Game-Theoretic Cost-Sensitive Adversarial Training for Robust Cloud Intrusion Detection Against GAN-Based Evasion Attacks
Abstract
1. Introduction
- We propose GT-CSAT, a unified adversarial training framework in which an improved, attack-conditioned WGAN-GP threat generator co-evolves with the IDS detector under a minimax training protocol.
- We derive a game-theoretic cost-sensitive loss function (GTCS-Loss) rooted in a two-player zero-sum payoff formulation, whose misclassification cost weights are updated via a Nash equilibrium-inspired online adaptation rule during training.
- We conduct extensive experiments on the Cloud Vulnerabilities Dataset (CVD), CICIDS-2017 [24], and UNSW-NB15 [25], evaluating six evasion attack strategies across five detector baselines, demonstrating that GT-CSAT achieves a superior robustness–accuracy profile without sacrificing detection of conventional attacks.
- We release all code and experimental configurations to support reproducibility and future research.
2. Related Works
2.1. Machine Learning-Based Intrusion Detection
2.2. Adversarial Attacks on IDSs
2.3. Generative Adversarial Networks for Security
2.4. Adversarial Training and Robustness
2.5. Game Theory in Cybersecurity
2.6. Cost-Sensitive Learning
3. Preliminaries
3.1. Problem Formulation
3.2. Wasserstein GAN with Gradient Penalty (WGAN-GP)
3.3. Game-Theoretic Foundations
4. Methodology
4.1. Attack-Conditioned WGAN-GP Threat Generator
4.1.1. Architecture
4.1.2. Semantic Constraint Projection
4.1.3. Evasion-Guided Generator Update
4.2. Deep Residual IDS Detector
4.3. Game-Theoretic Cost-Sensitive Loss Function (GTCS-Loss)
4.3.1. Payoff Matrix Formulation
4.3.2. Cost-Sensitive Cross-Entropy
4.3.3. Nash Equilibrium-Inspired Cost Adaptation
4.3.4. Full Training Objective
4.4. Training Algorithm
| Algorithm 1 GT-CSAT Training Procedure |
|
5. Experiments
5.1. Dataset
5.2. Baselines
- Standard—the deep residual detector trained without any adversarial augmentation.
- AT-PGD—adversarial training [8] using PGD-10 perturbations (, ) as the sole augmentation source.
- TRADES—the TRADES objective [14] applied to the same detector architecture, with the boundary regularization weight .
- IDSGAN-AT—adversarial training augmented with samples from a separately pre-trained IDSGAN generator [10] (fixed generator, no co-training).
- Focal-AT—adversarial training with focal loss [61] () as a cost-sensitive baseline that uses static cost weighting.
5.3. Evaluation Metrics
- Clean Accuracy (CA): per-class macro-averaged accuracy on unperturbed test records.
- Robust Accuracy (RA): macro-averaged accuracy on adversarially perturbed test records under each attack strategy.
- False Negative Rate (FNR): the fraction of true attack records classified as benign.
- False Positive Rate (FPR): the fraction of benign records classified as attacks.
- F1 Score: macro-averaged across all five classes, on both clean and adversarial test sets.
- Robustness–Accuracy Gap (RAG): defined as , quantifying the accuracy penalty incurred by robustness; lower RAG is preferred.
- Attack Success Rate (ASR): the fraction of attack records that the evasion strategy successfully causes to be classified as benign.
