{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,8]],"date-time":"2026-07-08T05:02:32Z","timestamp":1783486952558,"version":"3.55.0"},"reference-count":54,"publisher":"MDPI AG","issue":"9","license":[{"start":{"date-parts":[[2021,9,14]],"date-time":"2021-09-14T00:00:00Z","timestamp":1631577600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/100010667","name":"H2020 Industrial Leadership","doi-asserted-by":"publisher","award":["957246"],"award-info":[{"award-number":["957246"]}],"id":[{"id":"10.13039\/100010667","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Information"],"abstract":"<jats:p>Recent technological innovations along with the vast amount of available data worldwide have led to the rise of cyberattacks against network systems. Intrusion Detection Systems (IDS) play a crucial role as a defense mechanism in networks against adversarial attackers. Machine Learning methods provide various cybersecurity tools. However, these methods require plenty of data to be trained efficiently, which may be hard to collect or to use due to privacy reasons. One of the most notable Machine Learning tools is the Generative Adversarial Network (GAN), and it has great potential for tabular data synthesis. In this work, we start by briefly presenting the most popular GAN architectures, VanillaGAN, WGAN, and WGAN-GP. Focusing on tabular data generation, CTGAN, CopulaGAN, and TableGAN models are used for the creation of synthetic IDS data. Specifically, the models are trained and evaluated on an NSL-KDD dataset, considering the limitations and requirements that this procedure needs. Finally, based on certain quantitative and qualitative methods, we argue and evaluate the most prominent GANs for tabular network data synthesis.<\/jats:p>","DOI":"10.3390\/info12090375","type":"journal-article","created":{"date-parts":[[2021,9,14]],"date-time":"2021-09-14T21:47:21Z","timestamp":1631656041000},"page":"375","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":139,"title":["A Review of Tabular Data Synthesis Using GANs on an IDS Dataset"],"prefix":"10.3390","volume":"12","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6122-4161","authenticated-orcid":false,"given":"Stavroula","family":"Bourou","sequence":"first","affiliation":[{"name":"Synelixis Solutions S.A., 34100 Chalkida, Greece"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Andreas","family":"El Saer","sequence":"additional","affiliation":[{"name":"Synelixis Solutions S.A., 34100 Chalkida, Greece"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0362-4607","authenticated-orcid":false,"given":"Terpsichori-Helen","family":"Velivassaki","sequence":"additional","affiliation":[{"name":"Synelixis Solutions S.A., 34100 Chalkida, Greece"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7580-3938","authenticated-orcid":false,"given":"Artemis","family":"Voulkidis","sequence":"additional","affiliation":[{"name":"Synelixis Solutions S.A., 34100 Chalkida, Greece"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Theodore","family":"Zahariadis","sequence":"additional","affiliation":[{"name":"Synelixis Solutions S.A., 34100 Chalkida, Greece"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2021,9,14]]},"reference":[{"key":"ref_1","unstructured":"James, P. (1980). Computer security threat monitoring and surveillance. Technical Report, Anderson Company, Fort. Technical Report 98-17."},{"key":"ref_2","first-page":"2828","article-title":"Decision tree based algorithm for intrusion detection","volume":"7","author":"Rai","year":"2016","journal-title":"Int. J. Adv. Netw. Appl."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Li, Z., Qin, Z., Huang, K., Yang, X., and Ye, S. (2017, January 14\u201318). Intrusion detection using convolutional neural networks for representation learning. Proceedings of the International Conference on Neural Information Processing, Guangzhou, China.","DOI":"10.1007\/978-3-319-70139-4_87"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"108","DOI":"10.1109\/JAS.2017.7510730","article-title":"SVM-DT-based adaptive and collaborative intrusion detection","volume":"5","author":"Teng","year":"2018","journal-title":"IEEE\/CAA J. Autom. Sin."