

de Recherche et d’Innovation
en Cybersécurité et Société
Guerziz, I.; Falk, T.; Le, L. B.; Houda, Z. A. E.
Domain Adversarial Neural Networks with Adversarial Robustness Evaluation for Intrusion Detection Systems Article d'actes
Dans: K., Adi; O., Nguena Timo; N., Boulahia-Cuppens; D., Espes; N., Stakhanova; M., Omar (Ed.): Lect. Notes Comput. Sci., p. 153–165, Springer Science and Business Media Deutschland GmbH, 2026, ISBN: 03029743 (ISSN); 978-303220731-9 (ISBN), (Journal Abbreviation: Lect. Notes Comput. Sci.).
Résumé | Liens | BibTeX | Étiquettes: Adversarial Attacks, Adversarial neural network, Adversarial Neural Networks, Attack Resilience, Attack resiliences, Computer crime, Domain adaptation, Fast gradient sign method, FGSM, Gradient-descent, Intrusion Detection, Intrusion Detection Systems, Network intrusion, Network intrusion detection systems, Network security, Neural networks, Neural-networks, PGD, Projected gradient, Projected gradient descent
@inproceedings{guerzizDomainAdversarialNeural2026,
title = {Domain Adversarial Neural Networks with Adversarial Robustness Evaluation for Intrusion Detection Systems},
author = {I. Guerziz and T. Falk and L. B. Le and Z. A. E. Houda},
editor = {Adi K. and Nguena Timo O. and Boulahia-Cuppens N. and Espes D. and Stakhanova N. and Omar M.},
url = {https://www.scopus.com/pages/publications/105046102448?origin=resultslist},
doi = {10.1007/978-3-032-20732-6_10},
isbn = {03029743 (ISSN); 978-303220731-9 (ISBN)},
year = {2026},
date = {2026-01-01},
booktitle = {Lect. Notes Comput. Sci.},
volume = {16295 LNCS},
pages = {153–165},
publisher = {Springer Science and Business Media Deutschland GmbH},
abstract = {Modern Network Intrusion Detection Systems (NIDS) face the dual challenge of maintaining performance across diverse network environments while resisting adversarial manipulations. This paper investigates the intersection of domain adaptation and adversarial robustness in NIDS, a topic that has not been extensively studied. We implement a Domain-Adversarial Neural Network (DANN) with dynamic gradient reversal to adapt models from NSL-KDD to UNSW-NB15. To evaluate security, we assess the model under Fast Gradient Sign Method (FGSM) and Projected Gradient Descent (PGD) attacks. Additionally, we introduce FGSM-based adversarial training to enhance robustness. Our results show that while domain adaptation improves cross-domain detection, it also increases susceptibility to adversarial attacks. Incorporating adversarial training mitigates this vulnerability, improving resilience without compromising performance on clean data. These findings provide key insights for designing adaptive and secure intrusion detection systems. © The Author(s), under exclusive license to Springer Nature Switzerland AG 2026.},
note = {Journal Abbreviation: Lect. Notes Comput. Sci.},
keywords = {Adversarial Attacks, Adversarial neural network, Adversarial Neural Networks, Attack Resilience, Attack resiliences, Computer crime, Domain adaptation, Fast gradient sign method, FGSM, Gradient-descent, Intrusion Detection, Intrusion Detection Systems, Network intrusion, Network intrusion detection systems, Network security, Neural networks, Neural-networks, PGD, Projected gradient, Projected gradient descent},
pubstate = {published},
tppubtype = {inproceedings}
}
Soltani, N.; Nejadshamsi, S.; Houda, Z. A. El; Khoury, R.; Costa, K. A. P.; Falk, T. H.; Avila, A. R.
Enhancing Network Intrusion Detection Systems: A Multi-Layer Ensemble Approach to Mitigate Adversarial Attacks Article d'actes
Dans: Conf. Proc. IEEE Int. Conf. Syst. Man Cybern., p. 39–44, Institute of Electrical and Electronics Engineers Inc., 2025, ISBN: 1062922X (ISSN); 979-833153358-8 (ISBN), (Journal Abbreviation: Conf. Proc. IEEE Int. Conf. Syst. Man Cybern.).
Résumé | Liens | BibTeX | Étiquettes: Adversarial machine learning, Adversarial networks, Classification (of information), Computer crime, Fast gradient sign method, Fast Gradient Sign Method (FGSM), Generative adversarial network, Generative Adversarial Network (GAN), Generative adversarial networks, Generative model, Generative Models, Intrusion Detection, Intrusion-Detection, Learning algorithms, Learning systems, Machine-learning, Multi-layers, Network intrusion, Network intrusion detection systems, Network layers, Network security, Second layer, Stackings
@inproceedings{soltaniEnhancingNetworkIntrusion2025,
title = {Enhancing Network Intrusion Detection Systems: A Multi-Layer Ensemble Approach to Mitigate Adversarial Attacks},
author = {N. Soltani and S. Nejadshamsi and Z. A. El Houda and R. Khoury and K. A. P. Costa and T. H. Falk and A. R. Avila},
url = {https://www.scopus.com/pages/publications/105033159769?origin=resultslist},
doi = {10.1109/SMC58881.2025.11342479},
isbn = {1062922X (ISSN); 979-833153358-8 (ISBN)},
year = {2025},
date = {2025-01-01},
booktitle = {Conf. Proc. IEEE Int. Conf. Syst. Man Cybern.},
pages = {39–44},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {Adversarial examples can represent a serious threat to machine learning (ML) algorithms. If used to manipulate the behaviour of ML-based Network Intrusion Detection Systems (NIDS), they can jeopardize network security. In this work, we aim to mitigate such risks by increasing the robustness of NIDS towards adversarial attacks. To that end, we explore two adversarial methods for generating malicious network traffic. The first method is based on Generative Adversarial Networks (GAN) and the second one is the Fast Gradient Sign Method (FGSM). The adversarial examples generated by these methods are then used to evaluate a novel multilayer defense mechanism, specifically designed to mitigate the vulnerability of ML-based NIDS. Our solution consists of one layer of stacking classifiers and a second layer based on an autoencoder. If the incoming network data are classified as benign by the first layer, the second layer is activated to ensure that the decision made by the stacking classifier is correct. We also incorporated adversarial training to further improve the robustness of our solution. Experiments on two datasets, namely UNSW-NB15 and NSL-KDD, demonstrate that the proposed approach increases resilience to adversarial attacks. © 2025 IEEE.},
note = {Journal Abbreviation: Conf. Proc. IEEE Int. Conf. Syst. Man Cybern.},
keywords = {Adversarial machine learning, Adversarial networks, Classification (of information), Computer crime, Fast gradient sign method, Fast Gradient Sign Method (FGSM), Generative adversarial network, Generative Adversarial Network (GAN), Generative adversarial networks, Generative model, Generative Models, Intrusion Detection, Intrusion-Detection, Learning algorithms, Learning systems, Machine-learning, Multi-layers, Network intrusion, Network intrusion detection systems, Network layers, Network security, Second layer, Stackings},
pubstate = {published},
tppubtype = {inproceedings}
}