5.4. Experimental Setup
5.4.1. Attack Configurations
5.4.2. Hyperparameter Settings
5.4.3. Hardware
5.4.4. Reproducibility
5.5. Main Results
5.5.1. Clean Accuracy and Overall Robustness
5.5.2. Per-Attack Robust Accuracy Breakdown
5.5.3. Per-Class Performance Under IDSGAN-BB
5.5.4. Cost Weight Trajectory
5.5.5. Robustness–Accuracy Trade-Off Curve
5.5.6. Ablation Study
5.5.7. Sensitivity Analysis
5.5.8. Computational Overhead
5.5.9. Discussion
5.6. Cross-Dataset Generalization
6. Conclusions and Future Works
6.1. Limitations
6.2. Future Directions
Author Contributions
Funding
Data Availability Statement
Conflicts of Interest
References
- Botta, A.; de Donato, W.; Persico, V.; Pescapé, A. Integration of cloud computing and internet of things: A survey. Future Gener. Comput. Syst. 2016, 56, 684–700. [Google Scholar] [CrossRef]
- Mell, P.; Grance, T. The NIST Definition of Cloud Computing; NIST Special Publication 800-145; National Institute of Standards and Technology: Gaithersburg, MD, USA, 2011. [Google Scholar]
- Zhang, S.; Qiu, L.; Zhang, H. Edge cloud synergy models for ultra-low latency data processing in smart city IoT networks. Int. J. Sci. 2025, 12. [Google Scholar]
- IBM Security. Cost of a Data Breach Report 2023; IBM Corporation: Armonk, NY, USA, 2023; Available online: https://www.ibm.com/reports/data-breach (accessed on 1 February 2025).
- Liao, H.-J.; Lin, C.-H.R.; Lin, Y.-C.; Tung, K.-Y. Intrusion detection system: A comprehensive review. J. Netw. Comput. Appl. 2013, 36, 16–24. [Google Scholar] [CrossRef]
- Buczak, A.L.; Guven, E. A survey of data mining and machine learning methods for cyber security intrusion detection. IEEE Commun. Surv. Tutor. 2016, 18, 1153–1176. [Google Scholar] [CrossRef]
- Goodfellow, I.J.; Shlens, J.; Szegedy, C. Explaining and harnessing adversarial examples. In Proceedings of the International Conference on Learning Representations (ICLR), San Diego, CA, USA, 7–9 May 2015. [Google Scholar]
- Madry, A.; Makelov, A.; Schmidt, L.; Tsipras, D.; Vladu, A. Towards deep learning models resistant to adversarial attacks. In Proceedings of the International Conference on Learning Representations (ICLR), Vancouver, BC, Canada, 30 April–3 May 2018. [Google Scholar]
- Carlini, N.; Wagner, D. Towards evaluating the robustness of neural networks. In Proceedings of the 2017 IEEE Symposium on Security and Privacy (S&P), San Jose, CA, USA, 22–26 May 2017; IEEE: New York, NY, USA, 2017; pp. 39–57. [Google Scholar] [CrossRef]
- Lin, Z.; Shi, Y.; Xue, Z. IDSGAN: Generative adversarial networks for attack generation against intrusion detection systems. In Proceedings of the Pacific-Asia Conference on Knowledge Discovery and Data Mining (PAKDD), Macau, China, 14–17 June 2022; Springer: Cham, Switzerland, 2022; pp. 79–91. [Google Scholar] [CrossRef]
- Apruzzese, G.; Colajanni, M.; Ferretti, L.; Marchetti, M. Modeling realistic adversarial attacks against network intrusion detection systems. Digit. Threat. Res. Pract. 2022, 3, 31. [Google Scholar] [CrossRef]
- Arjovsky, M.; Chintala, S.; Bottou, L. Wasserstein generative adversarial networks. In Proceedings of the 34th International Conference on Machine Learning (ICML), Sydney, Australia, 6–11 August 2017; Proceedings of Machine Learning Research; PMLR: Sydney, Australia, 2017; Volume 70, pp. 214–223. [Google Scholar]
