Integrating Lifecycle Robustness in Machine Learning Models for Cybersecurity
AdvGuard is a highly scalable, modular ecosystem designed to embed threat simulation and dynamic defense generation natively within an MLOps pipeline. By focusing on tabular network telemetry, AdvGuard ensures that modern intrusion detection systems are resilient against cutting-edge Adversarial Machine Learning (AML) exploits.
Important
Why AdvGuard? As deep learning architectures rapidly replace conventional rule-based filters in Security Operations Centers (SOCs), their vulnerability to mathematically engineered input distortions has become a severe operational hazard. AdvGuard provides autonomous, real-time threat resistance.
| Paper | Venue | Status |
|---|---|---|
| Proactive Adversarial Defense Framework Integrating Lifecycle Robustness in Machine Learning Models for Cybersecurity | IEEE CSR 2026 — Lisbon, Portugal · August 3–5 | ✅ Presented |
Warning
Evaluation-status caveat (2026-09-06). The 93.00% robust accuracy at
ε=0.15 figure cited below reflects the retired one-shot gradient-snapped
evaluation convention. It is not a valid categorical robustness measure:
the categorical snap is inactive under the published defaults, so the figure
measures a K=0 continuous-only attack with learned categorical gradients
masked by non-differentiable argmax snapping
(backend/app/ml/attacks/pgd.py). The canonical protocol is now exhaustive
mixed-norm enumeration (ADR-001 in docs/01-documentation/adrs/), and the
original paper's 29.10% NSL-KDD figure was retracted. Do not cite either
number as a robustness claim without first running the canonical evaluator.
Introduces DACM (Discrete Adversarial Constraint Mapping) — maps continuous adversarial gradients onto structurally valid discrete categorical boundaries, enabling real-world executable payloads against tabular network telemetry. Validated on NSL-KDD and CICIDS2017; adversarially trained model sustains 93.00% robust accuracy at ε = 0.15. Implementation: AdvGuard.
-
🎯 Multi-Faceted Threat Simulation Backend
A PyTorch-powered evaluation engine capable of generating rapid gradient shifts (FGSM, PGD), targeted feature mapping (JSMA), and complex distance-minimization routines. -
🔐 Discrete Adversarial Constraint Mapping (DACM)
Our novel algorithmic process forces continuous mathematical noise to snap back to valid categorical boundaries (via Euclidean distance minimization), ensuring adversarial cyber-payloads remain structurally executable in network parsers. -
⚡ Decoupled Event-Driven MLOps Integration
Evaluates algorithmic threats efficiently by separating GPU-heavy threat generation from lightweight UI dashboards via asynchronous message brokering.
AdvGuard physically separates UI components from computationally intensive threat generation to ensure enterprise-grade scalability.
graph TD
%% Define styles
classDef ui fill:#000000,stroke:#333,stroke-width:2px,color:#fff
classDef api fill:#0f52ba,stroke:#333,stroke-width:2px,color:#fff
classDef gpu fill:#e32636,stroke:#333,stroke-width:2px,color:#fff
classDef db fill:#006600,stroke:#333,stroke-width:2px,color:#fff
classDef msg fill:#ff9900,stroke:#333,stroke-width:2px,color:#000
A[🖥️ Next.js Interactive Dashboard]:::ui <-->|REST / WebSockets| B
B[🌐 FastAPI Gateway]:::api
B -->|Fetch Weights| C[(💾 S3 / Local Storage)]:::db
B -->|Async Triggers| D((🐇 RabbitMQ)):::msg
D -->|Consume Tasks| E[🔥 PyTorch Simulation Engine]:::gpu
E -->|Write Hardened .pth| C
E -->|Real-time Diagnostics| B
- Frontend UI: A Next.js dashboard providing interactive diagnostics and real-time metric tracking.
- FastAPI Gateway: Handles configuration injection and orchestrates the microservices logic.
- PyTorch Simulation Engine: A GPU-bound microservice that constructs and evaluates mathematically engineered payloads against targeted tensors.
Empirical evaluations conducted on the NSL-KDD and CICIDS2017 datasets confirm the necessity and efficacy of the AdvGuard platform.
When exposed to an aggressive perturbation limit of ϵ = 0.15 via FGSM:
Warning
Baseline Collapse
Unmitigated models experienced a massive accuracy drop from 98.60% down to 39.20%.
Caution
Ensemble Inadequacy
Standard multi-model consensus provided highly superficial protection, collapsing to 73.50% under heavy strain due to adversarial transferability.
Tip
AdvGuard Hardening (Success!)
The architecture subjected to integrated adversarial training sustained a robust accuracy of 93.00%, effectively crippling evasion success rates without diminishing baseline predictive capabilities.
Standard for all robustness claims. Full decision in
docs/01-documentation/adrs/001-canonical-exhaustive-evaluation.md(ADR-001); historical evidence indocs/02-postmortems/.
Pros
- Eliminates invalid-state artifacts (no fractional one-hots, no gradient-masking
argmax). - Guarantees coverage of the discrete categorical state space within budget
$K$ . - Faithful reproduction yields 40.36% robust accuracy for the hardened NSL-KDD model (vs. the retracted 29.10%).
Cons
- Runtime scales combinatorially with
$K$ and the number of categorical groups (UNSW-NB15,$K=2$ : 667 states per sample). - Memory bandwidth is the bottleneck; GPU parallelism is essential for large datasets.
Neutral
- Inner optimization remains PGD-based (no global certificate).
- Random-start PGD adds run-to-run variance; pre-registered tolerances live in
verification/compare_exh_fresh.py.
- Python 3.10+
- Node.js 18+
- PyTorch (CUDA supported recommended)
1. Train the Baseline Models
Trains the base MLP and the Ensemble array on your telemetry data.
make train2. Launch the Dashboard & API
Spins up both the Next.js frontend and the FastAPI backend.
make dev3. Monitor via UI
Navigate to http://localhost:3000 to trigger on-the-fly FGSM/PGD attacks and simulate AdvGuard's real-time defensive re-calibrations.
- Desai Prathmesh Prakash
This project is licensed under the Apache License 2.0 - see the LICENSE file for details.