Diff-DDoS: Realistic cyber-physical attack synthesis and robust detection for 5G-enabled CPS using tabular diffusion models
Date Issued
2026
Publisher
Institute of Electrical and Electronics Engineers (IEEE)
ISSN
1551-3203
1941-0050
Citation
IEEE Transactions on Industrial Informatics, 2026, pp. 1-11.
Description
Open access
Type
Peer Reviewed Journal Article
Abstract
Deep learning-based distributed denial-of-service (DDoS) detectors for 5G-enabled cyber-physical systems face two challenges: scarce real-world labeled attack data and the unrealism of naive synthetic substitutes, which limit robustness against adaptive adversaries. Detectors trained on hand-crafted attacks with fixed scaling multipliers degrade catastrophically—F1-score drops of ∼47%–100% depending on scenario—when confronted with realistic, distribution-preserving samples. We propose Diff-DDoS, a three-phase framework for realistic attack synthesis and robust detection using tabular diffusion models. Phase 1 establishes a baseline convolutional neural network cell-level detector on spatiotemporal grids derived from call detail records (CDRs). Phase 2 trains a tabular denoising diffusion probabilistic model (TabDDPM) on normal CDR aggregates to generate realistic attacks, exposing detector vulnerabilities. Phase 3 introduces adversarial diffusion training (ADT), which applies inverse classifier guidance to iteratively generate hard yet distribution-preserving adversarial samples until the detector converges. On a real-world Milano CDR dataset across SMS-flooding, silent-call, Internet-signaling, and blended scenarios, ResNet50 with ADT recovers F1-scores of 79.62% (silent-call), 100% (Internet), and 92.79% (blended) while retaining near-perfect multiplier-test F1 on most scenarios. We further benchmark ADT against gradient-based adversarial training, CTGAN, and fixed-multiplier baselines under identical iterative training and validation-based threshold calibration; after calibration, ADT reaches 100% SMS F1 versus 47.3% for CTGAN and attains silent-call F1 on par with the strongest gradient-based adversarial-training baseline. SMS flooding remains challenging for lightweight architectures, though calibration enables near-perfect ResNet50 detection. These results establish tabular diffusion models as a practical tool for stress-testing and hardening intrusion detectors in data-scarce 5G cyber-physical deployments.
Subjects
Loading...
Availability at HKSYU Library

