PPATF: A Privacy-Preserving Adversarial Training Framework to Enhance the Robustness of Lightweight Intrusion Detection Models

0Citations
Citations of this article
6Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

As adversarial attacks become more sophisticated, AI-driven intrusion detection models are increasingly at risk. Adversarial evasion typically originates from data leakage, allowing attackers to infer training data and generate adversarial examples that evade detection. This study proposes a Privacy-Preserving Adversarial Training Framework (PPATF), a robustness-enhancing architecture that combines adversarial transfer learning optimized with differential privacy—to ensure data privacy—and data smoothing techniques—to reduce the sensitivity of both input and output data. Experiments were conducted using LightGBM-based models, trained on the MQTTset and UNSW-NB15 datasets. Model robustness was evaluated under closed box scenarios using Zero Order Optimization and HopSkipJump attacks. To validate practical applicability in constrained environments, both training and inference times were considered. The results confirm that the proposed ensemble framework, which integrates DP-SGD–optimized shadow models with data smoothing, achieves significant gains in robustness while maintaining original performance levels.

Cite

CITATION STYLE

APA

Han, W., & Lee, S. (2025). PPATF: A Privacy-Preserving Adversarial Training Framework to Enhance the Robustness of Lightweight Intrusion Detection Models. IEEE Access, 13, 199227–199246. https://doi.org/10.1109/ACCESS.2025.3635667

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free