ROBUSTNESS OF TREE-BASED MACHINE LEARNING ALGORITHMS AGAINST ADVERSARIAL EXAMPLES IN NETWORK INTRUSION DETECTION SYSTEM (NIDS) A COMPARATIVE STUDY OF RANDOM FOREST AND XGBOOST

dc.contributor.advisorTriwinarko, Andy
dc.contributor.authorSirait, David Hamonangan
dc.date.accessioned2026-08-18T02:14:20Z
dc.date.issued2026-07-22
dc.description.abstractThe security of machine learning-based Network Intrusion Detection Systems (NIDS) is increasingly threatened by Adversarial Machine Learning (AML) attacks capable of manipulating input data to deceive models and evade detection. The RobEns study [1] built a comprehensive adversarial ensemble framework evaluating four black-box attacks against six models on IoT traffic data, ye left three research gaps unresolved: the accuracy of the substitute model used to represent Random Forest was never validated, XGBoost was excluded from the evaluation entirely, and the single-step adversarial training scheme suffered from label leakage. This study addresses those gaps through a direct comparative analysis between Random Forest and XGBoost on the ToN-IoT dataset, using two complementary black-box attack techniques, ZOO Attack and Genetic Adversarial Attack (GAA), together with Feature Squeezing as a data-level defense mechanism. The methodology comprises four phases: data collection and preprocessing, baseline model training, adversarial attack implementation under two feature-encoding schemes, and defense implementation with comparative evaluation using six metrics: Standard Accuracy (SA), Adversarial Accuracy (AA), Robust Accuracy (RA), Attack Success Rate (ASR), Robust Accuracy Gain (RAG), and SA Preservation Rate (SPR). Results show that both models strongly resist ZOO Attack (ASR=0%) owing to their non differentiable, piecewise-constant decision structure, but respond very differently to GAA: Random Forest retains strong robustness under One-Hot Encoding (ASR=0%) yet becomes highly vulnerable under Ordinal Encoding with StandardScaler (ASR = 99,90%), whereas XGBoost remains consistently vulnerable (ASR = 100%) regardless of the encoding scheme. Feature Encoding (RAG = 28.87%) but offers little benefit in the continuous feature space. These findings indicate that feature representation is as critical as model architecture in determining adversarial robustness, offering practical guidance for designing more resilient tree based NIDS.
dc.identifier.citationIEEE
dc.identifier.kodeprodiKODEPRODI57302#Rekayasa Keamanan Siber
dc.identifier.nidnNIDN1007107901
dc.identifier.nimNIM4332201062
dc.identifier.urihttps://repository.polibatam.ac.id//handle/PL29/5178
dc.language.isoother
dc.publisherPoliteknik Negeri Batam
dc.subjectAdversarial machine learning
dc.subjectfeature squeezing
dc.subjectrandom forest
dc.subjectxgboost
dc.subjectzoo attack
dc.titleROBUSTNESS OF TREE-BASED MACHINE LEARNING ALGORITHMS AGAINST ADVERSARIAL EXAMPLES IN NETWORK INTRUSION DETECTION SYSTEM (NIDS) A COMPARATIVE STUDY OF RANDOM FOREST AND XGBOOST
dc.typeArticle

Files

Original bundle

Now showing 1 - 4 of 4
Loading...
Thumbnail Image
Name:
Borang_Publikasi.pdf
Size:
357.04 KB
Format:
Adobe Portable Document Format
Loading...
Thumbnail Image
Name:
Lembar_Pengesahan.pdf
Size:
377.67 KB
Format:
Adobe Portable Document Format
Loading...
Thumbnail Image
Name:
4332201062_Article.pdf
Size:
1.13 MB
Format:
Adobe Portable Document Format
Loading...
Thumbnail Image
Name:
4332201062_Poster_Tugas_Akhir.pdf
Size:
143.3 KB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: