Researchers Develop Novel Framework to Generate Evasive Malicious Traffic, Evading ML/DL-Based NIDS
Researchers at Space Engineering University in Beijing, People's Republic of China, have developed a novel framework called Transfficformer to generate adversarial attack traffic that can evade modern Network Intrusion Detection Systems (NIDS) powered by machine learning (ML) and deep learning (DL). The framework combines a heuristic algorithm and a transformer to generate mutant malicious traffic with reversible metadata feature vectors. Experimental results demonstrate that Transfficformer can autonomously generate such traffic, effectively evading various ML/DL-based NIDS with minimal overhead.
Key Takeaways:
- The researchers proposed Transfficformer, a novel framework that generates adversarial attack traffic to evade ML/DL-based NIDS.
- The framework utilizes a three-layer particle swarm optimization algorithm to optimize the generation of adversarial mutation malicious traffic with reversible metadata feature vectors.
- The discriminator feedback probability is fine-tuned using reinforcement learning strategies to preserve both malicious intent and normal communication functionality within the generated traffic.
- Comprehensive experiments demonstrated that Transfficformer can autonomously generate mutant malicious traffic, effectively evading various ML/DL-based NIDS with minimal overhead.
- The practicality of the generated mutant traffic was validated in the NSFOCUS cyber range.
- The research was funded by the National Natural Science Foundation of China (NSFC).
- Weijie Han, Wenbiao Du, Jingfeng Xue, Xiuqi Yang, Wenjie Guo, and Dujuan Gu are the authors of the research.
Statistics:
- The framework was trained using a dataset of discrete sequence autoregressive models.
- The three-layer particle swarm optimization algorithm was used to optimize the generation of adversarial mutation malicious traffic.
- The discriminator feedback probability was fine-tuned using reinforcement learning strategies.
- The experimental results demonstrated that Transfficformer can generate mutant malicious traffic with an accuracy of 95%. (Source: Knowledge-Based Systems)
- The overhead of using Transfficformer was minimal, with a processing time of less than 1 second per packet. (Source: Knowledge-Based Systems)
Sources:
- Transfficformer: a Novel Transformer-based Framework To Generate Evasive Malicious Traffic. Knowledge-Based Systems, 2025;319.
- National Natural Science Foundation of China (NSFC)
- Elsevier (www.elsevier.com)
- Knowledge-Based Systems (www.journals.elsevier.com/knowledge-based-systems/)