Researchers Develop Novel Framework to Generate Evasive Malicious Traffic, Evading ML/DL-Based NIDS

Researchers at Space Engineering University in Beijing, People's Republic of China, have developed a novel framework called Transfficformer to generate adversarial attack traffic that can evade modern Network Intrusion Detection Systems (NIDS) powered by machine learning (ML) and deep learning (DL). The framework combines a heuristic algorithm and a transformer to generate mutant malicious traffic with reversible metadata feature vectors. Experimental results demonstrate that Transfficformer can autonomously generate such traffic, effectively evading various ML/DL-based NIDS with minimal overhead.

Key Takeaways:

  • The researchers proposed Transfficformer, a novel framework that generates adversarial attack traffic to evade ML/DL-based NIDS.
  • The framework utilizes a three-layer particle swarm optimization algorithm to optimize the generation of adversarial mutation malicious traffic with reversible metadata feature vectors.
  • The discriminator feedback probability is fine-tuned using reinforcement learning strategies to preserve both malicious intent and normal communication functionality within the generated traffic.
  • Comprehensive experiments demonstrated that Transfficformer can autonomously generate mutant malicious traffic, effectively evading various ML/DL-based NIDS with minimal overhead.
  • The practicality of the generated mutant traffic was validated in the NSFOCUS cyber range.
  • The research was funded by the National Natural Science Foundation of China (NSFC).
  • Weijie Han, Wenbiao Du, Jingfeng Xue, Xiuqi Yang, Wenjie Guo, and Dujuan Gu are the authors of the research.

Statistics:

  • The framework was trained using a dataset of discrete sequence autoregressive models.
  • The three-layer particle swarm optimization algorithm was used to optimize the generation of adversarial mutation malicious traffic.
  • The discriminator feedback probability was fine-tuned using reinforcement learning strategies.
  • The experimental results demonstrated that Transfficformer can generate mutant malicious traffic with an accuracy of 95%. (Source: Knowledge-Based Systems)
  • The overhead of using Transfficformer was minimal, with a processing time of less than 1 second per packet. (Source: Knowledge-Based Systems)

Sources:

  • Transfficformer: a Novel Transformer-based Framework To Generate Evasive Malicious Traffic. Knowledge-Based Systems, 2025;319.
  • National Natural Science Foundation of China (NSFC)
  • Elsevier (www.elsevier.com)
  • Knowledge-Based Systems (www.journals.elsevier.com/knowledge-based-systems/)