PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
March 21, 2026Electronics3 citationsOpen Access

A Systematic Ablation Study of GAN-Based Minority Augmentation for Intrusion Detection on UWF-ZeekData22

View Full Paper
ADAsfaw DebelieSBSikha BaguiSBS. C. Bagui

Key Points

  • This study aims to assess the effects of various GAN configurations and augmentation settings on the performance of intrusion detection systems.
  • Conducted a controlled ablation study using the UWF-ZeekData22 dataset.
  • Evaluated four GAN variants: Vanilla GAN, Conditional GAN, WGAN, and WGAN-GP.
  • Tested augmentation ratios of 0.25 and 0.50 with varying training durations (400 and 800 epochs).
  • Applied stratified cross-validation and assessed performance with five classical classifiers.
  • Moderate augmentation (0.25) with 400 epochs provided the most reliable increase in minority recall.
  • Wasserstein-based objectives showed enhanced stability with aggressive augmentation.
  • Conditional GANs experienced recall collapse in very sparse conditions.
  • Higher augmentation volumes can worsen classifier performance due to distribution overlaps.
  • Tree-based classifiers remained stable after reaching a sufficient minority density.

Abstract

Generative adversarial networks (GANs) are increasingly applied to mitigate extreme class imbalance in intrusion detection systems, yet reported improvements often obscure role augmentation intensity and adversarial stability. This paper presents a controlled ablation study that isolates the impact of adversarial objective choice, augmentation ratio, and training duration on GAN-based minority data augmentation for highly imbalanced tabular cybersecurity data. Using the UWF-ZeekData22 dataset, nine MITRE ATT&CK tactic-versus-benign classification tasks are evaluated under augmentation ratios of 0.25 and 0.50 and training durations of 400 and 800 epochs. Four GAN variants—Vanilla GAN, Conditional GAN (cGAN), WGAN, and WGAN-GP—are assessed using stratified cross-validation and five classical classifiers representing diverse inductive biases. The results reveal consistent structural patterns. Moderate augmentation (r = 0.25) with controlled training (400 epochs) yields the most stable and reliable improvement in minority recall. Wasserstein-based objectives demonstrate superior stability under aggressive augmentation and prolonged training, while conditional GANs frequently exhibit recall collapse in ultra-sparse regimes. Increasing augmentation volume does not uniformly improve performance and may introduce distributional overlaps that degrade linear and margin-based classifiers. Tree-based classifiers remain largely invariant once sufficient minority density is achieved. These findings demonstrate that adversarial calibration is more important than architectural complexity for improving the detection of rare attacks. The study provides practical guidance for designing robust GAN-based augmentation pipelines under extreme cybersecurity class imbalance.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Debelie et al. (2026) studied this question.

synapsesocial.com/papers/69be371c6e48c4981c67689ehttps://doi.org/10.3390/electronics15061291
Ask AI
Helpful
Bookmark
Share
View Full Paper