Javascript must be enabled to continue!
MORPH-IDS: A Context-Driven Multi-Agent Reinforcement Learning Framework for Drift-Aware Moving Target Defense in Adversarial-Robust Intrusion Detection
View through CrossRef
In the rapidly evolving cybersecurity landscape, Machine Learning (ML)-based Network Intrusion Detection Systems (NIDS) have become essential for detecting sophisticated threats, yet they are increasingly vulnerable to adversarial evasion attacks and concept drift caused by adaptive attackers. Existing ensemble-based defenses optimize for instantaneous accuracy without incorporating drift signals, while drift adaptation methods remain reactive rather than proactive against strategic adversaries. Therefore, we propose MORPH-IDS (Moving Objective Reinforcement Learning framework for Proactive and Hardened Intrusion Detection Systems), which integrates Moving Target Defense (MTD) with Reinforcement Learning (RL) to mitigate these risks by creating a dynamic, unpredictable attack surface that invalidates adversaries’ reconnaissance and increases attack costs. The core of MORPH-IDS is a multi-agent RL (MARL) setup modeled as a Markov Game, featuring two competing agents in a co-evolutionary environment. The defender agent, implemented as a Dueling Double Deep Q-Network (D3QN), learns to intelligently select and combine strategies from a diverse model pool. Conditioned on a carefully designed a low-dimensional drift embedding, which quantifies distributional shifts, temporal dynamics, and poisoning indicators, the agent dynamically orchestrates robust ensembles during periods of high concept drift and accuracy-optimal methods under stable conditions, thereby creating a non-stationary, unpredictable moving target defense. To enable proactive adaptation, an Adversarial Drift Injection (ADI) scheduler—driven by the adversarial agent—proactively synthesizes diverse drift and evasion scenarios during training. This co-evolutionary process teaches the defender to interpret contextual signals effectively, generalize to unseen adversarial threats, and mitigate catastrophic forgetting through integrated continual learning mechanisms. Empirical evaluation on three benchmarks, including CIC-IDS2017, CIC-IDS2019, CIC-APT-IIoT-2024 dataset, demonstrates that MORPH-IDS improves robustness of NIDS against both concept drift and adversarial attacks. Specifically, it outperforms recent baselines such as Apollon by over 15% in F1-score on CIC-IDS2017 and improves adversarial robustness by up to 22.65% against black-box attacks. Furthermore, on the CIC-APT-IIoT-2024 dataset, the system detects 91.53% of APT patterns while maintaining stable performance under temporal drift. The results underscore the effectiveness of drift-aware MTD for risk mitigation in real-time defensive adaptation.
Title: MORPH-IDS: A Context-Driven Multi-Agent Reinforcement Learning Framework for Drift-Aware Moving Target Defense in Adversarial-Robust Intrusion Detection
Description:
In the rapidly evolving cybersecurity landscape, Machine Learning (ML)-based Network Intrusion Detection Systems (NIDS) have become essential for detecting sophisticated threats, yet they are increasingly vulnerable to adversarial evasion attacks and concept drift caused by adaptive attackers.
Existing ensemble-based defenses optimize for instantaneous accuracy without incorporating drift signals, while drift adaptation methods remain reactive rather than proactive against strategic adversaries.
Therefore, we propose MORPH-IDS (Moving Objective Reinforcement Learning framework for Proactive and Hardened Intrusion Detection Systems), which integrates Moving Target Defense (MTD) with Reinforcement Learning (RL) to mitigate these risks by creating a dynamic, unpredictable attack surface that invalidates adversaries’ reconnaissance and increases attack costs.
The core of MORPH-IDS is a multi-agent RL (MARL) setup modeled as a Markov Game, featuring two competing agents in a co-evolutionary environment.
The defender agent, implemented as a Dueling Double Deep Q-Network (D3QN), learns to intelligently select and combine strategies from a diverse model pool.