- Gulrajani, I.; Ahmed, F.; Arjovsky, M.; Dumoulin, V.; Courville, A. Improved training of Wasserstein GANs. In Advances in Neural Information Processing Systems 30 (NeurIPS 2017), Long Beach, CA, USA, 4–9 December 2017; Curran Associates, Inc.: Red Hook, NY, USA, 2017; pp. 5767–5777. [Google Scholar]
- Zhang, H.; Yu, Y.; Jiao, J.; Xing, E.; El Ghaoui, L.; Jordan, M. Theoretically principled trade-off between robustness and accuracy. In Proceedings of the 36th International Conference on Machine Learning (ICML), Long Beach, CA, USA, 9–15 June 2019; PMLR: Long Beach, CA, USA, 2019; pp. 7472–7482. [Google Scholar]
- Tramèr, F.; Boneh, D. Adversarial training and robustness for multiple perturbations. In Advances in Neural Information Processing Systems 32 (NeurIPS 2019), Vancouver, BC, Canada, 8–14 December 2019; Curran Associates, Inc.: Red Hook, NY, USA, 2019; pp. 5858–5868. [Google Scholar]
- Croce, F.; Andriushchenko, M.; Sehwag, V.; Debenedetti, E.; Flammarion, N.; Chiang, M.; Mittal, P.; Hein, M. RobustBench: A standardized adversarial robustness benchmark. In Advances in Neural Information Processing Systems 34 (NeurIPS 2021 Datasets and Benchmarks Track), Virtual, 6–14 December 2021; Curran Associates, Inc.: Red Hook, NY, USA, 2021. [Google Scholar]
- Raghunathan, A.; Xie, S.M.; Yang, F.; Duchi, J.; Liang, P. Understanding and mitigating the tradeoff between robustness and accuracy. In Proceedings of the 37th International Conference on Machine Learning (ICML), Virtual, 13–18 July 2020; PMLR: Virtual, 2020; pp. 7909–7919. [Google Scholar]
- Tramèr, F.; Kurakin, A.; Papernot, N.; Goodfellow, I.; Boneh, D.; McDaniel, P. Ensemble adversarial training: Attacks and defenses. In Proceedings of the International Conference on Learning Representations (ICLR), Vancouver, BC, Canada, 30 April–3 May 2018. [Google Scholar]
- Kariyappa, S.; Qureshi, M.K. Improving adversarial robustness of ensembles with diversity training. arXiv 2019, arXiv:1901.09981. [Google Scholar] [CrossRef]
- Guo, C.; Rana, M.; Cisse, M.; Van Der Maaten, L. Countering adversarial images using input transformations. In Proceedings of the International Conference on Learning Representations (ICLR), Vancouver, BC, Canada, 30 April–3 May 2018. [Google Scholar]
- Cohen, J.; Rosenfeld, E.; Kolter, Z. Certified adversarial robustness via randomized smoothing. In Proceedings of the 36th International Conference on Machine Learning (ICML), Long Beach, CA, USA, 9–15 June 2019; PMLR: Long Beach, CA, USA, 2019; pp. 1310–1320. [Google Scholar]
- Elkan, C. The foundations of cost-sensitive learning. In Proceedings of the 17th International Joint Conference on Artificial Intelligence (IJCAI), Seattle, WA, USA, 4–10 August 2001; pp. 973–978. [Google Scholar]
- Zhou, Z.-H.; Liu, X.-Y. On multi-class cost-sensitive learning. Comput. Intell. 2010, 26, 232–257. [Google Scholar] [CrossRef]
- Sharafaldin, I.; Lashkari, A.H.; Ghorbani, A.A. Toward generating a new intrusion detection dataset and intrusion traffic characterization. In Proceedings of the 4th International Conference on Information Systems Security and Privacy (ICISSP), Funchal, Portugal, 22–24 January 2018; SCITEPRESS: Setúbal, Portugal, 2018; pp. 108–116. [Google Scholar]
- Moustafa, N.; Slay, J. UNSW-NB15: A comprehensive data set for network intrusion detection systems. In Proceedings of the 2015 Military Communications and Information Systems Conference (MilCIS), Canberra, Australia, 10–12 November 2015; IEEE: Piscataway, NJ, USA, 2015; pp. 1–6. [Google Scholar] [CrossRef]
