RandomForestNN Classification for Adversarial AI Black-Box Techniques on MITRE ATT&CK Labeled Data
Abstract
1. Introduction
2. Background and Related Works
2.1. Adversarial Machine Learning Research Landscape
2.2. Tagging Alerts to Adversaries: ML-Enabled Classification Using MITRE ATT&CK
2.3. AI-Based MITRE ATT&CK Detection System
2.4. Adaptive Threat Modeling with MITRE ATT&CK
2.5. Other Works on Adversarial Machine Learning
3. The Datasets Used
3.1. UWF-ZeekData22
- TCP: 33,987,569 records;
- UDP: 105,098,306 records;
- ICMP: 1,391,241 records.
3.2. UWF-ZeekData24
- Temporal Accuracy: UWF-ZeekData22 exhibits a “slop factor” of approximately 5 min, meaning the timestamps between mission logs and network traffic may vary significantly, introducing noise into the labeling process. Conversely, UWF-ZeekData24 demonstrates far greater temporal precision with accurate timestamps and distinct network “floors” and “peaks,” facilitating exact correlation for machine learning training.
- Noise and Anomalies: The crowd-sourced nature of UWF-ZeekData22 results in a dataset rich in anomalous behavior and noise, which effectively represents the chaotic nature of human-driven attack scenarios. However, UWF-ZeekData24 provides a “cleaner” signal with significantly less noise, making it potentially more suitable for establishing baseline ground truth for algorithmic training.
- Attack Composition: While UWF-ZeekData22 contains a diverse mix of attacks generated by students (red teams) against blue teams, UWF-ZeekData24 relies on specific automated scripts (e.g., Nmap scans) to generate reproducible attack patterns, such as the heavy concentration of Credential Access attempts.
4. Adversarial Attacks Used in This Work
4.1. The HopSkipJump Attack
4.2. The SPSA Attack
4.3. The Square Attack
5. Methodology
5.1. Research Flow
- How do adversarial attacks (HopSkipJump, SPSA and Square) affect the classification performance of a network traffic model trained using the Random ForestNN MITRE ATT&CK framework?
- Does leveraging the MITRE ATT&CK framework for training reduce the effectiveness of adversarial attacks on a network traffic classification model?
- Is there a specific attribute that is weighed more than another to make misclassification more frequent (or likely)?
- Is using a combination of modified attributes more successful in misclassification?
5.2. Parameters Used
5.2.1. Spark Parameters
5.2.2. Random Forest
- featuresCol: str = ‘features’; labelCol: str = ‘label’; predictionCol: str = ‘prediction’; probabilityCol: str = ‘probability’; rawPredictionCol: str = ‘rawPrediction’; maxDepth: int = 5; maxBins: int = 32; minInstancesPerNode: int = 1; minInfoGain: float = 0.0; maxMemoryInMB: int = 256; cacheNodeIds: bool = False; checkpointInterval: int = 10; impurity: str = ‘gini’; numTrees: int = 20; featureSubsetStrategy: str = ‘auto’; seed: Optional[int] = None; subsamplingRate: float = 1.0; leafCol: str = ‘’; minWeightFractionPerNode: float = 0.0; weightCol: Optional[str] = None; and bootstrap: Optional[bool] = True.
5.2.3. Neural Network Parameters
6. Results
6.1. Classification Performance Metrics
6.2. Baseline Analysis
6.3. Attack Perturbation Analysis
6.4. HopSkipJump Attack Performance by MITRE ATT&CK Tactic
- For Credential Access, a TP of 0 and FP of 0.
- For Defense Evasion, a TP of 0 and FP of 0.
- For Exfiltration, a TP of 0 and FP of 0.
- For Initial Access, a TP of 0 and FP of 0.
- For Persistence, a TP of 0 and FP of 0.
- For Privilege Escalation, a TP of 0 and FP of 0.
- For Reconnaissance, a TP of 0 and FP of 9.
- For Credential Access, the features orig_bytes, dest_ip_zeek, orig_pkts, orig_ip_bytes, dest_post_zeek, conn_state, resp_pkts, resp_ip_bytes, src_port_zeek, resp_bytes, src_ip_zeek, and missed_bytes were perturbed with a frequency of 0.61, reflecting a modification rate exceeding half of the total occurrences.
