Detecting and Mitigating Adversarial Attacks: Model Comparison Between Tree-Based and Deep Learning-Based Intrusion Detection Systems

Authors

  • Idris Ibraheem Al-Hikmah University https://orcid.org/0009-0002-3677-2478
  • Sanni-Akintunde Awaw Kehinde https://orcid.org/0009-0006-4889-712X
  • Adewuyi M’Sahid Abiola https://orcid.org/0009-0009-4764-8123
  • Sanusi-Akintunde Aishat Taiwo https://orcid.org/0009-0006-6594-6579

DOI:

https://doi.org/10.25159/3005-4222/20907

Keywords:

Adversarial Attacks, Deep Learning Security, Robust Neural Networks, Threat Mitigation Strategies, Intrusion Detection System, Tree-Based Algorithm

Abstract

The study investigates the detection and mitigation of adversarial attacks targeting tree-based and deep learning-based intrusion detection systems (IDS). There has been a rise in advanced cyber threats; traditional IDS techniques often fall short, rendering them ineffective in some situations, prompting increased adoption of deep learning-based models as alternatives. These models are also prone to adversarial attacks that are creatively designed to deceive the system into classifying malicious traffic as benign. The Canadian Institute for Cybersecurity Intrusion Detection System 2017 (CICIDS2017) dataset was used for the study. Data were processed to handle missing values, normalisation features, and address the class imbalance using the ADASYN (adaptive synthetic) sampling approach. Evaluation was carried out on two models, namely the random forest classifier and the deep neural network system. An almost perfect accuracy of 99.80% was achieved with the random forest model, which shows its effectiveness against adversarial attacks like the fast gradient sign method (FGSM) and projected gradient descent (PGD). However, as promising as the deep neural network (DNN) system is, it only achieved an accuracy rate of 81%, which shows that it is open to adversarial attacks. Feature importance analysis highlighted critical network attributes, such as packet length and flow size, for intrusion detection. The finding shows the superior adversarial effectiveness of tree-based models relative to deep learning, which motivates for hybrid AI approaches and advanced future research. The study emphasises the integration of adversarial training, interoperability of models, and detection of anomalies. The study contributes to the ever-evolving development of robust and secure IDS, while not overlooking the recurring issues in cybersecurity.

References

Arjunan, T. 2024. “Real-Time Detection of Network Traffic Anomalies in Big Data Environments Using Deep Learning Models.” International Journal for Research in Applied Science and Engineering Technology 12 (III): 844–850. https://doi.org/10.22214/ijraset.2024.58946

Basati, A., and M. M. Faghih. 2023. “APAE: An IoT Intrusion Detection System Using Asymmetric Parallel Auto-Encoder.” Neural Computing and Applications 35 (7): 4813–4833. https://doi.org/10.1007/s00521-021-06011-9

Carlini, N., and D. A. Wagner. 2016. “Towards Evaluating the Robustness of Neural Networks.” In 2017 IEEE Symposium on Security and Privacy (SP), 39–57. Piscataway, NJ: IEEE. https://doi.org/10.1109/SP.2017.49

Okafor, M. O. 2024. “Deep Learning in Cybersecurity: Enhancing Threat Detection and Response.” World Journal of Advanced Research and Reviews 24 (3): 1116–1132. https://doi.org/10.30574/wjarr.2024.24.3.3819

Duan, Y., X. Zuo, H. Huang, B. Wu, and X. Zhao. 2023. “A Local Interpretability Model-Based Approach for Black-Box Adversarial Attack.” In Data Mining and Big Data, DMBD 2023, edited by Y. Tan and Y. Shi, 3–15. Singapore: Springer Nature. https://doi.org/10.1007/978-981-97-0844-4_1

Goodfellow, I. J., J. Shlens, and C. Szegedy. 2014. “Explaining and Harnessing Adversarial Examples.” Preprint, submitted December 14, 2014. https://doi.org/10.48550/arXiv.1412.6572

Hassan, M., S. Younis, A. Rasheed, and M. Bilal. 2022. “Integrating Single-Shot Fast Gradient Sign Method (FGSM) with Classical Image Processing Techniques for Generating Adversarial Attacks on Deep Learning Classifiers.” In Proceedings of the SPIE 12084, Fourteenth International Conference on Machine Vision (ICMV 2021), 1208415 (5 March 2022). https://doi.org/10.1117/12.2623585

Kimanzi, R., P. Kimanga, D. Cherori, and P. K. Gikunda. 2024. “Deep Learning Algorithms Used in Intrusion Detection Systems – A Review.” Preprint, submitted February 23, 2024. https://doi.org/10.48550/arXiv.2402.17020

