer of stacking classifiers and a second layer based on an autoencoder. If the incoming network data are classified as benign by the first layer, the second layer is activated to ensure that the decision made by the stacking classifier is correct. We also incorporated adversarial training to further improve the robustness of our solution. Experiments on two datasets, namely UNSW-NB15 and NSL-KDD, demonstrate that the proposed approach increases resilience to adversarial attacks.
format Preprint
id arxiv_https___arxiv_org_abs_2603_10413
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Enhancing Network Intrusion Detection Systems: A Multi-Layer Ensemble Approach to Mitigate Adversarial Attacks
Soltani, Nasim
Nejadshamsi, Shayan
Houda, Zakaria Abou El
Khoury, Raphael
Costa, Kelton A. P.
Falk, Tiago H.
Avila, Anderson R.
Cryptography and Security
Artificial Intelligence
Adversarial examples can represent a serious threat to machine learning (ML) algorithms. If used to manipulate the behaviour of ML-based Network Intrusion Detection Systems (NIDS), they can jeopardize network security. In this work, we aim to mitigate such risks by increasing the robustness of NIDS towards adversarial attacks. To that end, we explore two adversarial methods for generating malicious network traffic. The first method is based on Generative Adversarial Networks (GAN) and the second one is the Fast Gradient Sign Method (FGSM). The adversarial examples generated by these methods are then used to evaluate a novel multilayer defense mechanism, specifically designed to mitigate the vulnerability of ML-based NIDS. Our solution consists of one layer of stacking classifiers and a second layer based on an autoencoder. If the incoming network data are classified as benign by the first layer, the second layer is activated to ensure that the decision made by the stacking classifier is correct. We also incorporated adversarial training to further improve the robustness of our solution. Experiments on two datasets, namely UNSW-NB15 and NSL-KDD, demonstrate that the proposed approach increases resilience to adversarial attacks.
title Enhancing Network Intrusion Detection Systems: A Multi-Layer Ensemble Approach to Mitigate Adversarial Attacks
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2603.10413