- Tavallaee, M.; Bagheri, E.; Lu, W.; Ghorbani, A.A. A detailed analysis of the KDD CUP 99 data set. In Proceedings of the 2009 IEEE Symposium on Computational Intelligence for Security and Defense Applications (CISDA), Ottawa, ON, Canada, 8–10 July 2009; IEEE: New York, NY, USA, 2009; pp. 1–6. [Google Scholar] [CrossRef]
- Tang, T.A.; Mhamdi, L.; McLernon, D.; Zaidi, S.A.R.; Ghogho, M. Deep learning approach for network intrusion detection in software defined networking. In Proceedings of the 2016 International Conference on Wireless Networks and Mobile Communications (WINCOM), Fez, Morocco, 26–29 October 2016; IEEE: Piscataway, NJ, USA, 2016; pp. 258–263. [Google Scholar] [CrossRef]
- Yin, C.; Zhu, Y.; Fei, J.; He, X. A deep learning approach for intrusion detection using recurrent neural networks. IEEE Access 2017, 5, 21954–21961. [Google Scholar] [CrossRef]
- Mirsky, Y.; Doitshman, T.; Elovici, Y.; Shabtai, A. Kitsune: An ensemble of autoencoders for online network intrusion detection. In Proceedings of the Network and Distributed System Security Symposium (NDSS), San Diego, CA, USA, 18–21 February 2018; Internet Society: Reston, VA, USA, 2018. [Google Scholar] [CrossRef]
- Lo, W.W.; Layeghy, S.; Sarhan, M.; Gallagher, M.; Portmann, M. E-GraphSAGE: A graph neural network based intrusion detection system for IoT. In Proceedings of the IEEE/IFIP Network Operations and Management Symposium (NOMS), Budapest, Hungary, 25–29 April 2022; IEEE: New York, NY, USA, 2022; pp. 1–9. [Google Scholar] [CrossRef]
- Ding, G.; Yang, S.; Lin, H.; Chen, Z.; Yang, J.S. LLM-driven adaptive cloud resource scheduling: Bridging reasoning intelligence with optimization guarantees. IEEE Open J. Comput. Soc. 2026, 7, 560–573. [Google Scholar] [CrossRef]
- Zhao, W.; Chen, T.; Yang, J.S.; Qiu, L. AutoML-Pipeline: A RAG-enhanced code generation framework with pre-validation for cloud-native machine learning workflows. IEEE Access 2026, 14, 41932–41945. [Google Scholar] [CrossRef]
- Sultan, S.; Ahmad, I.; Dimitriou, T. Container security: Issues, challenges, and the road ahead. IEEE Access 2019, 7, 52976–52996. [Google Scholar] [CrossRef]
- Baldini, I.; Castro, P.; Chang, K.; Cheng, P.; Fink, S.; Ishakian, V.; Mitchell, N.; Muthusamy, V.; Rabbah, R.; Slominski, A.; et al. Serverless computing: Current trends and open problems. In Research Advances in Cloud Computing; Springer: Singapore, 2017; pp. 1–20. [Google Scholar] [CrossRef]
- Sindhu, S.S.S.; Geetha, S.; Kannan, A. Decision tree based light weight intrusion detection using a wrapper approach. Expert Syst. Appl. 2012, 39, 129–141. [Google Scholar] [CrossRef]
- Szegedy, C.; Zaremba, W.; Sutskever, I.; Bruna, J.; Erhan, D.; Goodfellow, I.; Fergus, R. Intriguing properties of neural networks. In Proceedings of the International Conference on Learning Representations (ICLR), Banff, AB, Canada, 14–16 April 2014. [Google Scholar]
- Usama, M.; Asim, M.; Latif, S.; Khan, W.; Ahmad, J. Unsupervised machine learning for networking: Techniques, applications and research challenges. IEEE Access 2019, 7, 65579–65615. [Google Scholar] [CrossRef]
- Han, D.; Wang, Z.; Zhong, Y.; Chen, W.; Yang, J.; Lu, S.; Shi, X.; Yin, X. Evaluating and improving adversarial robustness of machine learning-based network intrusion detectors. IEEE J. Sel. Areas Commun. 2021, 39, 2632–2647. [Google Scholar] [CrossRef]
