Hybrid Adversarial Retraining Approach for a Proactive Network Intrusion Detection System

Noora Al Roken, Hakim Hacid, Ahmed Bouridane, Abir Jaafar Hussain · IEEE Open Journal of the Communications Society · 2026

Artificial intelligence provides benefits across many areas, including network security. It also enables novel attacks and new security risks. However, AI-generated attacks now outpace the capabilities of current defense systems. Therefore, it is crucial to implement proactive security measures to identify unknown threats and protect digital systems. Existing research is limited by small or outdated datasets, data from virtual machines, inefficient or complex behavior-based methods, and reliance on a single adversarial condition. To address this, our study developed a new attack-detection framework. We used a proactive approach with a hybrid retraining technique that integrates both black- and white-box attacks. The framework combines two different attack concealment methods with a two-stage classification method to enhance detection accuracy and reduce false negatives. We joined two large network attack datasets, CICIDS2017 and CSE-CIC-IDS2018, to train and test the framework. Experiments show that our intrusion detection system achieved high detection rates. The two-layer convolutional neural network, using our all-attacks adversarial retraining method, demonstrated superior generalization across 12 adversarial attack algorithms, achieving an overall accuracy of 89%. This finding shows that simpler models can still provide robust protection with our hybrid retraining approach. Our method improved accuracy by up to 7.02% on CICIDS2017 and 3.7% on CSE-CIC-IDS2018. These results demonstrate that our method provides a practical and reliable defense against real-world network security threats.

Read the paper · More papers on PaperTik