PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
June 1, 2026Array0 citationsOpen Access

HAPMA: A Hybrid Adaptive Protocol Morphing Attack Framework for Robust Deep Learning Intrusion Detection

View Full Paper
MKM. KohliICIndu Chhabra

Key Points

  • The aim is to improve deep learning models for detecting network intrusions by addressing class imbalance and representing diverse attack patterns.
  • Developed Hybrid Attack Pattern Morphing and Augmentation (HAPMA) framework using CIC-IDS2017 dataset.
  • Integrated statistical blending, Gaussian Mixture Model sampling, and feature mutation techniques.
  • Trained deep learning models including CNN, DNN, and LSTM on HAPMA-augmented data for performance comparison.
  • HAPMA-CNN doubles macro F1-score compared to baseline models.
  • Improved Matthews Correlation Coefficient while maintaining overall accuracy of approximately 99%.
  • Demonstrated realistic synthetic data generation through low Jensen Shannon Divergence and generalization in cross-validation.

Abstract

Network intrusion detection systems frequently suffer from severe class imbalance and limited representation of minority attack patterns, restricting deep learning models' ability to detect emerging web-based threats. This work proposes Hybrid Attack Pattern Morphing and Augmentation (HAPMA), a multi-mechanism feature-level synthetic augmentation framework designed to generate diverse, novel, and realistic web attack variants using the CIC-IDS2017 dataset. HAPMA integrates statistical blending, Gaussian Mixture Model (GMM) sampling, pairwise interpolation, adversarial micro-perturbations, and protocol-aware feature mutation to construct novel composite intrusion archetypes that capture hybridised, adaptive, and protocol-level attack characteristics. Deep learning models including Deep Neural Networks (DNN), Convolutional Neural Networks (CNN), and Long Short-Term Memory (LSTM) are trained on HAPMA-augmented data and compared against baseline models and Synthetic Minority Oversampling (SMOTE), augmentation techniques. Results show balanced gains, HAPMA-CNN doubles macro F1-score, improves Matthews Correlation Coefficient (MCC), while maintaining high overall accuracy (∼99%). Low Jensen Shannon Divergence confirms synthetic realism; cross validation on CIC IDS 2018 demonstrates generalization. Additional evaluation on UNSW-NB 15 benchmark, further support HAPMA, yielding constant gains in macro-F1 and balanced accuracy in native feature and harmonized feature settings. The HAPMA framework presents a systematic, layered, reproducible, and protocol-sensitive augmentation strategy, offering practical minority-class enhancement for existing IDS workflows rather than complete solutions.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Kohli et al. (2026) studied this question.

synapsesocial.com/papers/6a1d21e502fbce9130637d21https://doi.org/10.1016/j.array.2026.100949
Ask AI
Helpful
Bookmark
Share
View Full Paper