Home / Journals / CMES / Online First / doi:10.32604/cmes.2026.086180
Special Issues
Table of Content

Open Access

ARTICLE

Hierarchical Adversarially-Driven Escalation System (HADES) for Network Intrusion Detection

Abdelouahid Derhab1,*, Adlen Kerboua2, Noureddine Seddari3,4, Anis Haniche5, Mohammad Mehedi Hassan6
1 Center of Excellence in Information Assurance (CoEIA), King Saud University, Riyadh, Saudi Arabia
2 LGMM Laboratory, University 20 Août 1955-Skikda, Skikda, Algeria
3 LICUS Laboratory, Department of Computer Science, University 20 Août 1955-Skikda, Skikda, Algeria
4 Future Technology Laboratory, University of Parma, Parco Area delle Scienze 181/A, Parma, Italy
5 SecDevOPS Consulting, 61 Rue de Lyon, Paris, France
6 Department of Information Systems, College of Computer and Information Sciences, King Saud University, Riyadh, Saudi Arabia
* Corresponding Author: Abdelouahid Derhab. Email: email
(This article belongs to the Special Issue: Emerging Technologies in Information Security: Modeling, Algorithms, and Applications)

Computer Modeling in Engineering & Sciences https://doi.org/10.32604/cmes.2026.086180

Received 25 May 2026; Accepted 10 August 2026; Published online 31 August 2026

Abstract

Machine learning has radically transformed network security, enabling intrusion detection systems capable of identifying malicious traffic with near-perfect accuracy on standard benchmarks. However, these systems remain critically vulnerable to adversarial examples—subtly manipulated inputs designed to escape detection—where performance can severely drop under minimal perturbation. This paper introduces the Hierarchical Adversarially-Driven Escalation System (hades), a framework that addresses this vulnerability through three coordinated mechanisms. First, dedicated detectors are trained for each network protocol, enabling each model to specialize in specific traffic patterns it will face in practice. Second, these detectors are continuously hardened by simulating an arms race between an attacking agent, which learns to find the most damaging evasion strategies, and a defending model that adapts in response, thus producing classifiers that remain robust across a wide range of attack types. Third, incoming traffic is routed through a cost-aware pipeline that reserves expensive analysis for uncertain or suspicious flows, keeping average processing time at 5.4 ms per batch on normal traffic. hades is evaluated on CIC-IDS-2018, a large-scale real-world network dataset, and maintains near-perfect detection accuracy under both normal and adversarial conditions, with robustness verified across nine distinct attack strategies and 95% bootstrap confidence intervals of maximum width 0.0007.

Keywords

Network intrusion detection; adversarial robustness; adversarial training; protocol-stratified detection; multi-tier cascade; parameter-efficient learning
  • 6

    View

  • 1

    Download

  • 0

    Like

Share Link