Beyond Attack Success Rate: Representing Consistency in Evading the NIDS Feature-Space

  • Allan da S. Espindola PUCPR / Universidade de Lisboa
  • Altair O. Santin PUCPR
  • António Casimiro Universidade de Lisboa
  • Pedro M. Ferreira Universidade de Lisboa
  • Eduardo K. Viegas PUCPR

Resumo


Feature-space attacks directly modify NIDS inputs. Their attack success rate (ASR) measures classifier evasion under vector access but does not by itself establish an end-to-end NIDS vulnerability. We evaluate FGSM and PGD attacks against an MLP-based NIDS using ASR, Pearson correlation changes across records, and flow-level checks of features within each flow. ASR and correlation change followed distinct trajectories. At the largest perturbation limit, almost all successful volume-only and mixed evasions introduced a tested violation. In the packet-derived reference, no strong clean pair reversed sign, and no re-extracted record violated a tested relationship. Together, these findings show that correlation change and flow-level checks provide complementary evidence about representation consistency beyond classifier evasion.

Referências

Alhussien, N., Aleroud, A., Melhem, A., and Khamaiseh, S. Y. (2024). Constraining adversarial attacks on network intrusion detection systems: Transferability and defense analysis. IEEE Transactions on Network and Service Management, 21(3):2751–2772.

Apruzzese, G., Andreolini, M., Ferretti, L., Marchetti, M., and Colajanni, M. (2022). Modeling realistic adversarial attacks against network intrusion detection systems. Digital Threats: Research and Practice, 3(3):1–19.

Catillo, M., Pecchia, A., Repola, A., and Villano, U. (2025). A critique on the (mis)use of feature-space attacks for adversarial machine learning in NIDS. In 2025 20th European Dependable Computing Conference (EDCC), pages 110–115. IEEE.

Catillo, M., Pecchia, A., and Villano, U. (2026). Similarity is not enough: Issues with adversarial perturbations of traffic features against intrusion detection systems. In Proceedings of the 12th International Conference on Information Systems Security and Privacy (ICISSP), volume 1, pages 325–332. SciTePress.

Claise, B. and Trammell, B. (2013). Information model for IP flow information export (IPFIX). RFC 7012, Internet Engineering Task Force.

Espindola, A. d. S., Casimiro, A., Santin, A. O., Ferreira, P. M., and Viegas, E. K. (2026a). Enhancing intrusion detection generalization via diversity-driven multi-view ensemble learning in industrial systems. Future Generation Computer Systems, 182:108458.

Espindola, A. d. S., Santin, A. O., Casimiro, A., Ferreira, P. M., and Viegas, E. K. (2026b). Understanding the adversary: A survey of adversarial machine learning in network intrusion detection. Computer Science Review, 62:100995.

Espindola, A. d. S., Santin, A. O., Viegas, E. K., Ferreira, P. M., and Casimiro, A. (2026c). Diversity as a security primitive for ML-based network intrusion detection. In 2026 IEEE 12th International Conference on Network Softwarization (NetSoft), pages 409–414. IEEE.

Espindola, A. d. S., Viegas, E. K., Casimiro, A., Santin, A. O., and Ferreira, P. M. (2025). D-MOOD: Diversity-based multi-objective optimization defense. GitHub software repository, [link]. Revision 483af25.

Filho, A. G., Viegas, E. K., Santin, A. O., and Geremias, J. (2025). A dynamic network intrusion detection model for infrastructure as code deployed environments. Journal of Network and Systems Management, 33(4).

Goodfellow, I. J., Shlens, J., and Szegedy, C. (2015). Explaining and harnessing adversarial examples. In 3rd International Conference on Learning Representations (ICLR 2015), Conference Track Proceedings, San Diego, CA, USA.

Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A. (2018). Towards deep learning models resistant to adversarial attacks. In 6th International Conference on Learning Representations (ICLR 2018), Conference Track Proceedings, Vancouver, BC, Canada.

Moustafa, N. and Slay, J. (2015). UNSW-NB15: A comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set). In 2015 Military Communications and Information Systems Conference (MilCIS), pages 1–6. IEEE.

Nicolae, M.-I., Sinn, M., Tran, M. N., Buesser, B., Rawat, A., Wistuba, M., Zantedeschi, V., Baracaldo, N., Chen, B., Ludwig, H., Molloy, I. M., and Edwards, B. (2018). Adversarial robustness toolbox v1.0.0. CoRR, abs/1807.01069.

Pierazzi, F., Pendlebury, F., Cortellazzi, J., and Cavallaro, L. (2020). Intriguing properties of adversarial ML attacks in the problem space. In 2020 IEEE Symposium on Security and Privacy (SP), pages 1332–1349. IEEE.

Sharon, Y., Berend, D., Liu, Y., Shabtai, A., and Elovici, Y. (2022). TANTRA: Timing-based adversarial network traffic reshaping attack. IEEE Transactions on Information Forensics and Security, 17:3225–3237.

Simioni, J., Viegas, E. K., Santin, A., and Horchulhack, P. (2025). An early exit deep neural network for fast inference intrusion detection. In Proceedings of the 40th ACM/SIGAPP Symposium on Applied Computing, SAC ’25, page 730–737. ACM.

Vormayr, G., Fabini, J., and Zseby, T. (2020). Why are my flows different? a tutorial on flow exporters. IEEE Communications Surveys & Tutorials, 22(3):2064–2103.
Publicado
01/09/2026
ESPINDOLA, Allan da S.; SANTIN, Altair O.; CASIMIRO, António; FERREIRA, Pedro M.; VIEGAS, Eduardo K.. Beyond Attack Success Rate: Representing Consistency in Evading the NIDS Feature-Space. In: WORKSHOP DE CIBERSEGURANÇA EM IA - SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 1008-1015. DOI: https://doi.org/10.5753/sbseg_estendido.2026.33790.

Artigos mais lidos do(s) mesmo(s) autor(es)

<< < 1 2 3 4 > >>