{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,15]],"date-time":"2026-07-15T16:09:01Z","timestamp":1784131741595,"version":"3.55.0"},"reference-count":61,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2025,2,22]],"date-time":"2025-02-22T00:00:00Z","timestamp":1740182400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nd\/4.0\/"}],"funder":[{"name":"U.S. Military Academy (USMA) under Cooperative Agreement","award":["W911NF-22-2-0045"],"award-info":[{"award-number":["W911NF-22-2-0045"]}]},{"name":"U.S. Army Combat Capabilities Development Command C5ISR Center","award":["USMA21056"],"award-info":[{"award-number":["USMA21056"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Priv. Secur."],"published-print":{"date-parts":[[2025,5,31]]},"abstract":"<jats:p>Recent advancements in artificial intelligence (AI) and machine learning (ML) algorithms, coupled with the availability of faster computing infrastructure, have enhanced the security posture of cybersecurity operations centers (defenders) through the development of ML-aided network intrusion detection systems (NIDS). Concurrently, the abilities of adversaries to evade security have also increased with the support of AI\/ML models. Therefore, defenders need to proactively prepare for evasion attacks that exploit the detection mechanisms of NIDS. Recent studies have found that the perturbation of flow-based and packet-based features can deceive ML models, but these approaches have limitations. Perturbations made to the flow-based features are difficult to reverse-engineer, while samples generated with perturbations to the packet-based features are not playable.<\/jats:p>\n          <jats:p>Our methodological framework, Deep PackGen, employs deep reinforcement learning to generate adversarial packets and aims to overcome the limitations of approaches in the literature. By taking raw malicious network packets as inputs and systematically making perturbations on them, Deep PackGen camouflages them as benign packets while still maintaining their functionality. In our experiments, using publicly available data, Deep PackGen achieved an average adversarial success rate of 66.4% against various ML models and across different attack types. Our investigation also revealed that more than 45% of the successful adversarial samples were out-of-distribution packets that evaded the decision boundaries of the classifiers. The knowledge gained from our study on the adversary\u2019s ability to make specific evasive perturbations to different types of malicious packets can help defenders enhance the robustness of their NIDS against evolving adversarial attacks.<\/jats:p>","DOI":"10.1145\/3712307","type":"journal-article","created":{"date-parts":[[2025,1,14]],"date-time":"2025-01-14T11:25:39Z","timestamp":1736853939000},"page":"1-33","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":22,"title":["Deep PackGen: A Deep Reinforcement Learning Framework for Adversarial Network Packet Generation"],"prefix":"10.1145","volume":"28","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-9326-291X","authenticated-orcid":false,"given":"Soumyadeep","family":"Hore","sequence":"first","affiliation":[{"name":"Department of Industrial and Management Systems Engineering, University of South Florida, Tampa, United States"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-7554-5740","authenticated-orcid":false,"given":"Jalal","family":"Ghadermazi","sequence":"additional","affiliation":[{"name":"Department of Industrial and Management Systems Engineering, University of South Florida, Tampa, United States"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4290-7191","authenticated-orcid":false,"given":"Diwas","family":"Paudel","sequence":"additional","affiliation":[{"name":"Department of Industrial and Management Systems Engineering, University of South Florida, Tampa, United States"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8314-6392","authenticated-orcid":false,"given":"Ankit","family":"Shah","sequence":"additional","affiliation":[{"name":"Department