- Peng, X.; Huang, W.; Shi, Z. Adversarial attack against DoS intrusion detection: An improved boundary-based method. In Proceedings of the 2019 IEEE 31st International Conference on Tools with Artificial Intelligence (ICTAI), Portland, OR, USA, 4–6 November 2019; IEEE: New York, NY, USA, 2019; pp. 1288–1295. [Google Scholar] [CrossRef]
- Bae, S.; Kim, D.; Lee, K. Adversarial examples for tabular data: Beyond the obvious. In Proceedings of the 29th ACM SIGKDD Conference on Knowledge Discovery and Data Mining (KDD), Long Beach, CA, USA, 6–10 August 2023; ACM: New York, NY, USA, 2023; pp. 72–81. [Google Scholar] [CrossRef]
- Alhussien, N.; Aleroud, A.; Melhem, A.; Khamaiseh, S.Y. Constraining adversarial attacks on network intrusion detection systems: Transferability and defense analysis. IEEE Trans. Netw. Serv. Manag. 2024, 21, 2751–2772. [Google Scholar] [CrossRef]
- Goodfellow, I.; Pouget-Abadie, J.; Mirza, M.; Xu, B.; Warde-Farley, D.; Ozair, S.; Courville, A.; Bengio, Y. Generative adversarial nets. In Advances in Neural Information Processing Systems 27 (NeurIPS 2014), Montreal, QC, Canada, 8–13 December 2014; Curran Associates, Inc.: Red Hook, NY, USA, 2014; pp. 2672–2680. [Google Scholar]
- Duy, P.T.; Khoa, N.H.; Hien, D.T.T.; Hoang, H.D.; Pham, V.-H. Investigating on the robustness of flow-based intrusion detection system against adversarial samples using generative adversarial networks. J. Inf. Secur. Appl. 2023, 74, 103472. [Google Scholar] [CrossRef]
- Randhawa, R.H.; Aslam, N.; Khalid, M.; Ahsan, M.; Hassan, M.A. Security hardening of botnet detectors using generative adversarial networks. IEEE Access 2021, 9, 106184–106198. [Google Scholar] [CrossRef]
- Hu, W.; Tan, Y. Generating adversarial malware examples for black-box attacks based on GAN. arXiv 2017, arXiv:1702.05983. [Google Scholar] [CrossRef]
- Shahraki, A.; Abbasi, M.; Taherkordi, A.; Jurcut, A.D. Active learning for network traffic classification: A technical study. IEEE Trans. Cogn. Commun. Netw. 2022, 8, 1424–1436. [Google Scholar] [CrossRef]
- Novaes, M.P.; Carvalho, L.F.; Lloret, J.; Proencça, M.L. Adversarial deep learning approach detection and defense against DDoS attacks in SDN environments. Future Gener. Comput. Syst. 2021, 125, 156–167. [Google Scholar] [CrossRef]
- Maalouf, M.; Farhan, A.; El-Halabi, T. Adversarial defense in cybersecurity: A systematic review of GANs for threat detection and mitigation. arXiv 2025, arXiv:2509.20411. [Google Scholar] [CrossRef]
- Sheatsley, R.; Hoak, B.; Raber, E.; McDaniel, P. On the robustness of network intrusion detection systems against adversarial inputs. arXiv 2022, arXiv:2303.07003. [Google Scholar]
- Xing, S.; Wang, Y.; Liu, W. Self-adapting CPU scheduling for mixed database workloads via hierarchical deep reinforcement learning. Symmetry 2025, 17, 1109. [Google Scholar] [CrossRef]
- Zhu, L.; Chen, J.; Al-Azzam, N.; Jiang, X. An enhanced ensemble defense framework for boosting adversarial robustness of intrusion detection systems. Sci. Rep. 2025, 15, 14202. [Google Scholar] [CrossRef]
- Jiang, C.; Wang, J.; Dong, M.; Gui, J.; Shi, X.; Cao, Y.; Tang, Y.Y.; Kwok, J.T.-Y. Improving fast adversarial training via self-knowledge guidance. IEEE Trans. Inf. Forensics Secur. 2025, 20, 3772–3787. [Google Scholar] [CrossRef]