},{"key":"ref_5","unstructured":"Bringas, P.G., and Grueiro, I.S. (2021, September 10). Bayesian Networks for Network Intrusion Detection. Available online: https:\/\/intechopen.com\/books\/bayesian-network\/bayesian-networks-for-network-intrusion-detection."},{"key":"ref_6","first-page":"1423","article-title":"PrivBayes: Private data release via bayesian networks","volume":"42","author":"Zhang","year":"2014","journal-title":"Acm Trans. Database Syst."},{"key":"ref_7","unstructured":"Avi\u00f1\u00f3, L., Ruffini, M., and Gavald\u00e0, R. (2018). Generating Synthetic but Plausible Healthcare Record Datasets. arXiv."},{"key":"ref_8","first-page":"29","article-title":"A nonparametric method to generate synthetic populations to adjust for complex sampling design features","volume":"40","author":"Dong","year":"2014","journal-title":"Surv. Methodol."},{"key":"ref_9","unstructured":"Oliva, J.B., Dubey, A., Wilson, A.G., P\u00f3czos, B., Schneider, J., and Xing, E.P. (2016, January 9\u201311). Bayesian nonparametric kernel-learning. Proceedings of the Artificial Intelligence and Statistics, Cadiz, Spain."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"1","DOI":"10.18637\/jss.v074.i11","article-title":"synthpop: Bespoke creation of synthetic data in R","volume":"74","author":"Nowok","year":"2016","journal-title":"J. Stat. Softw."},{"key":"ref_11","first-page":"441","article-title":"Using CART to generate partially synthetic public use microdata","volume":"21","author":"Reiter","year":"2005","journal-title":"J. Off. Stat."},{"key":"ref_12","unstructured":"Goodfellow, I., Pouget-Abadie, J., Mirza, M., Xu, B., Warde-Farley, D., Ozair, S., Courville, A., and Bengio, Y. (2021, September 10). Generative Adversarial Nets. Available online: https:\/\/papers.nips.cc\/paper\/5423-generative-adversarial-nets.pdf."},{"key":"ref_13","unstructured":"Arjovsky, M., Chintala, S., and Bottou, L. (2017, January 6\u201311). Wasserstein generative adversarial networks. Proceedings of the International conference on machine learning, Sydney, Australia."},{"key":"ref_14","unstructured":"Gulrajani, I., Ahmed, F., Arjovsky, M., Dumoulin, V., and Courville, A. (2021, September 10). Improved training of wasserstein GANs. Available online: http:\/\/papers.nips.cc\/paper\/7159-improved-training-of-wasserstein-gans.pdf."},{"key":"ref_15","unstructured":"Radford, A., Metz, L., and Chintala, S. (2015). Unsupervised representation learning with deep convolutional generative adversarial networks. arXiv."},{"key":"ref_16","unstructured":"Denton, E., Chintala, S., Szlam, A., and Fergus, R. (2015). Deep generative image models using a Laplacian pyramid of adversarial networks. arXiv."},{"key":"ref_17","unstructured":"Karras, T., Aila, T., Laine, S., and Lehtinen, J. (2017). Progressive growing of gans for improved quality, stability, and variation. arXiv."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Liu, S., Wang, T., Bau, D., Zhu, J.-Y., and Torralba, A. (2020, January 13\u201319). Diverse image generation via self-conditioned gans. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Seattle, WA, USA.","DOI":"10.1109\/CVPR42600.2020.01429"},{"key":"ref_19","unstructured":"Lin, Z., Shi, Y., and Xue, Z. (2018). Idsgan: Generative adversarial networks for attack generation against intrusion detection. arXiv."},{"key":"ref_20","unstructured":"Charlier, J., Singh, A., Ormazabal, G., State, R., and Schulzrinne, H. (2019). SynGAN: Towards generating synthetic network attacks using GANs. arXiv."},{"key":"ref_21","unstructured":"Hu, W., and Tan, Y. (2017). Generating adversarial malware examples for black-box attacks based on GAN. arXiv."},{"key":"ref_22","unstructured":"Xu, L., and Veeramachaneni, K. (2018). Synthesizing Tabular Data using Generative Adversarial Networks. arXiv."},{"key":"ref_23","unstructured":"Xu, L., Skoularidou, M., Infante, A.C., and Veeramachaneni, K. (2021, September 10). Modeling Tabular Data Using Conditional GAN. Available online: https:\/\/nips.cc\/conferences\/2019\/acceptedpapersinitial."},{"key":"ref_24","unstructured":"Zhao, Z., Kunar, A., van der Scheer, H., Birke, R., and Chen, L.Y. (2021). CTAB-GAN: Effective Table Data Synthesizing. arXiv."},{"key":"ref_25","unstructured":"Mottini, A., Lheritier, A., and Acuna-Agost, R. (2018). Airline passenger name record generation using generative adversarial networks. arXiv."},{"key":"ref_26","unstructured":"Yahi, A., Vanguri, R., Elhadad, N., and Tatonetti, N.P. (2017). Generative adversarial networks for electronic health records: A framework for exploring and evaluating methods for predicting drug-induced laboratory test trajectories. arXiv."},{"key":"ref_27","unstructured":"Choi, E., Biswal, S., Malin, B., Duke, J., Stewart, W.F., and Sun, J. (2017, January 18\u201319). Generating multi-label discrete patient records using generative adversarial networks. Proceedings of the Machine Learning for Healthcare Conference, Boston, MA, USA."},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Park, N., Mohammadi, M., Gorde, K., Jajodia, S., Park, H., and Kim, Y. (2018). Data synthesis based on generative adversarial networks. arXiv.","DOI":"10.14778\/3231751.3231757"},{"key":"ref_29","unstructured":"(2021, July 15). CopulaGAN Model. Available online: https:\/\/sdv.dev\/SDV\/user_guides\/single_table\/copulagan.html."},{"key":"ref_30","unstructured":"(2021, July 15). SDV\u2014The Synthetic Data Vault. Available online: https:\/\/sdv.dev\/SDV\/user_guides\/benchmarking\/synthesizers.html."},{"key":"ref_31","unstructured":"Patki, N. (2021, September 10). The Synthetic Data Vault: Generative Modeling for Relational Databases. Available online: https:\/\/dspace.mit.edu\/handle\/1721.1\/109616."},{"key":"ref_32","unstructured":"(2021, July 15). NSL-KDD Dataset. Available online: https:\/\/www.unb.ca\/cic\/datasets\/index.html."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"29575","DOI":"10.1109\/ACCESS.2020.2972627","article-title":"BAT: Deep learning methods on network intrusion detection using NSL-KDD dataset","volume":"8","author":"Su","year":"2020","journal-title":"IEEE Access"},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Moustafa, N., and Slay, J. (2018, January 3\u20135). A network forensic scheme using correntropy-variation for attack detection. Proceedings of the IFIP International Conference on Digital Forensics, New Delhi, India.","DOI":"10.1007\/978-3-319-99277-8_13"},{"key":"ref_35","first-page":"148","article-title":"Distributed privacy-preserving collaborative intrusion detection systems for VANETs","volume":"4","author":"Zhang","year":"2018","journal-title":"IEEE Trans. Signal Inf. Process. Netw."},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Xevgenis, M., Kogias, D.G., Karkazis, P., Leligou, H.C., and Patrikakis, C. (2020). Application of Blockchain Technology in Dynamic Resource Management of Next Generation Networks. Information, 11.","DOI":"10.3390\/info11120570"},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Short, R., Leligou, H.C., and Theocharis, E. (2021, January 10\u201312). Execution of a Federated Learning process within a smart contract. Proceedings of the 2021 IEEE International Conference on Consumer Electronics (ICCE), Las Vegas, NV, USA.","DOI":"10.1109\/ICCE50685.2021.9427734"},{"key":"ref_38","unstructured":"Svens\u00e9n, M., and Bishop, C.M. (2007). Pattern Recognition and Machine Learning, Springer."},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Borji, A. (2021). Pros and Cons of GAN Evaluation Measures: New Developments. arXiv.","DOI":"10.1016\/j.cviu.2021.103329"},{"key":"ref_40","unstructured":"Theis, L., Oord, A.V.d., and Bethge, M. (2015). A note on the evaluation of generative models. arXiv."