[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-83568-en":3,"doc-seo-83568-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},83568,34359740700684,"Finn","https://ap-avatar.wpscdn.com/avatar/1f400023980c374ae676?_k=1777273430885731487",8,"Research & Report","Detecting Adversarial Evasion Attacks Against Autoencoder-Based Network Intrusion Detection Systems","Evasion attacks manipulate inputs to machine-learning systems to force incorrect predictions while keeping manipulated traffic visually or structurally benign. Using the PANDA pipeline, adversarial examples from vision are transferred to network intrusion detection by converting packet sequences into invertible grayscale images, enabling gradient-based attacks such as masked FGSM against autoencoder-based NIDS. The resulting perturbations alter the anomaly score without changing attack semantics, undermining threshold-only defenses. This work introduces the Residual Localisation Detector (RLD) and the Feature-Space Perturbation Consistency (FPC) Detector and evaluates them on UQ-IoT across benign, malicious, and adversarial traffic.","Detecting Adversarial Evasion Attacks Against Autoencoder-Based Network Intrusion Detection Systems  \nNiklas Bunzel  \nFraunhofer SIT / TU Darmstadt / ATHENE Darmstadt, Germany [niklas.bunzel@sit.fraunhofer.de](niklas.bunzel@sit.fraunhofer.de)  \nAshim Siwakoti  \nTU Darmstadt Darmstadt, Germany [siwakoti.ashim1995@gmail.com](siwakoti.ashim1995@gmail.com)  \narXiv :2607 .0 1 194v 1 [ cs .CR] 1 Jul 2026  \nABSTRACT  \nEvasion attacks deliberately manipulate input to an ML-based system to produce an incorrect prediction while the manipulated input still appears benign. The PANDA framework has demonstrated that adversarial examples developed for the vision domain can be transferred to the network domain by converting packet sequences into invertible grayscale images, enabling gradient-based attacks such as masked FGSM against autoencoder-based network intrusion detection systems (NIDS) . These attacks manipulate the NIDS anomaly score without altering the underlying attack semantics, leaving defenders without a straightforward way to distinguish between benign flows and carefully perturbed malicious traffic. In this paper, we propose two complementary detectors: the Residual Localisation Detector (RLD), which tracks the spatial concentration of reconstruction errors in the inter-arrival time feature region in image space; and the Feature-Space Perturbation Consistency (FPC) Detector, which operates directly on packet-level inter-arrival time features in packet-feature space. We evaluate both detectors on benign, malicious, and adversarial traffic from multiple IoT devices in the UQ-IoT dataset. Both detectors achieve near-perfect detection performance (TNR, TPR, precision, recall, and F1-score ≥ 0. 99) against adversarial examples across the evaluated IoT traffic. Our results indicate that integrating reconstruction-based scoring with perturbation consistency checks, in both image space and packet-feature space, offers a practical defence against emerging PANDA-style adversarial attacks on NIDS.  \n1 INTRODUCTION  \nNetworked systems are routinely exposed to a broad range of attacks, from denial-of-service and data exfiltration to lateral movement across enterprise and IoT environments [3, 8, 17] . Network Intrusion Detection Systems (NIDS) play a central role in such environments by observing traffic and raising alarms when flows deviate from expected behaviour [17, 20]. Classical NIDS either rely on hand-crafted signatures that match known attack patterns, or on anomaly-based techniques that learn a model of benign traffic and flag deviations [1, 21]. In recent years, anomaly-based NIDS have increasingly adopted machine-learning and deep-learning models, as these can capture complex non-linear relationships and often achieve higher detection rates [8, 13] .  \nIn parallel, adversarial machine learning (AML) has shown that even highly accurate ML models can be forced into misclassification by small, carefully crafted perturbations [9, 24] . This phenomenon was first studied in computer vision, but has since been applied to security-relevant tasks including NIDS [3, 15] . Transferring adversarial techniques to NIDS is more challenging than to image  \nclassifiers because of the mismatch between feature space and problem space [5, 23]. In image classification, the model operates directly on pixel values and gradients can be computed with respect to each pixel. In NIDS, raw packets must first be parsed and transformed into higher-level features, and these feature extractors are typically non-differentiable [10] .  \nThe PANDA framework by Swain et al. addresses this gap by proposing an invertible representation that enables gradient-based adversarial attacks directly on network traffic [23] . PANDA converts a sequence of packets into a grayscale image by extracting selected header and timing fields. A convolutional autoencoder (CNN-AE) is trained as an anomaly-based surrogate NIDS on these images. Because the mapping from packets to image is ","cbCaitCxciVpKWWl","https://ap.wps.com/l/cbCaitCxciVpKWWl","pdf",2081921,3,1,7,"English","en",105,"# Introduction\n## Background: NIDS and anomaly-based learning\n## Adversarial machine learning and challenges for NIDS\n## PANDA invertible representation and masked FGSM\n## Detector design for adversarial traffic\n# Proposed Detectors\n## Residual Localisation Detector (RLD)\n## Feature-Space Perturbation Consistency (FPC) Detector","[{\"question\":\"What problem does the paper address in autoencoder-based NIDS?\",\"answer\":\"It addresses adversarial evasion attacks where manipulated inputs keep traffic semantics intact but change the NIDS anomaly score enough to be classified as benign.\"},{\"question\":\"How does PANDA enable gradient-based adversarial attacks on network traffic?\",\"answer\":\"PANDA converts packet sequences into invertible grayscale images using selected header and timing fields, trains a convolutional autoencoder surrogate, and uses a masked FGSM variant that perturbs inter-arrival time bits.\"},{\"question\":\"What detectors does the paper propose to identify adversarial traffic?\",\"answer\":\"It proposes two complementary detectors: RLD, which analyzes where reconstruction errors concentrate in an image-space region tied to inter-arrival times, and FPC, which checks consistency of perturbations directly on packet-level inter-arrival time features.\"}]",1784188902,18,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"detecting-adversarial-evasion-attacks-against-autoencoder-based-network-intrusion-detection-systems","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":20},"https://docshare.wps.com/document/research-report/",{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/detecting-adversarial-evasion-attacks-against-autoencoder-based-network-intrusion-detection-systems/83568/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-26","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does the paper address in autoencoder-based NIDS?","Question",{"text":75,"@type":76},"It addresses adversarial evasion attacks where manipulated inputs keep traffic semantics intact but change the NIDS anomaly score enough to be classified as benign.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does PANDA enable gradient-based adversarial attacks on network traffic?",{"text":80,"@type":76},"PANDA converts packet sequences into invertible grayscale images using selected header and timing fields, trains a convolutional autoencoder surrogate, and uses a masked FGSM variant that perturbs inter-arrival time bits.",{"name":82,"@type":73,"acceptedAnswer":83},"What detectors does the paper propose to identify adversarial traffic?",{"text":84,"@type":76},"It proposes two complementary detectors: RLD, which analyzes where reconstruction errors concentrate in an image-space region tied to inter-arrival times, and FPC, which checks consistency of perturbations directly on packet-level inter-arrival time features.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,119,122,127,130,134],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":22,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]