- For Defense Evasion, the features history, service, orig_bytes, dest_ip_zeek, orig_pkts, orig_ip_bytes, dest_port_zeek, conn_state, resp_pkts, resp_ip_bytes, src_port_zeek, resp_bytes, src_ip_zeek, and missed_bytes were perturbed with a frequency of 0.64, reflecting a modification rate exceeding half of the total occurrences.
- For Exfiltration, the features orig_bytes, dest_ip_zeek, orig_pkts, orig_ip_bytes, dest_port_zeek, duration, resp_pkts, resp_ip_bytes, src_port_zeek, resp_bytes, and mised_bytes were perturbed with a frequency of 0.8630, reflecting a modification rate exceeding half of the total occurrences.
- For Initial Access, the features history, service, orig_bytes, dest_ip_zeek, orig_pkts, orig_ip_bytes, dest_port_zeek, resp_pkts, resp_ip_bytes, src_port_zeek, resp_bytes, src_ip_zeek, and missed_bytes were perturbed with a frequency of 0.44, reflecting a modification rate under half of the total occurrences.
- For Persistence, the features history, orig_bytes, dest_ip_zeek, orig_pkts, orig_ip_bytes, dest_port_zeek, conn_state, resp_pkts, resp_ip_bytes, src_port_zeek, resp_bytes, src_ip_zeek, and missed_bytes were perturbed with a frequency of 0.55, reflecting a modification rate exceeding half of the total occurrences.
- For Privilege Escalation, the features history, service, orig_bytes, dest_ip_zeek, orig_pkts, orig_ip_bytes, dest_port_zeek, conn_state, resp_pkts, resp_ip_bytes, src_port_zeek, resp_bytes, src_ip_zeek, and missed_bytes were perturbed with a frequency of 0.54, reflecting a modification rate exceeding half of the total occurrences.
- For Reconnaissance, the features history, proto, service, orig_bytes, dest_ip_zeek, orig_pkts, orig_ip_bytes, dest_port_zeek, resp_pkts, resp_ip_bytes, src_port_zeek, resp_bytes, src_ip_zeek, and missed_bytes were perturbed with a frequency of 0.41, reflecting a modification rate under half of the total occurrences.
6.5. SPSA Attack Performance by MITRE ATT&CK Tactic
- For Credential Access, a TP of 0 and FP of 4.
- For Defense Evasion, a TP of 0 and FP of 49.
- For Exfiltration, a TP of 0 and FP of 48.
- For Initial Access, a TP of 0 and FP of 50.
- For Persistence, a TP of 0 and FP of 48.
- For Privilege Escalation, a TP of 0 and FP of 48.
- For Reconnaissance, a TP of 0 and FP of 50.
- For Credential Access, the features dest_ip_zeek, orig_pkts, orig_ip_bytes, src_port_zeek, and src_ip_zeek were perturbed with a frequency of 1, reflecting a modification rate of all occurrences.
- For Defense Evasion, the features dest_ip_zeek, orig_pkts, orig_ip_bytes, src_port_zeek, and src_ip_zeek were perturbed with a frequency of 1, reflecting a modification rate of all occurrences.
- For Exfiltration, the features dest_ip_zeek, orig_pkts, orig_ip_bytes, src_port_zeek, and src_ip_zeek were perturbed with a frequency of 1, reflecting a modification rate of all occurrences.
- For Initial Access, the features dest_ip_zeek, orig_pkts, orig_ip_bytes, src_port_zeek, and src_ip_zeek were perturbed with a frequency of 1, reflecting a modification rate of all occurrences.
- For Persistence, the features dest_ip_zeek, orig_pkts, orig_ip_bytes, src_port_zeek, and src_ip_zeek, were perturbed with a frequency of 1 reflecting a modification rate of all occurrences.
- For Privilege Escalation, the features dest_ip_zeek, orig_ip_bytes, src_port_zeek, and src_ip_zeek were perturbed with a frequency of 1, reflecting a modification rate of all occurrences.
- For Reconnaissance, the features dest_ip_zeek, orig_pkts, orig_ip_bytes, src_port_zeek, and src_ip_zeek were perturbed with a frequency of 1, reflecting a modification rate of all occurrences.
6.6. Square Attack Performance by MITRE ATT&CK Tactic
- For Credential Access, a TP of 50 and FP of 11.
- For defense evasion, a TP of 0 and FP of 50.
- For Exfiltration, a TP of 0 and FP of 48.
- For Initial Access, a TP of 0 and FP of 36.
- For Persistence, a TP of 0 and FP of 50.
- For Privilege Escalation, a TP of 0 and FP of 50.
