{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T14:11:59Z","timestamp":1784297519993,"version":"3.55.0"},"reference-count":29,"publisher":"MDPI AG","issue":"5","license":[{"start":{"date-parts":[[2025,5,13]],"date-time":"2025-05-13T00:00:00Z","timestamp":1747094400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Future Internet"],"abstract":"<jats:p>Network Intrusion Detection Systems (NIDS) often suffer from severe class imbalance, where minority attack types are underrepresented, leading to degraded detection performance. To address this challenge, we propose a novel augmentation framework that integrates Soft Nearest Neighbor Loss (SNNL) into Generative Adversarial Networks (GANs), including WGAN, CWGAN, and WGAN-GP. Unlike traditional oversampling methods (e.g., SMOTE, ADASYN), our approach improves feature-space alignment between real and synthetic samples, enhancing classifier generalization on rare classes. Experiments on NSL-KDD, CSE-CIC-IDS2017, and CSE-CIC-IDS2018 show that SNNL-augmented GANs consistently improve minority-class F1-scores without degrading overall accuracy or majority-class performance. UMAP visualizations confirm that SNNL produces more compact and class-consistent sample distributions. We also evaluate the computational overhead, finding the added cost moderate. These results demonstrate the effectiveness and practicality of SNNL as a general enhancement for GAN-based data augmentation in imbalanced NIDS tasks.<\/jats:p>","DOI":"10.3390\/fi17050216","type":"journal-article","created":{"date-parts":[[2025,5,13]],"date-time":"2025-05-13T09:26:48Z","timestamp":1747128408000},"page":"216","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":11,"title":["Mitigating Class Imbalance in Network Intrusion Detection with Feature-Regularized GANs"],"prefix":"10.3390","volume":"17","author":[{"ORCID":"https:\/\/orcid.org\/0009-0008-9976-1753","authenticated-orcid":false,"given":"Jing","family":"Li","sequence":"first","affiliation":[{"name":"Institute of Cybersecurity and Cryptology, School of Computing and Information Technology, University of Wollongong, Wollongong, NSW 2522, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9714-6759","authenticated-orcid":false,"given":"Wei","family":"Zong","sequence":"additional","affiliation":[{"name":"Institute of Cybersecurity and Cryptology, School of Computing and Information Technology, University of Wollongong, Wollongong, NSW 2522, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3348-7014","authenticated-orcid":false,"given":"Yang-Wai","family":"Chow","sequence":"additional","affiliation":[{"name":"Institute of Cybersecurity and Cryptology, School of Computing and Information Technology, University of Wollongong, Wollongong, NSW 2522, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1562-5105","authenticated-orcid":false,"given":"Willy","family":"Susilo","sequence":"additional","affiliation":[{"name":"Institute of Cybersecurity and Cryptology, School of Computing and Information Technology, University of Wollongong, Wollongong, NSW 2522, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2025,5,13]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Zong, W., Chow, Y.-W., and Susilo, W. (2018, January 3\u20135). A 3D Approach for the Visualization of Network Intrusion Detection Data. Proceedings of the 2018 International Conference on Cyberworlds (CW), Singapore.","DOI":"10.1109\/CW.2018.00064"},{"key":"ref_2","first-page":"197","article-title":"A Two-Stage Classifier Approach for Network Intrusion Detection","volume":"Volume 11125","author":"Su","year":"2018","journal-title":"Information Security Practice and Experience, Proceedings of the 14th International Conference, ISPEC 2018, Tokyo, Japan, 25\u201327 September 2018"},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"121","DOI":"10.1007\/s00779-019-01332-y","article-title":"GAN-Based Imbalanced Data Intrusion Detection System","volume":"25","author":"Lee","year":"2021","journal-title":"Pers. Ubiquitous Comput."