Digitala Vetenskapliga Arkivet

Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Synthetic Data Augmentation for Intrusion Detection: Evaluating WGAN-GP for Class Imbalance and Novel Attack Detection
Blekinge Institute of Technology, Faculty of Computing, Department of Computer Science.
2026 (English)Independent thesis Basic level (university diploma), 12 credits / 18 HE creditsStudent thesis
Abstract [en]

Background. Society has become increasingly reliant on digital infrastructure, and with it an increasing importance is placed on cyber security. Intrusion detection systems (IDSs) play a crucial role in modern cyber security in mitigating the risk of cyber-attacks. However, the effectiveness of IDS models is constrained by the availability and quality of training data. Network flow datasets can be difficult to acquire due to their proprietary and sensitive nature, and those that are available frequently suffer from large class imbalances. This research aims to explore options for solving these problems through synthetic data generation.

Objectives. This research investigates whether the Wasserstein Generative Adversarial Network with Gradient Penalty (WGAN-GP) can be used to generate high-fidelity synthetic data to alleviate class imbalances in an IDS context, and whether this augmentation can lead to improved detection inpreviously unseen and rare attack types.

Methods. A WGAN-GP was trained per attack label on the CIC-IDS2017 dataset. Generated synthetic data had its fidelity rigorously tested using the Kolmogorov-Smirnov metric (KS), Pearson’s correlation coefficient, Kernel Density Estimation plots (KDE), and Train on Synthetic, Test on Real (TSTR) evaluation. Labels for which generated synthetic data was acceptable were included in an augmented classification pipeline, which was compared to a baseline pipeline using an ensemble of classifiers consisting of a Logistic Regression (LR) model, an XGBoost model, and a Multilayer Perceptron (MLP) model. These were evaluated on classification metrics, calibration plots, low resource experiment, and Area Under the Receiver Operating Characteristics Curve (ROC-AUC). A withheld label experiment was conducted at the same time in order to evaluate generalization and unseen attack detection.

Results. Synthetic data generation succeeded for five out of eight labels, with varying fidelity results across labels. Downstream classification results produced negligible differences between augmented and baseline pipelines, largely attributed to problematic network flow data characteristics as well as dataset limitations. Synthetic data did not provide a noticeable improvement in previously unseen attacks.

Conclusions. The synthetic data produced by WGAN-GP did not yield any meaningful improvements for either IDS classification performance or generalizability for unseen attacks. Results suggest that particularly problematic network data features such as large outliers, heavy skews, near-zero value clusters, and multimodality present significant challenges for the WGAN-GP generator and achieving high-fidelity synthetic data in this type of context likely requires extensive feature- and label-specific tuning. Future work should explore more targeted feature-engineering, more aggressive augmentation approaches, a hybrid WGAN-GP approach that combines global and class-specific generation, and evaluating datasets with less discriminative feature separation.

Place, publisher, year, edition, pages
2026. , p. 29
Keywords [en]
WGAN-GP, synthetic data generation, intrusion detection system, CIC-IDS2017, class imbalance
National Category
Computer Sciences
Identifiers
URN: urn:nbn:se:bth-30161OAI: oai:DiVA.org:bth-30161DiVA, id: diva2:2084329
Subject / course
DV1583 Degree Project for Bachelor of Science in Engineering (Computer Science)
Educational program
Bachelor of Science in Engineering: Computer Security
Supervisors
Examiners
Available from: 2026-08-06 Created: 2026-07-04 Last updated: 2026-08-06Bibliographically approved

Open Access in DiVA

fulltext(5074 kB)14 downloads
File information
File name FULLTEXT01.pdfFile size 5074 kBChecksum SHA-512
dd6119ff85bdb40e80743ccabe5c78b0bcc4b63869d365e90fbe7e527175cbca72b630dac0765bc8652d1218b0314291b36638f198ca8d3a44485cd02c8218c3
Type fulltextMimetype application/pdf

By organisation
Department of Computer Science
Computer Sciences

Search outside of DiVA

GoogleGoogle Scholar
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 71 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf