Novel Multistage Adversarial Attack Defense Framework for DDoS Attack Detection Systems

Investigations at Addis Ababa University have led to the development of a novel Multistage Adversarial Attack Defense (MSAAD) framework to protect online DDoS attack detection systems from adversarial attacks. This breakthrough framework consists of three defense layers, designed to detect and prevent DDoS attacks in IoT systems. The MSAAD framework has been shown to be highly effective in improving the accuracy of DDoS attack detection models in the presence of adversarial attacks.

Key Takeaways:

  • The MSAAD framework consists of three defense layers: Resilient Adversarial Detector and Purification (RADP), multiple classifier, and Multi-Armed Bandit (MAB) with Thompson Sampling.
  • The RADP layer detects and purifies adversarial attacks targeting online DDoS attack detection systems against multiple and unknown adversarial attacks.
  • The multiple classifier layer increases complexity for an attacker to replicate the DDoS attack detection model.
  • The MAB layer dynamically selects the optimal classifier or ensemble of classifiers for each incoming traffic request.
  • The MSAAD framework was tested using the IOTID20 and CICIoT2023 datasets, resulting in improved accuracy of the MLBTSE based DDoS attack detection model from 32.38%-60.58% to 99.39%-99.48% for the IOTID20 dataset, and from 66.60%-86.20% to 99.01%-99.14% for the CICIoT2023 datasets.
  • The research was conducted by Yonas Kibret Beshah, Surafel Lemma Abebe, and Henock Mulugeta Melaku from the School of Information Technology and Engineering, Addis Ababa Institute of Technology, Addis Ababa University, Ethiopia.

Statistics:

  • Accuracy of the MLBTSE based DDoS attack detection model improved from 32.38%-60.58% to 99.39%-99.48% for the IOTID20 dataset.
  • Accuracy of the MLBTSE based DDoS attack detection model improved from 66.60%-86.20% to 99.01%-99.14% for the CICIoT2023 datasets.
  • The MSAAD framework was tested using two datasets: IOTID20 and CICIoT2023.

Sources:

  • Multi-Stage Adversarial Defense for Online DDoS Attack Detection System in IoT. IEEE Access, 2025, 13():72657-72673. (IEEE Access - http://ieeexplore.ieee.org/servlet/opac?punumber=6287639)
  • NewsRx. New Machine Learning Study Findings Reported from Addis Ababa University (Multi-Stage Adversarial Defense for Online DDoS Attack Detection System in IoT). Journal of Engineering. May 12, 2025; p 1987.