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"2596","DOI":"10.1007\/s11036-022-02075-6","article-title":"A GAN-Based Intrusion Detection Model for 5G Enabled Future Metaverse","volume":"27","author":"Ding","year":"2022","journal-title":"Mob. Netw. Appl."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Liao, D., Huang, S., Tan, Y., and Bai, G. (2020, January 21\u201323). Network Intrusion Detection Method Based on GAN Model. Proceedings of the 2020 International Conference on Computer Communication and Network Security (CCNS), Xi\u2019an, China.","DOI":"10.1109\/CCNS50731.2020.00041"},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"4951","DOI":"10.1109\/TNSM.2023.3260039","article-title":"Unsupervised GAN-Based Intrusion Detection System Using Temporal Convolutional Networks and Self-Attention","volume":"20","author":"Naili","year":"2023","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"ref_7","first-page":"9947059","article-title":"A GAN and Feature Selection-Based Oversampling Technique for Intrusion Detection","volume":"2021","author":"Liu","year":"2021","journal-title":"Secur. Commun. Netw."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"122198","DOI":"10.1016\/j.eswa.2023.122198","article-title":"HDA-IDS: A Hybrid DoS Attacks Intrusion Detection System for IoT by Using Semi-Supervised CL-GAN","volume":"238","author":"Li","year":"2024","journal-title":"Expert Syst. Appl."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"e4815","DOI":"10.1002\/ett.4815","article-title":"Intrusion Detection System Using Distributed Multilevel Discriminator in GAN for IoT System","volume":"34","author":"Poongodi","year":"2023","journal-title":"Trans. Emerg. Telecommun. Technol."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"101212","DOI":"10.1016\/j.iot.2024.101212","article-title":"SYN-GAN: A Robust Intrusion Detection System Using GAN-Based Synthetic Data for IoT Security","volume":"26","author":"Rahman","year":"2024","journal-title":"Internet Things"},{"key":"ref_11","first-page":"507","article-title":"A Method for Network Intrusion Detection Based on GAN-CNN-BiLSTM","volume":"14","author":"Li","year":"2023","journal-title":"Int. J. Adv. Comput. Sci. Appl."},{"key":"ref_12","unstructured":"Sophia, N.A., Sivasai, A.S.V., and Sachin, S. (2024, January 2\u20133). Intrusion Detection System Using Generative Adversarial Network (GAN). Proceedings of the 2024 2nd International Conference on Advancement in Computation & Computer Technologies (InCACCT), Gharuan, India."},{"key":"ref_13","unstructured":"Chen, H., and Jiang, L. (2019). Efficient GAN-Based Method for Cyber-Intrusion Detection. arXiv."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Xu, W., Jang-Jaccard, J., Liu, T., Sabrina, F., and Kwak, J. (2022). Improved Bidirectional GAN-Based Approach for Network Intrusion Detection Using One-Class Classifier. Computers, 11.","DOI":"10.3390\/computers11060085"},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"1156","DOI":"10.1109\/TIFS.2023.3331240","article-title":"TMG-GAN: Generative Adversarial Networks-Based Imbalanced Learning for Network Intrusion Detection","volume":"19","author":"Ding","year":"2024","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"105805","DOI":"10.1016\/j.engappai.2022.105805","article-title":"GAN-AE: An Unsupervised Intrusion Detection System for MQTT Networks","volume":"119","author":"Boppana","year":"2023","journal-title":"Eng. Appl. Artif. Intell."