Dataset-Calibrated Perturbation Budgets for Adversarial Robustness Evaluation of Machine-Learning Network Intrusion Detection Systems
Adversarial evaluation of machine-learning-based network intrusion detection systems (NIDSs) requires an explicit bound on attacker perturbations, yet fixed bounds are often reused across datasets without verifying scale comparability. We evaluate two differentiable detectors on CICIDS2017, TON_IoT, and UNSW-NB15 using a constrained, control-surface-aware evasion procedure in which perturbation cost is measured in interquartile-range units. The measured constrained feature-space evasion cost differs by more than two orders of magnitude across benchmarks. On UNSW-NB15, changing only the perturbation bound from a fixed reference value of 50 to a dataset-calibrated P95 value changes measured evasion success from 2.6% to 84.0%, with the conclusion remaining stable across P90, P95, and P99 calibration. We therefore propose a dataset-specific quantile calibration procedure and a monotonicity-based internal validity test exploiting nested attacker action spaces. Calibration removes the severe fixed-bound monotonicity violations observed on the two most poorly scaled datasets, although the test remains diagnostic rather than certifying. A secondary attribution-based robustness estimator does not generalise consistently across the three benchmarks. These results show that perturbation-budget calibration is an essential component of credible cross-dataset adversarial NIDS evaluation.
Authors
- Mohsen S. Alsaadi
- Iulian Sorin Munteanu (ORCID: https://orcid.org/0000-0001-7223-586X)
- Wasim A. Ali (ORCID: https://orcid.org/0000-0002-4602-461X)
- Malik AL-Essa (ORCID: https://orcid.org/0000-0002-0892-975X)
- Muhammad Imran (ORCID: https://orcid.org/0009-0009-5441-0359)
- Noora Fadhel
Institutions
- University of Jordan (JO)
- University of Bari Aldo Moro (IT)
- Universitatea Națională de Știință și Tehnologie Politehnica București (RO)
- Polytechnic University of Bari (IT)
Publication Details
- Journal
- Technologies
- Published
- 2026-10-09
- DOI
- https://doi.org/10.3390/technologies14100647
- Primary Topic
- Adversarial Robustness in Machine Learning
- Type
- article
- Field-Weighted Citation Impact
- 0.00