- Alpcan, T.; Basar, T. Network Security: A Decision and Game-Theoretic Approach; Cambridge University Press: Cambridge, UK, 2010. [Google Scholar]
- Roy, S.; Ellis, C.; Shiva, S.; Dasgupta, D.; Shandilya, V.; Wu, Q. A survey of game theory as applied to network security. In Proceedings of the 2010 43rd Hawaii International Conference on System Sciences (HICSS), Honolulu, HI, USA, 5–8 January 2010; IEEE: Piscataway, NJ, USA, 2010; pp. 1–10. [Google Scholar] [CrossRef]
- Lye, K.; Wing, J. Game strategies in network security. Int. J. Inf. Secur. 2005, 4, 71–86. [Google Scholar] [CrossRef]
- Carroll, T.E.; Grosu, D. A game theoretic investigation of deception in network security. Secur. Commun. Netw. 2011, 4, 1162–1172. [Google Scholar] [CrossRef]
- Liu, Y.; Feng, D.; Lian, Y.; Chen, K.; Zhang, Y. Optimal defense strategies for DDoS defender using Bayesian game model. In Information Security Practice and Experience; Lecture Notes in Computer Science; Springer: Berlin/Heidelberg, Germany, 2013; Volume 7863, pp. 44–59. [Google Scholar] [CrossRef]
- Bose, A.J.; Cianflone, A.; Hamilton, W.L. Adversarial example games. In Advances in Neural Information Processing Systems 33 (NeurIPS 2020), Virtual, 6–12 December 2020; Curran Associates, Inc.: Red Hook, NY, USA, 2020; pp. 8921–8932. [Google Scholar]
- Pinot, R.; Meunier, L.; Bhatt, U.; Yousefian, F.; Krichene, W.; Martin, A.; Biroli, G.; Pfister, T. A unified view of differential privacy and robustness to adversarial examples. arXiv 2019, arXiv:1906.07982. [Google Scholar] [CrossRef]
- Axelsson, S. The base-rate fallacy and the difficulty of intrusion detection. ACM Trans. Inf. Syst. Secur. 2000, 3, 186–205. [Google Scholar] [CrossRef]
- Lin, T.-Y.; Goyal, P.; Girshick, R.; He, K.; Dollár, P. Focal loss for dense object detection. In Proceedings of the IEEE International Conference on Computer Vision (ICCV), Venice, Italy, 22–29 October 2017; IEEE: New York, NY, USA, 2017; pp. 2980–2988. [Google Scholar] [CrossRef]
- Miyato, T.; Kataoka, T.; Koyama, M.; Yoshida, Y. Spectral normalization for generative adversarial networks. In Proceedings of the International Conference on Learning Representations (ICLR), Vancouver, BC, Canada, 30 April–3 May 2018. [Google Scholar]
- He, K.; Zhang, X.; Ren, S.; Sun, J. Deep residual learning for image recognition. In Proceedings of the 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), Las Vegas, NV, USA, 27–30 June 2016; IEEE: Piscataway, NJ, USA, 2016; pp. 770–778. [Google Scholar] [CrossRef]
- Ioffe, S.; Szegedy, C. Batch normalization: Accelerating deep network training by reducing internal covariate shift. In Proceedings of the 32nd International Conference on Machine Learning (ICML), Lille, France, 6–11 July 2015; PMLR: Lille, France, 2015; pp. 448–456. [Google Scholar]
- Hendrycks, D.; Gimpel, K. Gaussian error linear units (GELUs). arXiv 2016, arXiv:1606.08415. [Google Scholar]
- Srivastava, N.; Hinton, G.; Krizhevsky, A.; Sutskever, I.; Salakhutdinov, R. Dropout: A simple way to prevent neural networks from overfitting. J. Mach. Learn. Res. 2014, 15, 1929–1958. [Google Scholar]
- Freund, Y.; Schapire, R.E. Adaptive game playing using multiplicative weights. Games Econ. Behav. 1999, 29, 79–103. [Google Scholar] [CrossRef]
- CyberPrince. Cloud Vulnerabilities Dataset; Kaggle: San Francisco, CA, USA, 2023; Available online: https://www.kaggle.com/datasets/cyberprince/cloud-vulnerabilities-dataset (accessed on 1 February 2025).
