Adversarial Evasion Attacks Practicality in Networks: Testing the Impact of Dynamic Learning
Adversarial evasion attacks against machine learning–based network intrusion detection systems (ML-NIDS) often exhibit sharply diminished effectiveness when transitioning from controlled laboratory settings to real-world deployments. Method: To address this gap, we construct a threat model grounded in attack trees and propose the first taxonomy of practicality constraints for adversarial attacks targeting ML-NIDS—identifying seven critical limitations, including feature immutability and real-time processing requirements. We conduct systematic experiments on realistic traffic datasets (e.g., CICIDS2017) to evaluate attack viability under operational conditions. Contribution/Results: Our empirical analysis reveals that conventional dynamic retraining alone reduces adversarial attack success rates by over 40%, substantially degrading attack robustness. These findings bridge the chasm between theoretical adversarial research and industrial ML-NIDS deployment, providing both theoretical foundations and actionable guidelines for designing robust, production-ready ML-NIDS.