

de Recherche et d’Innovation
en Cybersécurité et Société
Soltani, N.; Nejadshamsi, S.; Houda, Z. A. El; Khoury, R.; Costa, K. A. P.; Falk, T. H.; Avila, A. R.
Enhancing Network Intrusion Detection Systems: A Multi-Layer Ensemble Approach to Mitigate Adversarial Attacks Article d'actes
Dans: Conf. Proc. IEEE Int. Conf. Syst. Man Cybern., p. 39–44, Institute of Electrical and Electronics Engineers Inc., 2025, ISBN: 1062922X (ISSN); 979-833153358-8 (ISBN), (Journal Abbreviation: Conf. Proc. IEEE Int. Conf. Syst. Man Cybern.).
Résumé | Liens | BibTeX | Étiquettes: Adversarial machine learning, Adversarial networks, Classification (of information), Computer crime, Fast gradient sign method, Fast Gradient Sign Method (FGSM), Generative adversarial network, Generative Adversarial Network (GAN), Generative adversarial networks, Generative model, Generative Models, Intrusion Detection, Intrusion-Detection, Learning algorithms, Learning systems, Machine-learning, Multi-layers, Network intrusion, Network intrusion detection systems, Network layers, Network security, Second layer, Stackings
@inproceedings{soltaniEnhancingNetworkIntrusion2025,
title = {Enhancing Network Intrusion Detection Systems: A Multi-Layer Ensemble Approach to Mitigate Adversarial Attacks},
author = {N. Soltani and S. Nejadshamsi and Z. A. El Houda and R. Khoury and K. A. P. Costa and T. H. Falk and A. R. Avila},
url = {https://www.scopus.com/pages/publications/105033159769?origin=resultslist},
doi = {10.1109/SMC58881.2025.11342479},
isbn = {1062922X (ISSN); 979-833153358-8 (ISBN)},
year = {2025},
date = {2025-01-01},
booktitle = {Conf. Proc. IEEE Int. Conf. Syst. Man Cybern.},
pages = {39–44},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {Adversarial examples can represent a serious threat to machine learning (ML) algorithms. If used to manipulate the behaviour of ML-based Network Intrusion Detection Systems (NIDS), they can jeopardize network security. In this work, we aim to mitigate such risks by increasing the robustness of NIDS towards adversarial attacks. To that end, we explore two adversarial methods for generating malicious network traffic. The first method is based on Generative Adversarial Networks (GAN) and the second one is the Fast Gradient Sign Method (FGSM). The adversarial examples generated by these methods are then used to evaluate a novel multilayer defense mechanism, specifically designed to mitigate the vulnerability of ML-based NIDS. Our solution consists of one layer of stacking classifiers and a second layer based on an autoencoder. If the incoming network data are classified as benign by the first layer, the second layer is activated to ensure that the decision made by the stacking classifier is correct. We also incorporated adversarial training to further improve the robustness of our solution. Experiments on two datasets, namely UNSW-NB15 and NSL-KDD, demonstrate that the proposed approach increases resilience to adversarial attacks. © 2025 IEEE.},
note = {Journal Abbreviation: Conf. Proc. IEEE Int. Conf. Syst. Man Cybern.},
keywords = {Adversarial machine learning, Adversarial networks, Classification (of information), Computer crime, Fast gradient sign method, Fast Gradient Sign Method (FGSM), Generative adversarial network, Generative Adversarial Network (GAN), Generative adversarial networks, Generative model, Generative Models, Intrusion Detection, Intrusion-Detection, Learning algorithms, Learning systems, Machine-learning, Multi-layers, Network intrusion, Network intrusion detection systems, Network layers, Network security, Second layer, Stackings},
pubstate = {published},
tppubtype = {inproceedings}
}
Soultana, O. A.; Moudoud, H.
Adaptive Heterogeneous Ensemble Learning for Attack Detection in IoT Networks Article d'actes
Dans: Conf. Proc. IEEE Int. Conf. Syst. Man Cybern., p. 27–32, Institute of Electrical and Electronics Engineers Inc., 2025, ISBN: 1062922X (ISSN); 979-833153358-8 (ISBN), (Journal Abbreviation: Conf. Proc. IEEE Int. Conf. Syst. Man Cybern.).
Résumé | Liens | BibTeX | Étiquettes: Attack detection, Classification (of information), Computational efficiency, Detection accuracy, Ensemble learning, Ensemble techniques, Heterogeneous ensembles, Internet of thing security, Internet of things, Intrusion Detection, Intrusion-Detection, IoT Security, Learning systems, Nearest neighbor search, Security vulnerabilities, Stackings, Support vector machines, Zero-day attack, Zero-day detection
@inproceedings{soultanaAdaptiveHeterogeneousEnsemble2025,
title = {Adaptive Heterogeneous Ensemble Learning for Attack Detection in IoT Networks},
author = {O. A. Soultana and H. Moudoud},
url = {https://www.scopus.com/pages/publications/105033149093?origin=resultslist},
doi = {10.1109/SMC58881.2025.11343130},
isbn = {1062922X (ISSN); 979-833153358-8 (ISBN)},
year = {2025},
date = {2025-01-01},
booktitle = {Conf. Proc. IEEE Int. Conf. Syst. Man Cybern.},
pages = {27–32},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {The proliferation of Internet of Things (IoT) devices has introduced significant security vulnerabilities, particularly in detecting zero-day attacks within highly dynamic and heterogeneous environments. Traditional machine learning models often fall short due to their static nature and computational demands. In this paper, we propose an adaptive ensemble learning framework that dynamically selects optimal detection models on a per-attack-class basis to improve detection accuracy while maintaining computational efficiency. Our approach combines multiple base classifiers (Random Forest, K-Nearest Neighbors, and Support Vector Machine) using ensemble techniques including bagging, boosting, and stacking. Ensemble techniques such as Bagging, Boosting, Voting, and Stacking. The key innovation lies in a class-aware model selection mechanism that identifies the most effective classifier-ensemble combination for each specific attack category, rather than applying a single model across all threat types. This targeted approach recognizes that different attack patterns exhibit distinct characteristics that may be better captured by different algorithmic approaches. Finally, we propose a decision-rule mechanism that selects the best-performing model for each attack class to improve detection accuracy. The proposed framework is evaluated through extensive experiments. The results show that our approach significantly enhances classification performance, especially for complex and rare attack types. © 2025 IEEE.},
note = {Journal Abbreviation: Conf. Proc. IEEE Int. Conf. Syst. Man Cybern.},
keywords = {Attack detection, Classification (of information), Computational efficiency, Detection accuracy, Ensemble learning, Ensemble techniques, Heterogeneous ensembles, Internet of thing security, Internet of things, Intrusion Detection, Intrusion-Detection, IoT Security, Learning systems, Nearest neighbor search, Security vulnerabilities, Stackings, Support vector machines, Zero-day attack, Zero-day detection},
pubstate = {published},
tppubtype = {inproceedings}
}