- For Reconnaissance, a TP of 0 and FP of 50.
- For Credential Access, all features were not perturbed, with a frequency of 0, reflecting a modification rate of all occurrences.
- For Defense Evasion, the features history, service, orig_bytes, dest_in_zeek, orig_pkts, orig_ip_bytes, resp_pkts, resp_ip_bytes, src_port_zeek, resp_bytes, and src_ip_zeek were perturbed with a frequency of 0.14, reflecting a modification rate of all occurrences.
- For Exfiltration, the features dest_ip_zeek, orig_ip_bytes, resp_ip_bytes, and src_ip_zeek were perturbed with a frequency of 0.2054, reflecting a modification of all occurrences.
- For Initial Access, the features history, service, orig_bytes, dest_ip_zeek, orig_pkts, orig_ip_bytes, duration, conn_state, resp_pkts, resp_ip_bytes, resp_bytes, and src_ip_zeek were perturbed with a frequency of 0.08, reflecting a modification rate of all occurrences.
- For Persistence, the features history, orig_bytes, dest_ip_zeek, orig_pkts, orig_ip_bytes, resp_pkts, resp_ip_bytes, src_port_zeek, resp_bytes, and src_ip_zeek were perturbed with a frequency of 0.05, reflecting a modification rate of all occurrences.
- For Privilege Escalation, the features history, service, orig_bytes, dest_ip_zeek, orig_pkts, orig_ip_bytes, duration, resp_pkts, resp_ip_bytes, src_port_zeek, resp_bytes, and src_ip_zeek were perturbed with a frequency of 0.04, reflecting a modification rate of all occurrences.
- For Reconnaissance, all features were perturbed with a frequency of 0, reflecting a modification rate of all occurrences.
6.7. Feature Vulnerability Analysis
Attack-Specific Feature Targeting Patterns
6.8. Attack Type Specific Feature Vulnerabilities
6.9. Comparative Attack Performance and Vulnerability Analysis
6.10. Feature Removal Experiment
6.11. Targeting Redistribution
7. Conclusions
8. Future Works
Author Contributions
Funding
Data Availability Statement
Acknowledgments
Conflicts of Interest
References
- Tekeste, B.; Al-Hussaeni, K.; Fung, B.C.M.; Alawadhi, I.; Fachkha, C. Adversarial Machine Learning: A 20-Year Survey of Attacks, Defenses, and Standards. IEEE Access 2026, 14, 69778–69812. [Google Scholar] [CrossRef]
- MITRE ATT&CK Framework. Available online: https://attack.mitre.org/ (accessed on 20 May 2026).
- Strom, B.E.; Applebaum, A.; Miller, D.P.; Nickels, K.C.; Pennington, A.G.; Thomas, C.B. MITRE ATT&CK: Design and Philosophy; Technical Report; The MITRE Corporation: Bedford, MA, USA, 2018. [Google Scholar]
- Al-Sada, B.; Sadighian, A.; Oligeri, G. MITRE ATT&CK: State of the Art and Way Forward. ACM Comput. Surv. 2024, 57, 1–37. [Google Scholar] [CrossRef]
- Adversarial Robustness Toolbox. Available online: https://github.com/Trusted-AI/adversarial-robustness-toolbox (accessed on 20 May 2026).
- Chen, J.; Jordan, M.I.; Wainwright, M.J. HopSkipJump attack: A query-efficient decision-based attack. In Proceedings of IEEE Symposium on Security and Privacy, San Francisco, CA, USA, 18–20 May 2020; pp. 1277–1294. [Google Scholar]
- CleverHans. Available online: https://github.com/cleverhans-lab/cleverhans (accessed on 20 May 2026).
