
@Article{cmes.2026.086180,
AUTHOR = {Abdelouahid Derhab, Adlen Kerboua, Noureddine Seddari, Anis Haniche, Mohammad Mehedi Hassan},
TITLE = {Hierarchical Adversarially-Driven Escalation System (HADES) for Network Intrusion Detection},
JOURNAL = {Computer Modeling in Engineering \& Sciences},
VOLUME = {},
YEAR = {},
NUMBER = {},
PAGES = {{pages}},
URL = {http://www.techscience.com/CMES/online/detail/28126},
ISSN = {1526-1506},
ABSTRACT = {Machine learning has radically transformed network security, enabling intrusion detection systems capable of identifying malicious traffic with near-perfect accuracy on standard benchmarks. However, these systems remain critically vulnerable to adversarial examples—subtly manipulated inputs designed to escape detection—where performance can severely drop under minimal perturbation. This paper introduces the Hierarchical Adversarially-Driven Escalation System (<sc>hades</sc>), a framework that addresses this vulnerability through three coordinated mechanisms. First, dedicated detectors are trained for each network protocol, enabling each model to specialize in specific traffic patterns it will face in practice. Second, these detectors are continuously hardened by simulating an arms race between an attacking agent, which learns to find the most damaging evasion strategies, and a defending model that adapts in response, thus producing classifiers that remain robust across a wide range of attack types. Third, incoming traffic is routed through a cost-aware pipeline that reserves expensive analysis for uncertain or suspicious flows, keeping average processing time at 5.4 ms per batch on normal traffic. <sc>hades</sc> is evaluated on CIC-IDS-2018, a large-scale real-world network dataset, and maintains near-perfect detection accuracy under both normal and adversarial conditions, with robustness verified across nine distinct attack strategies and 95% bootstrap confidence intervals of maximum width 0.0007.},
DOI = {10.32604/cmes.2026.086180}
}