- Lashkari, A.H.; Draper-Gil, G.; Mamun, M.S.I.; Ghorbani, A.A. Characterization of Tor traffic using time based features. In Proceedings of the 3rd International Conference on Information Systems Security and Privacy (ICISSP), Porto, Portugal, 19–21 February 2017; pp. 253–262. [Google Scholar] [CrossRef]
- Kurakin, A.; Goodfellow, I.; Bengio, S. Adversarial examples in the physical world. In Proceedings of the International Conference on Learning Representations Workshop (ICLR), Toulon, France, 24–26 April 2017. [Google Scholar]
- Moosavi-Dezfooli, S.-M.; Fawzi, A.; Frossard, P. DeepFool: A simple and accurate method to fool deep neural networks. In Proceedings of the 2016 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), Las Vegas, NV, USA, 27–30 June 2016; IEEE: New York, NY, USA, 2016; pp. 2574–2582. [Google Scholar] [CrossRef]





| Epoch | Interpretation | ||||
|---|---|---|---|---|---|
| 0 | — | — | 5.00 | 1.00 | Initial costs |
| 5 | 0.18 | 0.04 | 5.20 | 0.99 | Generator finding evasions |
| 15 | 0.12 | 0.06 | 7.84 | 0.88 | Strong evasions discovered |
| 30 | 0.05 | 0.04 | 12.31 | 0.93 | Detector closing gap |
| 50 | 0.03 | 0.05 | 14.56 | 0.95 | Near equilibrium |
| 80 | 0.02 | 0.05 | 14.72 | 0.97 | Approx. equilibrium reached |
| 100 | 0.02 | 0.05 | 14.74 | 0.98 | Converged |
| Method | CA (%) | RA (%) | FNR (%) | RAG (pp) | F1 (%) |
|---|---|---|---|---|---|
| Standard | 99.4 ± 0.1 | 72.9 ± 1.3 | 24.7 ± 1.1 | 26.5 | 98.8 ± 0.2 |
| AT-PGD | 97.1 ± 0.3 | 87.5 ± 0.6 | 10.3 ± 0.7 | 9.6 | 96.6 ± 0.3 |
| TRADES | 97.5 ± 0.2 | 88.1 ± 0.5 | 9.8 ± 0.6 | 9.4 | 97.1 ± 0.2 |
| IDSGAN-AT | 98.2 ± 0.2 | 85.3 ± 0.8 | 12.6 ± 0.9 | 12.9 | 97.7 ± 0.2 |
| Focal-AT | 97.8 ± 0.2 | 87.0 ± 0.7 | 11.0 ± 0.6 | 10.8 | 97.2 ± 0.3 |
| GT-CSAT (Ours) | 97.1 ± 0.2 | 94.3 ± 0.4 | 3.1 ± 0.3 | 2.8 | 96.8 ± 0.2 |
| Method | FGSM | PGD-20 | BIM | C&W | DeepFool | IDSGAN-BB |
|---|---|---|---|---|---|---|
| Standard | 74.2 | 68.1 | 70.3 | 66.4 | 71.1 | 77.2 |
| AT-PGD | 92.1 | 91.8 | 91.4 | 84.2 | 89.3 | 76.4 |
| TRADES | 92.5 | 92.0 | 91.8 | 83.4 | 90.1 | 79.0 |
| IDSGAN-AT | 88.6 | 86.4 | 87.2 | 81.1 | 87.0 | 81.6 |
| Focal-AT | 91.3 | 90.2 | 90.6 | 82.5 | 89.0 | 79.4 |
| GT-CSAT | 95.8 | 95.1 | 95.3 | 92.1 | 94.6 | 93.4 |