- Jonathan, U.; O’donoghue, B.; Kohli, P.; Oord, A. Adversarial risk and the dangers of evaluating against weak attacks. In Proceedings of the International Conference on Machine Learning, Stockholm, Sweden, 10–15 July 2018; PMLR. pp. 5025–5034. [Google Scholar]
- Rauber, J.; Zimmermann, R.; Bethge, M.; Brendel, W. Foolbox Native: Fast adversarial attacks to benchmark the robustness of machine learning models in PyTorch, TensorFlow, and JAX. J. Open Source Softw. 2020, 5, 2607. [Google Scholar] [CrossRef]
- Andriushchenko, M.; Croce, F.; Flammarion, N.; Hein, M. Square Attack: A Query-Efficient Black-Box Adversarial Attack via Random Search. In Proceedings of the European Conference on Computer Vision (ECCV), Glasgow, UK, 23–28 August 2020; pp. 484–501. [Google Scholar]
- Talpur, A.; Schröder, J.; Kistenmacher, L.; Becker, G.; Wingerath, W.; Fischer, M. Tagging Alerts to Adversaries: ML-Enabled Classification Using MITRE ATT&CK. In Proceedings of the 2025 IEEE Conference on Communications and Network Security (CNS), Taipei, Taiwan, 13–15 October 2025; pp. 1–9. [Google Scholar]
- Koutras, D.; Karamousadakis, M.; Konstantinidis, G.; Grigoriadis, C.; Malamas, V.; Kotzanikolaou, P. AI-Based MITRE ATT&CK Detection System: A Feasibility Study. In Proceedings of the 2025 11th International Conference on Control, Decision and Information Technologies (CoDIT), Volos, Greece, 2–5 July 2025; Volume 1, pp. 509–514. [Google Scholar]
- Maniyat, V.B.; Arun Kumar, B.R. Adaptive Threat Modeling with MITRE ATT&CK: A Machine Learning Framework for Real-Time Adversarial Detection. In Proceedings of the 2025 9th International Conference on Computational System and Information Technology for Sustainable Solutions (CSITSS), Bengaluru, India, 18–20 December 2025; pp. 1–6. [Google Scholar]
- Goodfellow, I.J.; Shlens, J.; Szegedy, C. Explaining and Harnessing Adversarial Examples. In Proceedings of the International Conference on Learning Representations (ICLR), San Diego, CA, USA, 7–9 May 2015. [Google Scholar]
- Verma, G.; Ciftcioglu, E.; Sheatsley, R.; Chan, K.; Scott, L. Network Traffic Obfuscation: An Adversarial Machine Learning Approach. In Proceedings of the MILCOM 2018—IEEE Military Communications Conference, Los Angeles, CA, USA, 29–31 October 2018; pp. 413–418. [Google Scholar] [CrossRef]
- Usama, M.; Qayyum, A.; Qadir, J.; Al-Fuqaha, A. Black-Box Adversarial Machine Learning Attack on Network Traffic Classification. In Proceedings of the IEEE International Conference on Communications Workshops (ICC Workshops), Shanghai, China, 20–24 May 2019; pp. 84–89. [Google Scholar] [CrossRef]
- Han, D.; Wang, Z.; Zhong, Y.; Chen, W.; Yang, J.; Lu, S.; Shi, X.; Yin, X. Evaluating and Improving Adversarial Robustness of Machine Learning-Based Network Intrusion Detectors. IEEE J. Sel. Areas Commun. 2021, 39, 2632–2647. [Google Scholar] [CrossRef]
- Subbaratinam, S. Machine Learning Based Risk Classification of Vulnerabilities Incorporating MITRE ATT&CK Framework and Threat Intelligence. Ph.D. Thesis, Marymount University, Arlington, VA, USA, 2022. [Google Scholar]
- Malik, J.; Muthalagu, R.; Pawar, P.M. A Systematic Review of Adversarial Machine Learning Attacks, Defensive Controls, and Technologies. IEEE Access 2024, 12, 99382–99421. [Google Scholar] [CrossRef]
- Khazane, H.; Ridouani, M.; Salahdine, F.; Kaabouch, N. A Holistic Review of Machine Learning Adversarial Attacks in IoT Networks. Future Internet 2024, 16, 32. [Google Scholar] [CrossRef]
- Abomakhelb, A.; Jalil, K.A.; Buja, A.G.; Alhammadi, A.; Alenezi, A.M. A Comprehensive Review of Adversarial Attacks and Defense Strategies in Deep Neural Networks. Technologies 2025, 13, 202. [Google Scholar] [CrossRef]
- Ennaji, S.; De Gaspari, F.; Hitaj, D.; Bidi, A.K.; Mancini, L.V. Adversarial Challenges in Network Intrusion Detection Systems: Research Insights and Future Prospects. ACM Comput. Surv. 2024, 13, 148613–148645. [Google Scholar] [CrossRef]
- Paya, A.; Arroni, S.; García-Díaz, V.; Gómez, A. Apollon: A Robust Defense System Against Adversarial Machine Learning Attacks in Intrusion Detection Systems. Comput. Secur. 2024, 136, 103546. [Google Scholar] [CrossRef]
- Khan, M.; Ghafoor, L. Adversarial Machine Learning in the Context of Network Security: Challenges and Solutions. J. Comput. Intell. Robot. 2024, 4, 51–63. Available online: https://thesciencebrigade.com/jcir/ (accessed on 20 May 2026).
