Skip to content
Open access

Adversarial Attack Detection in Wireless Networks Using Deep Learning Based Capsule Networks

Jul 2026 · Journal of Trends in Computer Science and Smart Technology · Vol 8, pp. 579-602 · 0 citations · 41 references

TL;DR

A Capsule Network (CapsNet)-based framework detecting adversarial attacks in wireless networks is proposed, which uses RF-aware capsule representations and dynamic routing to improve hierarchical feature learning and robustness against adversarial perturbations.

Abstract

The vulnerability of wireless networks to misclassification and security oversight is increased by adversarial attacks using Deep Learning (DL)-based Intrusion Detection Systems (IDS). Because they are unable to distinguish small fluctuations in signal data and retain spatial hierarchy, traditional neural networks prefer Convolutional Neural Networks (CNNs) and Recurrent Neural Networks (RNNs), which are highly prone to adversarial perturbations. In this research, a Capsule Network (CapsNet)-based framework detecting adversarial attacks in wireless networks is proposed. The network uses RF-aware capsule representations and dynamic routing to improve hierarchical feature learning and robustness against adversarial perturbations. To successfully search for adversarial distortion, the proposed model extracts significant network traffic features, encodes spatial hierarchy via primary and digit capsules, and uses a reconstruction loss function. To improve the model's robustness against sophisticated attack tactics, an exploratory quantum-assisted CapsNet implementation for preliminary investigation is also included. Experimental evaluation on benchmark wireless intrusion datasets shows that CapsNets outperform conventional CNNs and Long Short-Term Memory (LSTM) models, achieving 98.3% accuracy under normal conditions and maintaining 91.3% precision even under adversarial attack, compared to 87.5% and 72.4% for CNNs and 90.2% and 78.6% for LSTMs, respectively. In addition, compared with traditional DL models, CapsNets show a 34% improvement in robustness metrics. The proposed CapsNet system achieved 98.3% detection accuracy and a reduced False Positive Rate across several adversarial attack scenarios.

Read PDF

Similar papers

Open access Aug 2026

Adversarial Transferability in AI-based Network Intrusion Detection: A Comparative Study of ANN and CNN Models

Experimental results indicate that CNN-based NIDS are more vulnerable to adversarial attacks than ANN-based models, with adversarial examples successfully transferring across architectures, highlighting the critical risks associated with adversarial transferability.

Aasim Zafar, Shazra Wali, S. B. U. Haque · 0 citations
Open access Aug 2026

Enhanced Robustness in Neural Network Models against Adversarial Attacks and their Performance Analysis

Machine learning models, particularly deep learning architectures, achieve high performance in prediction tasks but remain susceptible to adversarial attacks. This study aims to enhance the robustness of Convolutional Neural Networks (CNNs), Deep Neural Networks (DNNs), and Recurrent Neural Networks (RNNs), thereby improving the security of machine learning systems. A three-step approach is adopted. First, benign sample classification is performed using the MNIST benchmark dataset. Second, adversarial attacks, namely Projected Gradient Descent (PGD), DeepFool (DF), and the Fast Gradient Sign Method (FGSM), are launched on the trained models, resulting in significant performance degradation. Based on the biased outputs induced by adversarial perturbations, an adversarial detection model is subsequently established. Third, to counteract these attacks, various defense strategies, including adversarial training, defensive distillation, autoencoder-based denoising, ensemble methods, and feature squeezing are employed and evaluated using standard performance metrics and graphical analyses. The results indicate that, in the absence of defense mechanisms, PGD attacks lead to accuracy drops of approximately 27% in CNNs, 83% in DNNs, and 90% in RNNs, demonstrating severe model vulnerabilities. However, when defense strategies are applied, all models recover to an accuracy of at least 98.9%, with adversarial training improving performance under attack by up to 90%. Among the evaluated models, CNNs exhibit the highest baseline robustness, whereas DNNs and RNNs rely more heavily on defense mechanisms to maintain performance. These findings provide valuable insights into the development of secure and resilient machine learning systems capable of mitigating adversarial threats.

Surekha M., A. K. Sagar, Vineeta Khemchandani · 0 citations
Open access Jul 2026

Detecting adversarial evasion in deep learning intrusion detection systems using explainable AI