of Operations and Decision Technologies, Indiana University, Bloomington, United States"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8464-7383","authenticated-orcid":false,"given":"Tapas","family":"Das","sequence":"additional","affiliation":[{"name":"Department of Industrial and Management Systems Engineering, University of South Florida, Tampa, United States"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9957-2778","authenticated-orcid":false,"given":"Nathaniel","family":"Bastian","sequence":"additional","affiliation":[{"name":"Army Cyber Institute, United States Military Academy, West Point, United States"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,2,22]]},"reference":[{"key":"e_1_3_1_2_2","first-page":"1","volume-title":"Proceedings of the 2019 IEEE Conference on Network Function Virtualization and Software Defined Networks","author":"Aiken James","year":"2019","unstructured":"James Aiken and Sandra Scott-Hayward. 2019. Investigating adversarial attacks against network intrusion detection systems in sdns. In Proceedings of the 2019 IEEE Conference on Network Function Virtualization and Software Defined Networks. IEEE, 1\u20137."},{"key":"e_1_3_1_3_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2021.115782"},{"key":"e_1_3_1_4_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2020.3031843"},{"key":"e_1_3_1_5_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2022.118641"},{"key":"e_1_3_1_6_2","first-page":"155","article-title":"Scapy documentation (!)","volume":"469","author":"Biondi Philippe","year":"2010","unstructured":"Philippe Biondi. 2010. Scapy documentation (!). vol 469 (2010), 155\u2013203.","journal-title":"vol"},{"issue":"7","key":"e_1_3_1_7_2","doi-asserted-by":"crossref","first-page":"8704","DOI":"10.1109\/TITS.2021.3085217","article-title":"A reinforcement learning approach for rebalancing electric vehicle sharing systems","volume":"23","author":"Bogyrbayeva Aigerim","year":"2021","unstructured":"Aigerim Bogyrbayeva, Sungwook Jang, Ankit Shah, Young Jae Jang, and Changhyun Kwon. 2021. A reinforcement learning approach for rebalancing electric vehicle sharing systems. IEEE Transactions on Intelligent Transportation Systems 23, 7 (2021), 8704\u20138714.","journal-title":"IEEE Transactions on Intelligent Transportation Systems"},{"key":"e_1_3_1_8_2","doi-asserted-by":"publisher","DOI":"10.1109\/TCOM.1974.1092259"},{"key":"e_1_3_1_9_2","article-title":"Constrained optimization based adversarial example generation for transfer attacks in network intrusion detection systems","author":"Chale Marc","year":"2024","unstructured":"Marc Chale, Bruce Cox, Jeffery Weir, and Nathaniel D. Bastian. 2024. Constrained optimization based adversarial example generation for transfer attacks in network intrusion detection systems. Optimization Letters 18, 9 (2024), 2169\u20132188.","journal-title":"Optimization Letters"},{"key":"e_1_3_1_10_2","unstructured":"Qiumei Cheng Shiying Zhou Yi Shen Dezhang Kong and Chunming Wu. 2021. Packet-level adversarial network traffic crafting using sequence generative adversarial networks. arXiv preprint arXiv:2103.04794 (2021)."},{"key":"e_1_3_1_11_2","doi-asserted-by":"publisher","DOI":"10.1145\/3544746"},{"key":"e_1_3_1_12_2","first-page":"185","volume-title":"Artificial Intelligence and Machine Learning for Multi-Domain Operations Applications III","author":"Lucia Michael J. De","year":"2021","unstructured":"Michael J. De Lucia, Paul E. Maxwell, Nathaniel D. Bastian, Ananthram Swami, Brian Jalaian, and Nandi Leslie. 2021. Machine learning raw network traffic detection. In Artificial Intelligence and Machine Learning for Multi-Domain Operations Applications III, Vol. 11746. SPIE, 185\u2013194."