Hussain, BilalBilalHussainTang, XiaoXiaoTangDu, QingheQingheDuLi, TanTanLiDr. AZHAR MuhammadKhan, DanistaDanistaKhan2026-09-232026-09-232026IEEE Transactions on Industrial Informatics, 2026, pp. 1-11.1551-32031941-0050http://hdl.handle.net/20.500.11861/30051Open accessDeep learning-based distributed denial-of-service (DDoS) detectors for 5G-enabled cyber-physical systems face two challenges: scarce real-world labeled attack data and the unrealism of naive synthetic substitutes, which limit robustness against adaptive adversaries. Detectors trained on hand-crafted attacks with fixed scaling multipliers degrade catastrophically—F1-score drops of ∼47%–100% depending on scenario—when confronted with realistic, distribution-preserving samples. We propose Diff-DDoS, a three-phase framework for realistic attack synthesis and robust detection using tabular diffusion models. Phase 1 establishes a baseline convolutional neural network cell-level detector on spatiotemporal grids derived from call detail records (CDRs). Phase 2 trains a tabular denoising diffusion probabilistic model (TabDDPM) on normal CDR aggregates to generate realistic attacks, exposing detector vulnerabilities. Phase 3 introduces adversarial diffusion training (ADT), which applies inverse classifier guidance to iteratively generate hard yet distribution-preserving adversarial samples until the detector converges. On a real-world Milano CDR dataset across SMS-flooding, silent-call, Internet-signaling, and blended scenarios, ResNet50 with ADT recovers F1-scores of 79.62% (silent-call), 100% (Internet), and 92.79% (blended) while retaining near-perfect multiplier-test F1 on most scenarios. We further benchmark ADT against gradient-based adversarial training, CTGAN, and fixed-multiplier baselines under identical iterative training and validation-based threshold calibration; after calibration, ADT reaches 100% SMS F1 versus 47.3% for CTGAN and attains silent-call F1 on par with the strongest gradient-based adversarial-training baseline. SMS flooding remains challenging for lightweight architectures, though calibration enables near-perfect ResNet50 detection. These results establish tabular diffusion models as a practical tool for stress-testing and hardening intrusion detectors in data-scarce 5G cyber-physical deployments.enRobust DetectionConvolutional Neural NetworkDenoisingF1 ScoreAdversarial TrainingCyber-Physical SystemsCall Detail RecordsDetection TrainingDistributed Denial Of ServiceFalse Positive RateInternet Of ThingsMulti-LabelStress TestResidual NetworkGround Truth LabelsLearned WeightsBinary Cross EntropyTest SplitImage XProjected Gradient DescentFast Gradient Sign MethodIntrusion Detection SystemImage GridTest GridNormal TrainingValidation Split10-Min IntervalsDiff-DDoS: Realistic cyber-physical attack synthesis and robust detection for 5G-enabled CPS using tabular diffusion modelsPeer Reviewed Journal Article10.1109/TII.2026.3725775