Conditioned on a carefully designed a low-dimensional drift embedding, which quantifies distributional shifts, temporal dynamics, and poisoning indicators, the agent dynamically orchestrates robust ensembles during periods of high concept drift and accuracy-optimal methods under stable conditions, thereby creating a non-stationary, unpredictable moving target defense.
To enable proactive adaptation, an Adversarial Drift Injection (ADI) scheduler—driven by the adversarial agent—proactively synthesizes diverse drift and evasion scenarios during training.
This co-evolutionary process teaches the defender to interpret contextual signals effectively, generalize to unseen adversarial threats, and mitigate catastrophic forgetting through integrated continual learning mechanisms.
Empirical evaluation on three benchmarks, including CIC-IDS2017, CIC-IDS2019, CIC-APT-IIoT-2024 dataset, demonstrates that MORPH-IDS improves robustness of NIDS against both concept drift and adversarial attacks.
Specifically, it outperforms recent baselines such as Apollon by over 15% in F1-score on CIC-IDS2017 and improves adversarial robustness by up to 22.
65% against black-box attacks.
Furthermore, on the CIC-APT-IIoT-2024 dataset, the system detects 91.
53% of APT patterns while maintaining stable performance under temporal drift.
The results underscore the effectiveness of drift-aware MTD for risk mitigation in real-time defensive adaptation.
Related Results
An enhanced ensemble defense framework for boosting adversarial robustness of intrusion detection systems
An enhanced ensemble defense framework for boosting adversarial robustness of intrusion detection systems
Abstract
Machine learning (ML) and deep neural networks (DNN) have emerged as powerful tools for enhancing intrusion detection systems (IDS) in cybersecurity. However, re...
Mobile Agent (MA) Based Intrusion Detection Systems (IDS): A Systematic Review
Mobile Agent (MA) Based Intrusion Detection Systems (IDS): A Systematic Review
An Intrusion Detection System (IDS) identifies the attacks by analysing the events, considered undesirable from a security perspective, in systems and networks. It is necessary for...
ProDef-MDS: A Proactive Defense Mechanism Protecting Malware Detection Systems from Adversarial Attacks
ProDef-MDS: A Proactive Defense Mechanism Protecting Malware Detection Systems from Adversarial Attacks
Malware threatens cybersecurity by enabling data theft, unauthorized access, and extortion. Traditional malware detection systems (MDS) struggle with the increasing volume and comp...
Cyber defense in breadth: Modeling and analysis of integrated defense systems
Cyber defense in breadth: Modeling and analysis of integrated defense systems
Cybersecurity is one of most critical concerns for any organization, as frequency and severity of cyber attacks constantly increase, resulting in loss of vital assets and/or servic...
Detection of Malicious Flows in the Software-Defined Networks by Using Statistical Flow Analysis-Based Intrusion Detection System
Detection of Malicious Flows in the Software-Defined Networks by Using Statistical Flow Analysis-Based Intrusion Detection System
Abstract
Specifically, in the past few years, internet traffic has grown rapidly, evolving modern network technologies with hybrid telecommunication systems and conventiona...
Smart Detection: Reinforcement Learning for Network Intrusion Defense
Smart Detection: Reinforcement Learning for Network Intrusion Defense
As cyber threats grow in complexity, the demand for intelligent and adaptive intrusion detection systems (IDS) is more critical than ever. Traditional machine learning models, whil...
An Efficient Network Intrusion Detection and Classification System using Machine Learning
An Efficient Network Intrusion Detection and Classification System using Machine Learning
In today's digital landscape, network security is of paramount importance, with intrusion detection systems (IDS) playing a crucial role in protecting sensitive data from maliciou...
SGAN-IDS: Self-Attention-Based Generative Adversarial Network against Intrusion Detection Systems
SGAN-IDS: Self-Attention-Based Generative Adversarial Network against Intrusion Detection Systems
In cybersecurity, a network intrusion detection system (NIDS) is a critical component in networks. It monitors network traffic and flags suspicious activities. To effectively detec...