Deep learning based network intrusion detection systems (IDS) can achieve strong traffic classification performance, but their resilience to adversarial manipulation remains a critical concern. This study evaluates the adversarial robustness of Long Short-Term Memory (LSTM) and Gated Recurrent Unit (GRU) models in a multiclass intrusion detection setting using the Train_Test_Network dataset with ten traffic classes. The models were trained on true sliding flow-window sequences under a unified preprocessing pipeline to support fair comparison. Adversarial robustness was first assessed under a white-box Fast Gradient Sign Method (FGSM) setting and then broadened through additional FGSM and Projected Gradient Descent (PGD) stress testing. SHapley Additive exPlanations (SHAP) were further used to analyse explanation instability under clean and adversarial conditions, and explanation-drift features were evaluated as a secondary adversarial detection signal. Under clean evaluation, both models achieved strong and nearly identical performance, with accuracies of 0.9614 for LSTM and 0.9615 for GRU and weighted F1-scores of 0.9597 and 0.9598, respectively. Under the main FGSM condition, performance declined substantially: the LSTM achieved adversarial accuracy of 0.6094 and weighted F1-score of 0.6290 with an evasion rate of 37.38%, while the GRU achieved adversarial accuracy of 0.5130 and weighted F1-score of 0.5690 with an evasion rate of 47.02%. The broader robustness sweep showed that iterative PGD exposed stronger fragility than FGSM alone. SHAP analysis indicated that adversarial perturbation altered both prediction outcomes and local explanation structure. A learned explanation-driven detector improved over the rule-based baseline, while larger-scale validation confirmed that explanation drift remained informative, though not perfectly separable, at broader scale. Overall, the results show that strong clean performance does not imply adversarial robustness, and that explanation drift provides a useful auxiliary signal for adversarial monitoring in recurrent IDS models.

Elijah M. Maseno, Yanxia Sun, Zenghui Wang · 0 citations
Review Aug 2026

A Comprehensive Review on Adversarial Attacks and Detection Techniques in Deep Learning Models for Image Analysis

The research methodology involved a systematic literature review using the Scopus database, adhering to Preferred Reporting Items for Systematic Reviews and Meta-Analyses guidelines, and focusing on recent advancements in attack and defence techniques.

Reeti Jaswal, Vikas Khullar, Surya Narayan Panda · 0 citations
Conference Jul 2026

An Adaptive Defense Framework for Enhancing Adversarial Robustness in Deep Learning-based Network Intrusion Detection Systems

This study investigated the robustness of deep learning-based Network Intrusion Detection Systems (NIDS) against adversarial attacks by proposing a confidence-aware adaptive defense framework. The proposed approach integrates a baseline feedforward neural network, an adversarially trained robust model, and an adversarial detector to dynamically select the most appropriate prediction path based on detector confidence. Experimental evaluation under single-step, multi-step, and adaptive adversarial attack scenarios demonstrated that the framework significantly improves detection robustness while maintaining high classification accuracy on clean network traffic. The adaptive fusion strategy effectively mitigates the impact of adversarial perturbations, reducing misclassification rates and enhancing the reliability of intrusion detection in dynamic cybersecurity environments. These findings confirm that confidence-guided adaptive defense mechanisms provide a practical solution for strengthening the resilience of AI-driven NIDS against evolving attack strategies. However, the proposed framework was evaluated using controlled experimental settings and specific attack models, which may not fully represent the diversity of real-world cyber threats. Future work will focus on validating the framework in large-scale operational networks, extending it to advanced zero-day and adaptive attacks, and investigating lightweight deployment strategies for real-time edge and cloud-based cybersecurity applications.

Aastha Ahlawat, Anurag Goel · 0 citations
Preprint Jul 2026

A Multi-Model Hybrid Defense Approach Against White-box Adversarial Attacks in Computer Network Traffic

It is crucial to safeguard computer networks from evolving network security threats and unknown cyberattacks. An essential tool for protecting computer networks against unknown cyber threats is Network Intrusion Detection System (NIDS). However, NIDS faces a major security concern due to its susceptibility to adversarial attacks. Adversarial attacks aim to deceive NIDS by crafting and injecting adversarial examples into the system. These adversarial inputs can deceive the NIDS into misclassifying benign network traffic as malicious. We developed a resilient hybrid defense mechanism aimed to mitigate the impact of two potent adversarial attacks: Fast Gradient Sign Method (FGSM) and Carlini&Wagner (C&W) attack. Our hybrid defense approach leverages the combined strength of two heuristic defense methods: Adversarial Training (AT) and Gaussian Data Augmentation (GDA). GDA provides multi-directional defense, while AT enhances NIDS robustness against specific adversarial vectors. Under pre-attack scenarios, NIDS demonstrated good accuracy and f1-score. However, in the post-attack scenario, its accuracy significantly dropped under FGSM and C&W attacks (0.2649 and 0.4961, respectively). Our proposed hybrid defense method effectively mitigated these adversarial threats, with post-defense accuracy of 96.57% and 89.20% for FGSM and C&W attacks. We evaluated the defense strategy across a range of epsilon and confidence noise factor values (ranging from 0.0001 to 0.0009). This research provides a good direction for future researchers in the emerging area of adversarial machine learning from a security perspective.

Khushnaseeb Roshan · 0 citations