- Alhajjar, E.; Maxwell, P.; Bastian, N. Adversarial machine learning in network intrusion detection systems. Expert Syst. Appl. 2021, 186, 115782. [Google Scholar] [CrossRef]
- Kumar, V.; Kumar, K.; Singh, M. Generating Practical Adversarial Examples Against Learning-Based Network Intrusion Detection Systems. Ann. Telecommun. 2024, 80, 209–226. [Google Scholar] [CrossRef]
- Sadeghzadeh, A.M.; Shiravi, S.; Jalili, R. Adversarial Network Traffic: Towards Evaluating the Robustness of Deep Learning-Based Network Traffic Classification. IEEE Trans. Netw. Serv. Manag. 2024, 18, 1962–1976. [Google Scholar] [CrossRef]
- Jedrzejewski, F.V.; Thode, L.; Fischbach, J.; Gorschek, T.; Mendez, D.; Lavesson, N. Adversarial Machine Learning in Industry: A Systematic Literature Review. Comput. Secur. 2024, 145, 103988. [Google Scholar] [CrossRef]
- Bagui, S.S.; Mink, D.; Bagui, S.C.; Ghosh, T.; Plenkers, R.; McElroy, T.; Dulaney, S.; Shabanali, S. Introducing UWF-ZeekData22: A Comprehensive Network Traffic Dataset Based on the MITRE ATT&CK Framework. Data 2023, 8, 18. [Google Scholar] [CrossRef]
- Elam, M.; Mink, D.; Bagui, S.S.; Plenkers, R.; Bagui, S.C. Introducing UWF-ZeekData24: An Enterprise MITRE ATT&CK Labeled Network Attack Traffic Dataset for Machine Learning/AI. Data 2025, 10, 59. [Google Scholar] [CrossRef]
- UWF Datasets. Available online: https://datasets.uwf.edu/ (accessed on 8 August 2025).
- Miller, E.; Mink, D.; Spellings, P.; Bagui, S.S.; Bagui, S.C. Classifying Cyber Ranges: A Case-Based Analysis Using the UWF Cyber Range. Encyclopedia 2025, 5, 162. [Google Scholar] [CrossRef]
- Tavallaee, M.; Bagheri, E.; Lu, W.; Ghorbani, A.A. A Detailed Analysis of the KDD CUP 99 Data Set. In Proceedings of the Second IEEE Symposium on Computational Intelligence for Security and Defense Applications, Ottawa, ON, Canada, 8–10 July 2009; pp. 1–6. Available online: https://ieeexplore.ieee.org/document/5356528 (accessed on 9 August 2025).
- Moustafa, N.; Slay, J. UNSW-NB15: A Comprehensive Data Set for Network Intrusion Detection Systems. In Proceedings of the Military Communications and Information Systems Conference (MilCIS), Canberra, Australia, 10–12 November 2015; pp. 1–6. Available online: https://ieee-dataport.org/documents/unswnb15-dataset (accessed on 9 August 2025).
- Bagui, S.; Mink, D.; Bagui, S.; Ghosh, T.; McElroy, T.; Paredes, E.; Khasnavis, N.; Plenkers, R. Detecting Reconnaissance and Discovery Tactics from the MITRE ATT&CK Framework in Zeek Conn Logs Using Spark’s Machine Learning in the Big Data Framework. Sensors 2022, 22, 7999. [Google Scholar] [CrossRef]
- Zeek Project. About Zeek. Available online: https://docs.zeek.org/en/current/about.html (accessed on 15 February 2026).