},{"key":"ref_41","first-page":"2234","article-title":"Improved techniques for training gans","volume":"29","author":"Salimans","year":"2016","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref_42","first-page":"6629","article-title":"Gans trained by a two time-scale update rule converge to a local nash equilibrium","volume":"30","author":"Heusel","year":"2017","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Karras, T., Laine, S., and Aila, T. (2019, January 15\u201320). A style-based generator architecture for generative adversarial networks. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Long Beach, CA, USA.","DOI":"10.1109\/CVPR.2019.00453"},{"key":"ref_44","unstructured":"(2021, May 11). KDD Cup 1999 Data. Available online: http:\/\/kdd.ics.uci.edu\/databases\/kddcup99\/kddcup99.html."},{"key":"ref_45","first-page":"446","article-title":"A study on NSL-KDD dataset for intrusion detection system based on classification algorithms","volume":"4","author":"Dhanabal","year":"2015","journal-title":"Int. J. Adv. Res. Comput. Commun. Eng."},{"key":"ref_46","doi-asserted-by":"crossref","first-page":"1561","DOI":"10.1016\/j.procs.2020.03.367","article-title":"Analysis of KDD-Cup\u201999, NSL-KDD and UNSW-NB15 datasets using deep learning in IoT","volume":"167","author":"Choudhary","year":"2020","journal-title":"Procedia Comput. Sci."},{"key":"ref_47","doi-asserted-by":"crossref","first-page":"147","DOI":"10.1016\/j.cose.2019.06.005","article-title":"A survey of network-based intrusion detection data sets","volume":"86","author":"Ring","year":"2019","journal-title":"Comput. Secur."},{"key":"ref_48","doi-asserted-by":"crossref","first-page":"115","DOI":"10.1145\/1132026.1132027","article-title":"Inferring internet denial-of-service activity","volume":"24","author":"Moore","year":"2006","journal-title":"ACM Trans. Comput. Syst."},{"key":"ref_49","doi-asserted-by":"crossref","unstructured":"Khamphakdee, N., Benjamas, N., and Saiyod, S. (2014, January 28\u201330). Improving intrusion detection system based on snort rules for network probe attack detection. Proceedings of the 2014 2nd International Conference on Information and Communication Technology, Bandung, Indonesia.","DOI":"10.1109\/ICoICT.2014.6914042"},{"key":"ref_50","first-page":"204","article-title":"Denial-of-service, probing, user to root (U2R) & remote to user (R2L) attack detection using hidden Markov models","volume":"7","author":"Alharbi","year":"2018","journal-title":"Int. J. Comput. Inf. Technol."},{"key":"ref_51","first-page":"57","article-title":"Denial-of-service, probing & remote to user (R2L) attack detection using genetic algorithm","volume":"60","author":"Paliwal","year":"2012","journal-title":"Int. J. Comput. Appl."},{"key":"ref_52","doi-asserted-by":"crossref","first-page":"227","DOI":"10.1145\/382912.382914","article-title":"A framework for constructing features and models for intrusion detection systems","volume":"3","author":"Lee","year":"2000","journal-title":"ACM Trans. Inf. Syst. Secur."},{"key":"ref_53","unstructured":"(2021, July 25). Table Evaluator. Available online: https:\/\/baukebrenninkmeijer.github.io\/table-evaluator\/."},{"key":"ref_54","unstructured":"(2021, July 25). Synthetic Data Evaluation-Single Table Metrics. Available online: https:\/\/sdv.dev\/SDV\/user_guides\/evaluation\/single_table_metrics.html."}],"container-title":["Information"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2078-2489\/12\/9\/375\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T07:02:36Z","timestamp":1760166156000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2078-2489\/12\/9\/375"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,9,14]]},"references-count":54,"journal-issue":{"issue":"9","published-online":{"date-parts":[[2021,9]]}},"alternative-id":["info12090375"],"URL":"https:\/\/doi.org\/10.3390\/info12090375","relation":{},"ISSN":["2078-2489"],"issn-type":[{"value":"2078-2489","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,9,14]]}}}