Kuzior, A., I. Tiutiunyk, A. Zielińska, and R. Kelemen. 2024. “Cybersecurity and Cybercrime: Current Trends and Threats.” Journal of International Studies 17 (2): 220–239. https://doi.org/10.14254/2071-8330.2024/17-2/12

Li, G., P. Sharma, L. Pan, S. Rajasegarar, C. Karmakar, and N. Patterson. 2021. “Deep Learning Algorithms for Cyber Security Applications: A Survey.” Journal of Computer Security 29 (5): 447–471. https://doi.org/10.3233/JCS-200095

Lourdu Mahima Doss P., and M. Gunasekaran. “Generating and Defending Against Adversarial Examples for Loan Eligibility Prediction.” In 2023 International Conference on System, Computation, Automation and Networking (ICSCAN), 1–6. Piscataway, NJ: IEEE. https://doi.org/10.1109/ICSCAN58655.2023.10395585

Madry, A., A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu. 2017. “Towards Deep Learning Models Resistant to Adversarial Attacks.” Preprint, submitted June 19, 2017. https://doi.org/10.48550/arXiv.1706.06083

Mirzakhaninafchi, H. 2024. “Comparative Analysis of Deep Learning-Based Anomaly Detection Models for GPS Spoofing Detection.” MA thesis, South Dakota State University.

Mmaduekwe, U., and E. Mmaduekwe. 2024. “Cybersecurity and Cryptography: The New Era of Quantum Computing.” Current Journal of Applied Science and Technology 43 (5): 41–51. https://doi.org/10.9734/cjast/2024/v43i54377

Mousa, A. K., and M. N. Abdullah. 2023. “An Improved Deep Learning Model for DDoS Detection Based On Hybrid Stacked Autoencoder and Checkpoint Network.” Future Internet 15 (8): 278. https://doi.org/10.3390/fi15080278

Papernot, N., P. McDaniel, and I. Goodfellow. 2016. “Transferability in Machine Learning: From Phenomena to Black-Box Attacks Using Adversarial Samples.” Preprint, submitted May 24, 2016. https://doi.org/10.48550/arXiv.1605.07277

Roshan, K., and A. Zafar. 2021. “Utilizing XAI Technique to Improve Autoencoder Based Model for Computer Network Anomaly Detection with Shapley Additive Explanation (SHAP).” Preprint, submitted December 14, 2021. https://doi.org/10.48550/arXiv.2112.08442

Sharma, N. A., R. R. Chand, Z. Buksh, A. B. M. Ali, A. Hanif, and A. Beheshti. 2024. “Explainable AI Frameworks: Navigating the Present Challenges and Unveiling Innovative Applications.” Algorithms 17 (6): 227. https://doi.org/10.3390/a17060227

Smith, J., A. Lee, and R. Patel. 2024. “Adversarial Attacks on Deep Learning-Based Intrusion Detection Systems: A Review.” Computers and Security 115: 102195. https://doi.org/10.1016/j.cose.2024.102195

Tramèr, F., A. Kurakin, N. Papernot, I. Goodfellow, D. Boneh, and P. McDaniel. 2017. “Ensemble Adversarial Training: Attacks and Defenses.” Preprint, submitted May 19, 2017. https://doi.org/10.48550/arXiv.1705.07204

Zhang, M., X. Shi, and J. Huang. 2024. “Real-Time Anomaly Detection in Time Series Using Transformer-Like Architecture.” In 2024 IEEE International Conference on Artificial Intelligence Testing (AITest), 150–151. Piscataway, NJ: IEEE. https://doi.org/10.1109/AITest62860.2024.00026

Zhao, Y. 2024. “Improvement of the Robustness of Deep Learning Models Against Adversarial Attacks.” Applied and Computational Engineering 75: 285–289. https://doi.org/10.54254/2755-2721/75/20240556

Downloads

Published

2026-07-22

How to Cite

Ibraheem, Idris, Sanni-Akintunde Awaw Kehinde, Adewuyi M’Sahid Abiola, and Sanusi-Akintunde Aishat Taiwo. 2026. “Detecting and Mitigating Adversarial Attacks: Model Comparison Between Tree-Based and Deep Learning-Based Intrusion Detection Systems”. Southern African Journal of Security, July, 19 pages . https://doi.org/10.25159/3005-4222/20907.

Issue

Section

Articles
Received 2025-11-16
Accepted 2026-06-22
Published 2026-07-22