| Tool | Attack Type | Primary Use Case | Key Function/Method |
|---|---|---|---|
| ART | HopSkipJump | Black-box decision-based | HopSkipJump(classifier).generate(x) |
| CleverHans | SPSA | Gradient-free/Obfuscated gradients | SPSA(model, …).generate(x) |
| Foolbox | Square Attack | Black-box score-based | SquareAttack() (model, x, y, epsilons) |
| Classifier | UWF-ZeekData24 (Test) | UWF-ZeekData22 |
|---|---|---|
| Random Forest |
| Attack Type | Accuracy | Precision (Macro) | Recall (Macro) | F1 (Macro) |
|---|---|---|---|---|
| Credential Access | 1 | 1 | 1 | 1 |
| Defense Evasion | 0.969 | 0.955 | 0.975 | 0.964 |
| Exfiltration | 0.87 | 0.862 | 0.873 | 0.865 |
| Initial Access | 0.988 | 0.983 | 0.989 | 0.986 |
| Persistence | 0.966 | 0.951 | 0.973 | 0.961 |
| Privilege Escalation | 0.972 | 0.958 | 0.98 | 0.968 |
| Reconnaissance | 0.998 | 0.998 | 0.998 | 0.998 |
| Attack Type | Accuracy | Precision (Macro) | Recall (Macro) | F1 (Macro) |
|---|---|---|---|---|
| Credential Access | 0.000 | 0.000 | 0.000 | 0.000 |
| Defense Evasion | 0.000 | 0.000 | 0.000 | 0.000 |
| Exfiltration | 0.000 | 0.000 | 0.000 | 0.000 |
| Initial Access | 0.000 | 0.000 | 0.000 | 0.000 |
| Persistence | 0.000 | 0.000 | 0.000 | 0.000 |
| Privilege Escalation | 0.000 | 0.000 | 0.000 | 0.000 |
| Reconnaissance | 0.090 | 0.076 | 0.090 | 0.083 |
| TACTIC | NN |
|---|---|
| Credential Access | |
| Defense Evasion | |
| Exfiltration | |
| Initial Access | |
| Persistence | |
| Privilege Escalation | |
| Reconnaissance |
| Feature | Credential Access | Defense Evasion | Exfiltration | Initial Access | Persistence | Privilege Escalation | Reconnaissance |
|---|---|---|---|---|---|---|---|
| history | 0.2 | 0.64 | 0.8082 | 0.44 | 0.55 | 0.54 | 0.41 |
| proto | 0.52 | 0.5 | 0.6712 | 0.36 | 0.5 | 0.5 | 0.41 |
| service | 0.55 | 0.64 | 0.8493 | 0.44 | 0.54 | 0.54 | 0.41 |
| orig_bytes | 0.61 | 0.64 | 0.8630 | 0.44 | 0.55 | 0.54 | 0.41 |
| dest_ip_zeek | 0.61 | 0.64 | 0.8630 | 0.44 | 0.55 | 0.54 | 0.41 |
| orig_pkts | 0.61 | 0.64 | 0.8630 | 0.44 | 0.55 | 0.54 | 0.41 |
| orig_ip_bytes | 0.61 | 0.64 | 0.8630 | 0.44 | 0.55 | 0.54 | 0.41 |
| local_resp | 0.58 | 0.14 | 0.3013 | 0.09 | 0.09 | 0.48 | 0.4 |
| dest_port_zeek | 0.61 | 0.64 | 0.8630 | 0.44 | 0.55 | 0.54 | 0.41 |
| Duration | 0.59 | 0.63 | 0.8630 | 0.42 | 0.53 | 0.52 | 0.4 |
| conn_state | 0.61 | 0.64 | 0.7534 | 0.24 | 0.55 | 0.54 | 0.29 |
| resp_pkts | 0.61 | 0.64 | 0.8630 | 0.44 | 0.55 | 0.54 | 0.41 |
| resp_ip_bytes | 0.61 | 0.64 | 0.8630 | 0.44 | 0.55 | 0.54 | 0.41 |
| src_port_zeek | 0.61 | 0.64 | 0.8630 | 0.44 | 0.55 | 0.54 | 0.41 |
| resp_bytes | 0.61 | 0.64 | 0.8630 | 0.44 | 0.55 | 0.54 | 0.41 |
| src_ip_zeek | 0.61 | 0.64 | 0.8630 | 0.44 | 0.55 | 0.54 | 0.41 |
| local_orig | 0.56 | 0.21 | 0.2191 | 0.08 | 0.3 | 0.11 | 0.36 |
| missed_bytes | 0.61 | 0.64 | 0.8630 | 0.44 | 0.55 | 0.54 | 0.41 |
