MORPH-IDS: A Context-Driven Multi-Agent Reinforcement Learning Framework for Drift-Aware Moving Target Defense in Adversarial-Robust Intrusion Detection

RESEARCH CREW
11:21 03/07/2026

In the rapidly evolving cybersecurity landscape, Machine Learning (ML)-based Network Intrusion Detection Systems (NIDS) have become essential for detecting sophisticated threats, yet they are increasingly vulnerable to adversarial evasion attacks and concept drift caused by adaptive attackers. Existing ensemble-based defenses optimize for instantaneous accuracy without incorporating drift signals, while drift adaptation methods remain reactive rather than proactive against strategic adversaries. Therefore, we propose MORPH-IDS (Moving Objective Reinforcement Learning framework for Proactive and Hardened Intrusion Detection Systems), which integrates Moving Target Defense (MTD) with Reinforcement Learning (RL) to mitigate these risks by creating a dynamic, unpredictable attack surface that invalidates adversaries' reconnaissance and increases attack costs. The core of MORPH-IDS is a multi-agent RL (MARL) setup modeled as a Markov Game, featuring two competing agents in a co-evolutionary environment. The defender agent, implemented as a Dueling Double Deep Q-Network (D3QN), learns to intelligently select and combine strategies from a diverse model pool. Conditioned on a carefully designed a low-dimensional drift embedding, which quantifies distributional shifts, temporal dynamics, and poisoning indicators, the agent dynamically orchestrates robust ensembles during periods of high concept drift and accuracy-optimal methods under stable conditions, thereby creating a non-stationary, unpredictable moving target defense. To enable proactive adaptation, an Adversarial Drift Injection (ADI) scheduler—driven by the adversarial agent—proactively synthesizes diverse drift and evasion scenarios during training. This co-evolutionary process teaches the defender to interpret contextual signals effectively, generalize to unseen adversarial threats, and mitigate catastrophic forgetting through integrated continual learning mechanisms. Empirical evaluation on three benchmarks, including CIC-IDS2017, CIC-IDS2019, CIC-APT-IIoT-2024 dataset, demonstrates that MORPH-IDS improves robustness of NIDS against both concept drift and adversarial attacks. Specifically, it outperforms recent baselines such as Apollon by over 15\% in F1-score on CIC-IDS2017 and improves adversarial robustness by up to 22.65\% against black-box attacks. Furthermore, on the CIC-APT-IIoT-2024 dataset, the system detects 91.53\% of Advanced Persistent Threat (APT) patterns while maintaining stable performance under temporal drift. The results underscore the effectiveness of drift-aware MTD for risk mitigation in real-time defensive adaptation.

TIN LIÊN QUAN
Web 3.0 technologies present fundamental challenges to established theories of platform strategy and organizational design, yet the organizational forms enabling decentralized innovation remain theoretically underexamined. This paper reconceptualizes cross-chain bridges, which enable value and message transfer across independent blockchain networks, not as passive technical utilities but as novel business models...