White-Box Adversarial Exploitation of NIDS: Insights from FGSM, PGD, and C&W
Uliya Ashfaque Ali, Krish Dogra, Seema Sharma · 2025
Network Intrusion Detection Systems (NIDS) help in detecting harmful activities and malicious activities by keeping an eye on network traffic or system for malignant activity. However, studies have found that Network Intrusion Detection Systems (NIDS) can be tricked by making tiny often invisible changes to the input data known as adversarial attacks to confuse machine learning models and cause them to make wrong decisions. This paper explores how different types of adversarial attacks affect NIDS models, focusing on techniques like Fast Gradient sign Method (FGSM), Projected Gradient Descent (PGD), and the Carlini and Wagner (C&W) attack. This work contributes by assessing how these adversarial attacks affect the NIDS model by analyzing three key metrics: precision, recall, and F1 score. These metrics were analyzed to evaluate how successful the adversarial attacks were and how they affected the performance of the NIDS. Experimental results demonstrate that these adversarial attacks significantly degrade the performance of NIDS, particularly in terms of precision and overall detection capability. FGSM was able to reduce the accuracy of NIDS from 73.01% to 53.92% as epsilon (ϵ) value increased from 0.1 to 0.5, while PGD was able to reduce it to 19.63%. The C&W attack, with the confidence parameter set to 1, resulted in 55.20% accuracy, highlighting the model's vulnerability to adversarial attacks. This research highlights the vulnerabilities of NIDS to adversarial attacks and provides a detailed analysis of the challenges posed by such threats in cybersecurity, emphasizing the need for advanced mitigation techniques to address them.