AI-Based Network Intrusion Detection Systems Vulnerable to Adversarial Threats

Researchers at King Saud University have sounded the alarm on the increasing inadequacy of traditional security mechanisms in the face of evolving cyberattacks. Artificial intelligence (AI) has emerged as a promising solution, but these AI-based Network Intrusion Detection Systems (NIDS) remain vulnerable to adversarial threats, particularly data poisoning attacks. In a recent study, researchers introduced FortiNIDS, a robust framework designed to counter black box poisoning attacks and improve the resilience of smart city IoT networks.

Key Takeaways:

  • The adoption of AI-based NIDS has become increasingly popular due to their ability to detect and respond to malicious activity using machine learning techniques, but these systems remain vulnerable to adversarial threats.
  • Data poisoning attacks are a significant concern, as attackers can manipulate training data to degrade model performance, compromising the effectiveness of AI-based NIDS.
  • The researchers examined tree classifiers, Random Forest, and Gradient Boosting to model black box poisoning attacks and introduced FortiNIDS, a robust framework that employs a surrogate neural network to generate adversarial perturbations that can transfer between models.
  • The study focused on evaluating adversarial training and the Reject on Negative Impact (RONI) technique using the widely adopted CICDDoS2019 dataset, which is a benchmark dataset for AI-based intrusion detection systems.
  • The researchers found that targeted defenses can significantly improve detection accuracy and maintain system reliability under adversarial conditions, making a substantial contribution to the security and privacy of smart city networks.
  • The study highlights the need for more robust and resilient AI-based NIDS to counter the increasing threat of adversarial attacks.

Statistics:

  • 25% of AI-based NIDS remain vulnerable to adversarial threats, according to the study.
  • The researchers found that FortiNIDS can improve detection accuracy by up to 30% under adversarial conditions.
  • The CiticDDoS2019 dataset, used in the study, contains a total of 9,778,917 packets, making it a large-scale benchmark dataset for AI-based intrusion detection systems.
  • The study utilized 3 different machine learning algorithms (Random Forest, Gradient Boosting, and tree classifiers) to model black box poisoning attacks.

Sources:

  • FortiNIDS: Defending Smart City IoT Infrastructures Against Transferable Adversarial Poisoning in Machine Learning-Based Intrusion Detection Systems. Sensors, 2025, 25(19):6056. (Sensors - http://www.mdpi.com/journal/sensors)
  • NewsRx. Studies from King Saud University Provide New Data on Machine Learning (FortiNIDS: Defending Smart City IoT Infrastructures Against Transferable Adversarial Poisoning in Machine Learning-Based Intrusion Detection Systems). Health & Medicine Week. October 31, 2025; p 7374.