Abstract
As adversarial attacks become more sophisticated, AI-driven intrusion detection models are increasingly at risk. Adversarial evasion typically originates from data leakage, allowing attackers to infer training data and generate adversarial examples that evade detection. This study proposes a Privacy-Preserving Adversarial Training Framework (PPATF), a robustness-enhancing architecture that combines adversarial transfer learning optimized with differential privacy—to ensure data privacy—and data smoothing techniques—to reduce the sensitivity of both input and output data. Experiments were conducted using LightGBM-based models, trained on the MQTTset and UNSW-NB15 datasets. Model robustness was evaluated under closed box scenarios using Zero Order Optimization and HopSkipJump attacks. To validate practical applicability in constrained environments, both training and inference times were considered. The results confirm that the proposed ensemble framework, which integrates DP-SGD–optimized shadow models with data smoothing, achieves significant gains in robustness while maintaining original performance levels.
Author supplied keywords
Cite
CITATION STYLE
Han, W., & Lee, S. (2025). PPATF: A Privacy-Preserving Adversarial Training Framework to Enhance the Robustness of Lightweight Intrusion Detection Models. IEEE Access, 13, 199227–199246. https://doi.org/10.1109/ACCESS.2025.3635667
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.