},{"key":"e_1_3_1_13_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISI53945.2021.9624731"},{"key":"e_1_3_1_14_2","doi-asserted-by":"publisher","DOI":"10.5555\/2188385.2188410"},{"key":"e_1_3_1_15_2","first-page":"1","article-title":"A black-box attack method against machine-learning-based anomaly network flow detection models","volume":"2021","author":"Guo Sensen","year":"2021","unstructured":"Sensen Guo, Jinxiong Zhao, Xiaoyu Li, Junhong Duan, Dejun Mu, and Xiao Jing. 2021. A black-box attack method against machine-learning-based anomaly network flow detection models. Security and Communication Networks 2021, 1 (2021), 1\u201313.","journal-title":"Security and Communication Networks"},{"key":"e_1_3_1_16_2","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2021.3087242"},{"key":"e_1_3_1_17_2","doi-asserted-by":"publisher","DOI":"10.1145\/3359992.3366642"},{"key":"e_1_3_1_18_2","article-title":"Adversarial machine learning for network intrusion detection systems: A comprehensive survey","author":"He Ke","year":"2023","unstructured":"Ke He, Dan Dongseong Kim, and Muhammad Rizwan Asghar. 2023. Adversarial machine learning for network intrusion detection systems: A comprehensive survey. IEEE Communications Surveys & Tutorials 25, 1 (2023), 538\u2013566.","journal-title":"IEEE Communications Surveys & Tutorials"},{"key":"e_1_3_1_19_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.123"},{"key":"e_1_3_1_20_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3000179"},{"key":"e_1_3_1_21_2","doi-asserted-by":"publisher","unstructured":"Ivan Homoliak Martin Tekn\u00f8s Mart\u00een Ochoa Dominik Breitenbacher Saeid Hosseini and Petr Hanacek. 2018. Improving network intrusion detection classifiers by non-payload-based exploit-independent obfuscations: An adversarial approach. EAI Endorsed Transactions on Security and Safety 5 17 (December 2018). DOI:10.4108\/eai.10-1-2019.156245","DOI":"10.4108\/eai.10-1-2019.156245"},{"key":"e_1_3_1_22_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3152164"},{"key":"e_1_3_1_23_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2023.119734"},{"key":"e_1_3_1_24_2","first-page":"686","volume-title":"Proceedings of the 2020 IEEE 32nd International Conference on Tools with Artificial Intelligence","author":"Huang Weiqing","year":"2020","unstructured":"Weiqing Huang, Xiao Peng, Zhixin Shi, and Yuru Ma. 2020. Adversarial attack against LSTM-based DDoS intrusion detection system. In Proceedings of the 2020 IEEE 32nd International Conference on Tools with Artificial Intelligence. IEEE, 686\u2013693."},{"key":"e_1_3_1_25_2","doi-asserted-by":"crossref","first-page":"64","DOI":"10.1007\/978-3-030-49186-4_6","volume-title":"Proceedings of the Artificial Intelligence Applications and Innovations: 16th IFIP WG 12.5 International Conference, AIAI 2020, Neos Marmaras, Greece, June 5\u20137, 2020, Proceedings, Part II 16","author":"Kirtas Manos","year":"2020","unstructured":"Manos Kirtas, Konstantinos Tsampazis, Nikolaos Passalis, and Anastasios Tefas. 2020. Deepbots: A webots-based deep reinforcement learning framework for robotics. In Proceedings of the Artificial Intelligence Applications and Innovations: 16th IFIP WG 12.5 International Conference, AIAI 2020, Neos Marmaras, Greece, June 5\u20137, 2020, Proceedings, Part II 16. Springer, 64\u201375."},{"key":"e_1_3_1_26_2","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2017.4451203"},{"key":"e_1_3_1_27_2","doi-asserted-by":"publisher","DOI":"10.1145\/3339252.3339266"},{"issue":"3","key":"e_1_3_1_28_2","article-title":"A precision advertising strategy based on deep reinforcement learning.","volume":"25","author":"Liang Haiqing","year":"2020","unstructured":"Haiqing Liang. 2020. A precision advertising strategy based on deep reinforcement learning. Ing\u00e9nierie des Syst\u00e8mes d\u2019Information 25, 3 (2020).","journal-title":"Ing\u00e9nierie des Syst\u00e8mes d\u2019Information"},{"key":"e_1_3_1_29_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2015.01.009"},{"key":"e_1_3_1_30_2","doi-asserted-by":"publisher","DOI":"10.1007\/s00500-019-04030-2"},{"key":"e_1_3_1_31_2","unstructured":"Scott M. Lundberg and Su-In Lee. 2017. A unified approach to interpreting model predictions. In Proceedings of the 31st International Conference on Neural Information Processing Systems (NIPS\u201917) Curran Associates Inc. Long Beach California USA 4768\u20134777."