PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
March 10, 2026Journal of Information Security and Applications3 citationsOpen Access

A novel perturb-ability score to mitigate evasion adversarial attacks on flow-based ML-NIDS

View Full Paper
MEMohamed ElShehabyAMAshraf Matrawy

Key Points

  • The aim is to develop a score that measures how vulnerable features of ML-based NIDS are to attacks, enhancing network security.
  • Introduced the Perturb-ability Score (PS) for quantifying feature susceptibility to manipulation.
  • Developed PS-guided defenses including feature selection and masking.
  • Validated the approach on datasets: UNSW-NB15, CSE-CIC-IDS2018, and MCFP.
  • Achieved a 0% attack success rate with high detection accuracy using PS-guided defenses.
  • Confirmed that masking high-PS features maintains solid detection performance.
  • Indicated effective universal protection across different ML models without added overhead.

Abstract

• Proposes PS to quantify flow-based NIDS features susceptibility to attacks. • PS-guided defenses achieve 0% attack success rate with high detection accuracy. • Universal protection independent of attack types and ML models without overhead. • Validated across UNSW-NB15, CSE-CIC-IDS2018 and MCFP datasets. As network security threats evolve, safeguarding flow-based Machine Learning (ML)-based Network Intrusion Detection Systems (NIDS) from evasion adversarial attacks is crucial. This paper introduces the notion of feature perturb-ability and presents a novel Perturb-ability Score (PS) , which quantifies how susceptible NIDS features are to manipulation in the problem-space by an attacker. PS thereby identifies features structurally resistant to evasion attacks in flow-based ML-NIDS due to the semantics of network traffic fields, as these features are constrained by domain-specific limitations and correlations. Consequently, attempts to manipulate such features would likely either compromise the attack’s malicious functionality, render the traffic invalid for processing, or potentially both outcomes simultaneously. We introduce and demonstrate the effectiveness of our PS-enabled defenses, PS-guided feature selection and PS-guided feature masking, in enhancing flow-based NIDS resilience. Experimental results across various ML-based NIDS models and public datasets show that discarding or masking highly manipulatable features (high-PS features) can maintain solid detection performance while significantly reducing vulnerability to evasion adversarial attacks. Our findings confirm that PS effectively identifies flow-based NIDS features susceptible to problem-space perturbations. This novel approach leverages problem-space NIDS domain constraints as lightweight universal defense mechanisms against evasion adversarial attacks targeting flow-based ML-NIDS.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

ElShehaby et al. (2026) studied this question.

synapsesocial.com/papers/69af952b70916d39fea4c6efhttps://doi.org/10.1016/j.jisa.2026.104409
Ask AI
Helpful
Bookmark
Share
View Full Paper