AEGIS: A Self-Hardening Network Intrusion Detection Framework Using Generative Adversarial Retraining

Machine learning-based Intrusion Detection Systems (ML-IDS) achieve detection accuracy exceeding 98% on clean network traffic benchmarks, yet this performance collapses under adversarial evasion because existing defences employ static, batch-mode retraining that cannot sustain protection against adversaries who adapt their evasion strategy after observing the retrained model. This project presents AEGIS (Adversarial Engine for Generative Intrusion Suppression): a self-hardening framework that closes the attack-defence loop through continuous, GAN-driven adversarial retraining grounded in the Moving Target Defence (MTD) paradigm, integrating Suricata for real-time network flow capture and Wazuh for SIEM-level active response within a Docker testbed. The framework combines a Random Forest (RF) classifier and a Feature Tokenizer Transformer (FT-Transformer), both augmented with SMOTE class balancing and MinMaxScaler normalisation, evaluated on the NF-UQ-NIDS-v2 dataset. Config A established a pre-hardening evasion rate of 84.4% against the unprotected RF classifier; Config B reduced evasion to 0.0% after a single adversarial retrain, with a latency of 15.8 seconds; and Config C demonstrated stable RF detection across ten self-hardening rounds, all meeting pre-defined performance targets. The FT-Transformer, evaluated across nineteen rounds, did not suppress evasion at any point, establishing that adversary capability rather than detector architecture is the primary determinant of MTD loop effectiveness. These results confirm that continuous GAN-driven adversarial retraining operationalises MTD at the machine learning layer and raises the practical cost of sustained adversarial evasion against network intrusion detection systems.

Authors

Institutions

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-09-14
DOI
https://doi.org/10.5281/zenodo.22758705
Primary Topic
Network Security and Intrusion Detection
Type
preprint
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
preprint

AEGIS: A Self-Hardening Network Intrusion Detection Framework Using Generative Adversarial Retraining

Alshafaraz Gazi
Zenodo (CERN European Organization for Nuclear Research)
Network Security and Intrusion Detection
preprint

AEGIS: A Self-Hardening Network Intrusion Detection Framework Using Generative Adversarial Retraining

Alshafaraz Gazi
preprint en

Abstract

Machine learning-based Intrusion Detection Systems (ML-IDS) achieve detection accuracy exceeding 98% on clean network traffic benchmarks, yet this performance collapses under adversarial evasion because existing defences employ static, batch-mode retraining that cannot sustain protection against adversaries who adapt their evasion strategy after observing the retrained model. This project presents AEGIS (Adversarial Engine for Generative Intrusion Suppression): a self-hardening framework that closes the attack-defence loop through continuous, GAN-driven adversarial retraining grounded in the Moving Target Defence (MTD) paradigm, integrating Suricata for real-time network flow capture and Wazuh for SIEM-level active response within a Docker testbed. The framework combines a Random Forest (RF) classifier and a Feature Tokenizer Transformer (FT-Transformer), both augmented with SMOTE class balancing and MinMaxScaler normalisation, evaluated on the NF-UQ-NIDS-v2 dataset. Config A established a pre-hardening evasion rate of 84.4% against the unprotected RF classifier; Config B reduced evasion to 0.0% after a single adversarial retrain, with a latency of 15.8 seconds; and Config C demonstrated stable RF detection across ten self-hardening rounds, all meeting pre-defined performance targets. The FT-Transformer, evaluated across nineteen rounds, did not suppress evasion at any point, establishing that adversary capability rather than detector architecture is the primary determinant of MTD loop effectiveness. These results confirm that continuous GAN-driven adversarial retraining operationalises MTD at the machine learning layer and raises the practical cost of sustained adversarial evasion against network intrusion detection systems.

Zenodo (CERN European Organization for Nuclear Research)
Whitecliffe College of Arts and Design (NZ)
Network Security and Intrusion Detection
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.