},{"key":"e_1_3_1_32_2","unstructured":"Daoming Lyu. 2019. Knowledge-based sequential decision-making under uncertainty. arXiv preprint arXiv:1905.07030 (2019)."},{"key":"e_1_3_1_33_2","volume-title":"Testing Guide Release 4.0","author":"Meucci Matteo","year":"2014","unstructured":"Matteo Meucci and Andrew Muller. 2014. Testing Guide Release 4.0. OWASP Foundation. Retrieved from https:\/\/books.google.com\/books?id=i7c7zAEACAAJ"},{"key":"e_1_3_1_34_2","doi-asserted-by":"publisher","DOI":"10.1038\/nature14236"},{"key":"e_1_3_1_35_2","first-page":"2705","volume-title":"Proceedings of the USENIX Security Symposium","author":"Nasr Milad","year":"2021","unstructured":"Milad Nasr, Alireza Bahramali, and Amir Houmansadr. 2021. Defeating DNN-Based traffic analysis systems in real-time with blind adversarial perturbations.. In Proceedings of the USENIX Security Symposium. 2705\u20132722."},{"key":"e_1_3_1_36_2","doi-asserted-by":"crossref","DOI":"10.6028\/NIST.AI.100-2e2023.ipd","volume-title":"Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (Draft)","author":"Oprea Alina","year":"2023","unstructured":"Alina Oprea and Apostol Vassilev. 2023. Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (Draft). Technical Report. National Institute of Standards and Technology."},{"key":"e_1_3_1_37_2","doi-asserted-by":"crossref","DOI":"10.6028\/NIST.AI.100-2e2023.ipd","volume-title":"Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (Draft)","author":"Oprea Alina","year":"2023","unstructured":"Alina Oprea and Apostol Vassilev. 2023. Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (Draft). Technical Report. National Institute of Standards and Technology."},{"key":"e_1_3_1_38_2","doi-asserted-by":"crossref","first-page":"1332","DOI":"10.1109\/SP40000.2020.00073","volume-title":"Proceedings of the 2020 IEEE Symposium on Security and Privacy","author":"Pierazzi Fabio","year":"2020","unstructured":"Fabio Pierazzi, Feargus Pendlebury, Jacopo Cortellazzi, and Lorenzo Cavallaro. 2020. Intriguing properties of adversarial ml attacks in the problem space. In Proceedings of the 2020 IEEE Symposium on Security and Privacy. IEEE, 1332\u20131349."},{"key":"e_1_3_1_39_2","doi-asserted-by":"publisher","DOI":"10.17487\/RFC0791"},{"key":"e_1_3_1_40_2","unstructured":"Maria Rigaki. 2017. Adversarial Deep Learning Against Intrusion Detection Classifiers. (2017)."},{"key":"e_1_3_1_41_2","doi-asserted-by":"publisher","DOI":"10.17487\/RFC1624"},{"key":"e_1_3_1_42_2","doi-asserted-by":"publisher","DOI":"10.1145\/3453158"},{"key":"e_1_3_1_43_2","doi-asserted-by":"publisher","DOI":"10.1145\/3453158"},{"key":"e_1_3_1_44_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2021.3052888"},{"key":"e_1_3_1_45_2","doi-asserted-by":"crossref","first-page":"3343","DOI":"10.1109\/BigData52589.2021.9671580","volume-title":"Proceedings of the 2021 IEEE International Conference on Big Data","author":"Schneider Madeleine","year":"2021","unstructured":"Madeleine Schneider, David Aspinall, and Nathaniel D. Bastian. 2021. Evaluating model robustness to adversarial samples in network intrusion detection. In Proceedings of the 2021 IEEE International Conference on Big Data. IEEE, 3343\u20133352."},{"key":"e_1_3_1_46_2","doi-asserted-by":"crossref","first-page":"172","DOI":"10.1007\/978-3-030-25109-3_9","volume-title":"Proceedings of the Information Systems Security and Privacy: 4th International Conference, ICISSP 2018, Funchal-Madeira, Portugal, January 22\u201324, 2018, Revised Selected Papers 4","author":"Sharafaldin Iman","year":"2019","unstructured":"Iman Sharafaldin, Arash Habibi Lashkari, and Ali A. Ghorbani. 2019. A detailed analysis of the cicids2017 data set. In Proceedings of the Information Systems Security and Privacy: 4th International Conference, ICISSP 2018, Funchal-Madeira, Portugal, January 22\u201324, 2018, Revised Selected Papers 4. Springer, 172\u2013188."