| Configuration | CA (%) | RA (%) | FNR (%) | FPR (%) |
|---|---|---|---|---|
| GT-CSAT (full) | 97.1 | 94.3 | 3.1 | 2.9 |
| – Nash cost adaptation | 97.3 | 91.1 ↓ | 5.8 ↑ | 2.7 |
| – Conditioned generation | 97.2 | 92.2 ↓ | 4.9 ↑ | 2.9 |
| – Semantic constraint projection | 96.8 | 92.9 ↓ | 4.2 ↑ | 3.8 ↑ |
| – Evasion guidance update | 97.0 | 92.7 ↓ | 4.6 ↑ | 2.9 |
| – WGAN-GP (replace with vanilla GAN) | 96.4 | 89.7 ↓ | 7.2 ↑ | 3.4 |
| Method | Train Time/Epoch (s) | Inference Latency (ms) |
|---|---|---|
| Standard | 8.2 | 0.11 |
| AT-PGD | 36.4 | 0.11 |
| TRADES | 35.1 | 0.11 |
| IDSGAN-AT | 42.6 | 0.11 |
| Focal-AT | 36.2 | 0.11 |
| GT-CSAT | 76.3 | 0.11 |
| Dataset | Method | CA (%) | RA (%) | FNR (%) | RAG (pp) |
|---|---|---|---|---|---|
| CICIDS- | Standard | 99.6 ± 0.1 | 71.4 ± 1.5 | 26.1 ± 1.2 | 28.2 |
| 2017 | AT-PGD | 97.3 ± 0.3 | 86.8 ± 0.7 | 11.0 ± 0.8 | 10.5 |
| TRADES | 97.7 ± 0.2 | 87.4 ± 0.6 | 10.5 ± 0.7 | 10.3 | |
| GT-CSAT | 97.3 ± 0.2 | 93.7 ± 0.5 | 3.5 ± 0.4 | 3.6 | |
| UNSW- | Standard | 98.9 ± 0.2 | 68.7 ± 1.8 | 28.3 ± 1.4 | 30.2 |
| NB15 | AT-PGD | 96.5 ± 0.3 | 84.2 ± 0.9 | 13.1 ± 0.8 | 12.3 |
| TRADES | 96.8 ± 0.3 | 85.0 ± 0.7 | 12.4 ± 0.7 | 11.8 | |
| GT-CSAT | 96.4 ± 0.3 | 92.1 ± 0.5 | 4.4 ± 0.4 | 4.3 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Ding, J.; Shen, Z.; Liu, W. Game-Theoretic Cost-Sensitive Adversarial Training for Robust Cloud Intrusion Detection Against GAN-Based Evasion Attacks. Appl. Sci. 2026, 16, 3944. https://doi.org/10.3390/app16083944
Ding J, Shen Z, Liu W. Game-Theoretic Cost-Sensitive Adversarial Training for Robust Cloud Intrusion Detection Against GAN-Based Evasion Attacks. Applied Sciences. 2026; 16(8):3944. https://doi.org/10.3390/app16083944
Chicago/Turabian StyleDing, Jianbo, Zijian Shen, and Wenhe Liu. 2026. "Game-Theoretic Cost-Sensitive Adversarial Training for Robust Cloud Intrusion Detection Against GAN-Based Evasion Attacks" Applied Sciences 16, no. 8: 3944. https://doi.org/10.3390/app16083944
APA StyleDing, J., Shen, Z., & Liu, W. (2026). Game-Theoretic Cost-Sensitive Adversarial Training for Robust Cloud Intrusion Detection Against GAN-Based Evasion Attacks. Applied Sciences, 16(8), 3944. https://doi.org/10.3390/app16083944