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Peng, Y., Fu, G., Luo, Y., Hu, J., Li, B., Yan, Q., and Wenzheng, L. (2020, January 16\u201318). Detecting Adversarial Examples for Network Intrusion Detection System with GAN. Proceedings of the 2020 IEEE 11th International Conference on Software Engineering and Service Science (ICSESS), Beijing, China.","DOI":"10.1109\/ICSESS49938.2020.9237728"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Ahmad, R., Li, L.H., Sharma, A.K., and Tanone, R. (2023, January 3\u20135). Boundary-Seeking GAN Approach to Improve Classification of Intrusion Detection Systems Based on Machine Learning Model. Proceedings of the 2023 17th International Conference on Ubiquitous Information Management and Communication (IMCOM), Seoul, Republic of Korea.","DOI":"10.1109\/IMCOM56909.2023.10035580"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Feng, J., Wang, C., Xue, H., and Zhang, L. (2024, January 10\u201312). Efficient Anomaly Intrusion Detection Using Transformer-Based GAN Network. Proceedings of the 2024 IEEE 7th International Electrical and Energy Conference (CIEEC), Harbin, China.","DOI":"10.1109\/CIEEC60922.2024.10583331"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Bai, G., Ishikawa, F., Ait-Ameur, Y., and Papadopoulos, G.A. (2025). SC-WGAN: GAN-Based Oversampling Method for Network Intrusion Detection. Engineering of Complex Computer Systems, Springer.","DOI":"10.1007\/978-3-031-66456-4_2"},{"key":"ref_21","first-page":"127564T","article-title":"GAN-Based Intrusion Detection Model Using MLP Encoder","volume":"Volume 12756","author":"Zhang","year":"2023","journal-title":"Proceedings of SPIE\u2014The International Society for Optical Engineering"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Strickland, C., Zakar, M., Saha, C., Soltani Nejad, S., Tasnim, N., Lizotte, D.J., and Haque, A. (2024). DRL-GAN: A Hybrid Approach for Binary and Multiclass Network Intrusion Detection. Sensors, 24.","DOI":"10.3390\/s24092746"},{"key":"ref_23","unstructured":"Frosst, N., Papernot, N., and Hinton, G. (2019). Analyzing and Improving Representations with the Soft Nearest Neighbor Loss. arXiv."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Schroff, F., Kalenichenko, D., and Philbin, J. (2015, January 7\u201312). FaceNet: A Unified Embedding for Face Recognition and Clustering. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR), Boston, MA, USA.","DOI":"10.1109\/CVPR.2015.7298682"},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Leibe, B., Matas, J., Sebe, N., and Welling, M. (2016). A Discriminative Feature Learning Approach for Deep Face Recognition. Computer Vision\u2013ECCV 2016, Springer.","DOI":"10.1007\/978-3-319-46454-1"},{"key":"ref_26","unstructured":"Hermans, A., Beyer, L., and Leibe, B. (2017). In Defense of the Triplet Loss for Person Re-Identification. arXiv."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Tavallaee, M., Bagheri, E., Lu, W., and Ghorbani, A. (2009, January 8\u201310). A Detailed Analysis of the KDD CUP 99 Data Set. Proceedings of the 2nd IEEE Symposium on Computational Intelligence for Security and Defense Applications (CISDA), Ottawa, ON, Canada.","DOI":"10.1109\/CISDA.2009.5356528"},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Sharafaldin, I., Lashkari, A.H., and Ghorbani, A.A. (2018). Toward Generating a New Intrusion Detection Dataset and Intrusion Traffic Characterization. Proceedings of the 4th International Conference on Information Systems Security and Privacy (ICISSP), SCITEPRESS.","DOI":"10.5220\/0006639801080116"},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"292","DOI":"10.1016\/j.future.2019.07.045","article-title":"Interactive Three-Dimensional Visualization of Network Intrusion Detection Data for Machine Learning","volume":"102","author":"Zong","year":"2020","journal-title":"Future Gener. Comput. Syst."}],"container-title":["Future Internet"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-5903\/17\/5\/216\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T17:32:00Z","timestamp":1760031120000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-5903\/17\/5\/216"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,5,13]]},"references-count":29,"journal-issue":{"issue":"5","published-online":{"date-parts":[[2025,5]]}},"alternative-id":["fi17050216"],"URL":"https:\/\/doi.org\/10.3390\/fi17050216","relation":{},"ISSN":["1999-5903"],"issn-type":[{"value":"1999-5903","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,5,13]]}}}