| Attack Type | Accuracy | Precision (Macro) | Recall (Macro) | F1 (Macro) |
|---|---|---|---|---|
| Credential Access | 0.040 | 0.037 | 0.040 | 0.038 |
| Defense Evasion | 0.500 | 0.250 | 0.500 | 0.333 |
| Exfiltration | 0.658 | 0.338 | 0.480 | 0.397 |
| Initial Access | 0.490 | 0.247 | 0.490 | 0.329 |
| Persistence | 0.460 | 0.240 | 0.460 | 0.315 |
| Privilege Escalation | 0.490 | 0.247 | 0.490 | 0.329 |
| Reconnaissance | 0.500 | 0.250 | 0.500 | 0.333 |
| TACTIC | SPSA |
|---|---|
| Credential Access | |
| Defense Evasion | |
| Exfiltration | |
| Initial Access | |
| Persistence | |
| Privilege Escalation | |
| Reconnaissance |
| Feature | Credential Access | Defense Evasion | Exfiltration | Initial Access | Persistence | Privilege Escalation | Reconnaissance |
|---|---|---|---|---|---|---|---|
| history | 0.45 | 0.58 | 0.7534 | 0.7 | 0.47 | 0.47 | 0.61 |
| proto | 0.52 | 0.48 | 0.6575 | 0.48 | 0.48 | 0.48 | 0.48 |
| service | 0.91 | 0.97 | 0.9178 | 0.78 | 0.98 | 0.98 | 0.99 |
| orig_bytes | 0.96 | 0.98 | 0.9726 | 0.58 | 0.98 | 0.98 | 0.6 |
| dest_ip_zeek | 1 | 1 | 1 | 1 | 1 | 1 | 1 |
| orig_pkts | 1 | 1 | 1 | 1 | 1 | 0.56 | 1 |
| orig_ip_bytes | 1 | 1 | 1 | 1 | 1 | 1 | 1 |
| local_resp | 0.5 | 0.5 | 0.3150 | 0.5 | 0.5 | 0.49 | 0.5 |
| dest_port_zeek | 0.5 | 0.5 | 0.6849 | 0.5 | 0.5 | 0.96 | 0.5 |
| Duration | 0.48 | 0.61 | 0.9726 | 0.56 | 0.51 | 0.51 | 0.95 |
| conn_state | 0.61 | 0.56 | 0.6849 | 0.4 | 0.45 | 0.45 | 0.49 |
| resp_pkts | 0.89 | 0.89 | 0.9589 | 0.89 | 0.89 | 0.89 | 0.89 |
| resp_ip_bytes | 0.89 | 0.89 | 0.8082 | 0.89 | 0.89 | 0.9 | 0.57 |
| src_port_zeek | 1 | 1 | 1 | 1 | 1 | 1 | 1 |
| resp_bytes | 0.91 | 0.91 | 0.904 | 0.56 | 0.91 | 0.91 | 0.81 |
| src_ip_zeek | 1 | 1 | 1 | 1 | 1 | 1 | 1 |
| local_orig | 0.89 | 0.5 | 0.3150 | 0.5 | 0.5 | 0.5 | 0.62 |
| missed_bytes | 0.5 | 0.5 | 0.6849 | 0.5 | 0.5 | 0.5 | 0.5 |
| Attack Type | Accuracy | Precision (Macro) | Recall (Macro) | F1 (Macro) |
|---|---|---|---|---|
| Credential Access | 0.610 | 0.781 | 0.610 | 0.540 |
| Defense Evasion | 0.500 | 0.250 | 0.500 | 0.333 |
| Exfiltration | 0.603 | 0.328 | 0.440 | 0.376 |
| Initial Access | 0.360 | 0.209 | 0.360 | 0.265 |
| Persistence | 0.390 | 0.219 | 0.390 | 0.281 |
| Privilege Escalation | 0.460 | 0.240 | 0.460 | 0.315 |
| Reconnaissance | 0.500 | 0.250 | 0.500 | 0.333 |
| TACTIC | SQUARE |
|---|---|
| Credential Access | |
| Defense Evasion | |
| Exfiltration | |
| Initial Access | |
| Persistence | |
| Privilege Escalation | |
| Reconnaissance |
| Feature | Credential Access | Defense Evasion | Exfiltration | Initial Access | Persistence | Privilege Escalation | Reconnaissance |
|---|---|---|---|---|---|---|---|
| history | 0 | 0.14 | 0.1917 | 0.08 | 0.05 | 0.04 | 0 |
| proto | 0 | 0.08 | 0.1232 | 0.05 | 0.03 | 0.02 | 0 |
| service | 0 | 0.14 | 0.1780 | 0.08 | 0.04 | 0.04 | 0 |
| orig_bytes | 0 | 0.14 | 0.1917 | 0.08 | 0.05 | 0.04 | 0 |