},{"key":"e_1_3_1_47_2","first-page":"108","article-title":"Toward generating a new intrusion detection dataset and intrusion traffic characterization.","volume":"1","author":"Sharafaldin Iman","year":"2018","unstructured":"Iman Sharafaldin, Arash Habibi Lashkari, and Ali A. Ghorbani. 2018. Toward generating a new intrusion detection dataset and intrusion traffic characterization. ICISSp 1 (2018), 108\u2013116.","journal-title":"ICISSp"},{"key":"e_1_3_1_48_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3201377"},{"key":"e_1_3_1_49_2","doi-asserted-by":"crossref","DOI":"10.3233\/JCS-210094","article-title":"Adversarial examples for network intrusion detection systems","author":"Sheatsley Ryan","year":"2022","unstructured":"Ryan Sheatsley, Nicolas Papernot, Michael J Weisman, Gunjan Verma, and Patrick McDaniel. 2022. Adversarial examples for network intrusion detection systems. Journal of Computer SecurityPreprint 30, 5 (2022), 727\u2013752.","journal-title":"Journal of Computer Security"},{"key":"e_1_3_1_50_2","doi-asserted-by":"publisher","DOI":"10.1109\/TETCI.2017.2772792"},{"key":"e_1_3_1_51_2","doi-asserted-by":"publisher","DOI":"10.1145\/3395352.3402618"},{"key":"e_1_3_1_52_2","unstructured":"Dug Song and Contributors. 2009. dpkt 1.9.2 Documentation. Retrieved from https:\/\/dpkt.readthedocs.io\/en\/latest\/. (2009). [Online; accessed 16-Feb-2023]."},{"key":"e_1_3_1_53_2","volume-title":"Reinforcement Learning: An Introduction","author":"Sutton Richard S.","year":"2018","unstructured":"Richard S. Sutton and Andrew G. Barto. 2018. Reinforcement Learning: An Introduction. MIT press."},{"key":"e_1_3_1_54_2","unstructured":"Christian Szegedy Wojciech Zaremba Ilya Sutskever Joan Bruna Dumitru Erhan Ian J. Goodfellow and Rob Fergus. 2014. Intriguing properties of neural networks. In 2nd International Conference on Learning Representations ICLR 2014 Banff AB Canada April 14-16 2014 Conference Track Proceedings Yoshua Bengio and Yann LeCun (Eds.). Retrieved from http:\/\/arxiv.org\/abs\/1312.6199"},{"key":"e_1_3_1_55_2","doi-asserted-by":"publisher","DOI":"10.1109\/IROS45743.2020.9340934"},{"key":"e_1_3_1_56_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v30i1.10295"},{"key":"e_1_3_1_57_2","doi-asserted-by":"publisher","DOI":"10.1109\/LRA.2020.2967289"},{"key":"e_1_3_1_58_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2854599"},{"key":"e_1_3_1_59_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2018.2825478"},{"key":"e_1_3_1_60_2","doi-asserted-by":"publisher","DOI":"10.1007\/s13042-019-00925-6"},{"key":"e_1_3_1_61_2","doi-asserted-by":"crossref","first-page":"27","DOI":"10.1145\/3411495.3421359","volume-title":"Proceedings of the 2020 ACM SIGSAC Conference on Cloud Computing Security Workshop","author":"Zhang Chaoyun","year":"2020","unstructured":"Chaoyun Zhang, Xavier Costa-P\u00e9rez, and Paul Patras. 2020. Tiki-taka: Attacking and defending deep learning-based intrusion detection systems. In Proceedings of the 2020 ACM SIGSAC Conference on Cloud Computing Security Workshop. 27\u201339."},{"key":"e_1_3_1_62_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2021.12.015"}],"container-title":["ACM Transactions on Privacy and Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3712307","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3712307","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T01:10:29Z","timestamp":1750295429000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3712307"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,2,22]]},"references-count":61,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2025,5,31]]}},"alternative-id":["10.1145\/3712307"],"URL":"https:\/\/doi.org\/10.1145\/3712307","relation":{},"ISSN":["2471-2566","2471-2574"],"issn-type":[{"value":"2471-2566","type":"print"},{"value":"2471-2574","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,2,22]]},"assertion":[{"value":"2023-03-27","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-01-04","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-02-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}