Abstract
As Network Intrusion Detection Systems (IDS) increasingly adopt unsupervised paradigms to detect zero-day threats, their vulnerability to adversarial evasion remains a critical security gap. We evaluate the robustness of three unsupervised models against a domain-restricted Masked FGSM attack, together with their inference latency. By enforcing categorical feature masks and discrete integer rounding, we craft protocol-valid adversarial samples. On UNSW-NB15 and CIC-IDS2017 all models prove susceptible, but the adversarially-learned latent space of the AnoGAN family can be more resilient than reconstruction-based Autoencoders; for the fast f-AnoGAN this advantage is strongly initialization-dependent, despite its inference time matching the Autoencoder, which was the most performant. These preliminary results suggest f-AnoGAN is a promising but unstable candidate for Network Intrusion Detection Systems and Next-Generation Firewalls.
Paper Type
Poster
DOI
10.62036/ISD.2026.41
Adversarial Resilience and Performance of Unsupervised Anomaly Detection Models: A Comparative Analysis Using Masked Fast Gradient Sign Method
As Network Intrusion Detection Systems (IDS) increasingly adopt unsupervised paradigms to detect zero-day threats, their vulnerability to adversarial evasion remains a critical security gap. We evaluate the robustness of three unsupervised models against a domain-restricted Masked FGSM attack, together with their inference latency. By enforcing categorical feature masks and discrete integer rounding, we craft protocol-valid adversarial samples. On UNSW-NB15 and CIC-IDS2017 all models prove susceptible, but the adversarially-learned latent space of the AnoGAN family can be more resilient than reconstruction-based Autoencoders; for the fast f-AnoGAN this advantage is strongly initialization-dependent, despite its inference time matching the Autoencoder, which was the most performant. These preliminary results suggest f-AnoGAN is a promising but unstable candidate for Network Intrusion Detection Systems and Next-Generation Firewalls.
Recommended Citation
Kowalski, J. & Nowak-Brzezińska, A.(2026). Adversarial Resilience and Performance of Unsupervised Anomaly Detection Models: A Comparative Analysis Using Masked Fast Gradient Sign Method. In M. Valenta, B. Mannová, R. Pergl, A. Przybylek, M. Lang, H. Linger, C. Schneider, N. Iivari, & E. Insfran (Eds.), Making ISD Sustainable: Reloaded with AI and Automation (ISD2026 Proceedings). Prague, Czech Republic: Czech Technical University in Prague. ISBN: 978-80-01-07585-2. https://doi.org/10.62036/ISD.2026.41