| dest_ip_zeek | 0 | 0.14 | 0.2054 | 0.08 | 0.05 | 0.04 | 0 |
| orig_pkts | 0 | 0.14 | 0.1780 | 0.08 | 0.05 | 0.04 | 0 |
| orig_ip_bytes | 0 | 0.14 | 0.2054 | 0.08 | 0.05 | 0.04 | 0 |
| local_resp | 0 | 0.08 | 0.1095 | 0.05 | 0.03 | 0.02 | 0 |
| dest_port_zeek | 0 | 0.07 | 0.095 | 0.05 | 0.03 | 0.03 | 0 |
| duration | 0 | 0.13 | 0.1917 | 0.08 | 0.04 | 0.04 | 0 |
| conn_state | 0 | 0.12 | 0.0821 | 0.08 | 0.04 | 0.03 | 0 |
| resp_pkts | 0 | 0.14 | 0.1780 | 0.08 | 0.05 | 0.04 | 0 |
| resp_ip_bytes | 0 | 0.14 | 0.2054 | 0.08 | 0.05 | 0.04 | 0 |
| src_port_zeek | 0 | 0.14 | 0.2054 | 0.08 | 0.05 | 0.04 | 0 |
| resp_bytes | 0 | 0.14 | 0.1780 | 0.08 | 0.05 | 0.04 | 0 |
| src_ip_zeek | 0 | 0.14 | 0.2054 | 0.08 | 0.05 | 0.04 | 0 |
| local_orig | 0 | 0.07 | 0.095 | 0.03 | 0.01 | 0.01 | 0 |
| missed_bytes | 0 | 0.09 | 0.1369 | 0.04 | 0.02 | 0.01 | 0 |
| Feature | HSJ Freq | SPSA Freq | Square Freq |
|---|---|---|---|
| dest_ip_zeek | 0.580 | 1.000 | 0.074 |
| orig_ip_bytes | 0.580 | 1.000 | 0.074 |
| src_port_zeek | 0.580 | 1.000 | 0.074 |
| src_ip_zeek | 0.580 | 1.000 | 0.074 |
| orig_pkts | 0.580 | 0.937 | 0.070 |
| Service | 0.568 | 0.935 | 0.068 |
| resp_bytes | 0.580 | 0.906 | 0.070 |
| resp_pkts | 0.580 | 0.900 | 0.070 |
| orig_bytes | 0.579 | 0.877 | 0.072 |
| resp_ip_bytes | 0.580 | 0.833 | 0.074 |
| Attack Method | Avg Accuracy | Avg Precision (Macro) | Avg Recall (Macro) | Avg F1 (Macro) | Avg Degradation |
|---|---|---|---|---|---|
| Baseline | 0.966 | 0.958 | 0.970 | 0.963 | - |
| HopSkipJump | 0.013 | 0.011 | 0.013 | 0.012 | 98.7% |
| SPSA | 0.448 | 0.230 | 0.423 | 0.302 | 53.6% |
| Square | 0.489 | 0.318 | 0.466 | 0.359 | 49.4% |
| Attack Method | With IP Features | Without IP Features | IP Advantage |
|---|---|---|---|
| HopSkipJump | 100.0% success | 68.4% success | +31.6% |
| SPSA | 100.0% success | 99.7% success | +0.3% |
| Square | 85.7% success | 85.7% success | +0.0% |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Mink, D.; Simpson, A.; Bagui, S.S.; Bagui, S.C. RandomForestNN Classification for Adversarial AI Black-Box Techniques on MITRE ATT&CK Labeled Data. Electronics 2026, 15, 2598. https://doi.org/10.3390/electronics15122598
Mink D, Simpson A, Bagui SS, Bagui SC. RandomForestNN Classification for Adversarial AI Black-Box Techniques on MITRE ATT&CK Labeled Data. Electronics. 2026; 15(12):2598. https://doi.org/10.3390/electronics15122598
Chicago/Turabian StyleMink, Dustin, Anthony Simpson, Sikha S. Bagui, and Subhash C. Bagui. 2026. "RandomForestNN Classification for Adversarial AI Black-Box Techniques on MITRE ATT&CK Labeled Data" Electronics 15, no. 12: 2598. https://doi.org/10.3390/electronics15122598
APA StyleMink, D., Simpson, A., Bagui, S. S., & Bagui, S. C. (2026). RandomForestNN Classification for Adversarial AI Black-Box Techniques on MITRE ATT&CK Labeled Data. Electronics, 15(12), 2598. https://doi.org/10.3390/electronics15122598

