Synthetic Network Packet Generation through Statistical Learning and Genetic Algorithms
This study addresses the limitations of existing IoT intrusion detection datasets, which commonly suffer from fixed attack categories and extreme class imbalance, as well as the inability of current generative models to guarantee the physical validity of synthesized packets. To overcome these challenges, the paper proposes two novel synthesis approaches that embed hard validity constraints directly into the generation process: a statistical learning method based on PCA and dual anomaly detection boundaries, and a genetic algorithm that formulates data generation as a multi-objective optimization problem. Innovatively integrating dual anomaly gating, feature-range clamping, and an independent validation mechanism, both methods significantly enhance the fidelity and validity of synthetic data. Evaluated on the ACI IoT 2023 dataset, they achieve average anomaly rates of 1.20% (at 1,091 pkt/s) and 0.62% (at 5.7 pkt/s), respectively, and successfully expand ARP spoofing samples to 1,000 instances—a 200-fold increase.