Skip to main content
Thesis defences

PhD Oral Exam - Ishfaq Bashir Sofi, Electrical and Computer Engineering

Generative Artificial Intelligence for Secure and Efficient Intrusion Detection in Imbalanced Multi-Attack Cyber Environments


Date & time
Thursday, August 20, 2026
10 a.m. – 1 p.m.
Cost

This event is free

Organization

School of Graduate Studies

Contact

Dolly Grewal

Where

Engineering, Computer Science and Visual Arts Integrated Complex
1515 Ste-Catherine St. W.
Room 2.184

Accessible location

Yes - See details

When studying for a doctoral degree (PhD), candidates submit a thesis that provides a critical review of the current state of knowledge of the thesis subject as well as the student’s own contributions to the subject. The distinguishing criterion of doctoral graduate research is a significant and original contribution to knowledge.

Once accepted, the candidate presents the thesis orally. This oral exam is open to the public.

Abstract

The rapid expansion of modern cyber infrastructures, including cloud computing, Internet of Things (IoT) ecosystems, industrial control systems, cyber-physical environments, and large-scale enterprise networks, has significantly increased the complexity and sophistication of cyber threats. Intrusion Detection Systems (IDS) play a critical role in protecting these environments by detecting malicious activities and abnormal network behaviors. Although Machine Learning (ML) and Deep Learning (DL) based IDS have substantially improved intrusion detection, their effectiveness remains limited by severe class imbalance, mode collapse, inadequate modeling of temporal attack behaviors, high computational complexity, and limited interpretability. In particular, the scarcity of minority attack samples biases learning algorithms toward majority classes, resulting in poor detection of rare but critical attacks. Addressing these interconnected challenges is essential for developing reliable, scalable, and deployable IDS. This thesis presents a suite of Generative Artificial Intelligence (GenAI) enabled IDS that collectively address these limitations. The first contribution focuses on mitigating class imbalance through generative modeling. An Autoencoder Multi-WGAN (AE–Multi–WGAN) is proposed to generate diverse and realistic minority attack samples while preserving meaningful latent representations. Building upon this scheme, an ensemble-based generative approach employing multiple class-specific Convolutional Neural Network (CNN) based Wasserstein GAN (WGAN) further improves minority attack representation, enhances sample diversity, and alleviates the effects of imbalanced data distributions, resulting in significant improvements in minority-class detection performance. The second contribution addresses mode collapse through the proposed Adaptive Class-Conditional Variational GAN (ACCV-GAN), which combines variational learning, transformer-based feature modeling, attention mechanisms, and Class Aware Batch Adaptation (CABA) to improve latent space continuity, sample diversity, and adversarial training stability. The proposed scheme achieves superior diversity preservation, enhanced minority-class detection, and more balanced performance across highly imbalanced intrusion datasets. The third contribution introduces Multi-View GAN IDS (MV-GAN-IDS), which jointly learns static feature representations and temporal attack behaviors using a Behavioral Reconstruction Module (BRM), a Class-Aware Generative Balancing Module (CGBM), and a transformer-based fusion classifier. By integrating complementary spatial and temporal information, the proposed scheme improves the detection of stealthy, evolving, and time-dependent cyberattacks while enhancing classification accuracy and generalization. Finally, the thesis addresses practical deployment by proposing a lightweight and efficient IDS. A Lightweight Multi-Head Early-Exit (LIME) scheme is proposed which reduces computational complexity, memory requirements, and inference latency while maintaining competitive detection performance. In addition, an efficient transformer-based knowledge distillation method incorporating contrastive feature learning, generative augmentation, and explainability enables the deployment of lightweight yet reliable intrusion detection models. Extensive experiments conducted on the NSL-KDD, UNSW-NB15, CICIDS-2017, CICIDS- 2018, and ToN-IoT benchmark datasets demonstrate that the proposed scheme consistently outperform existing methods in terms of minority-class detection, generative diversity, detection accuracy, computational efficiency, and deployment feasibility. Collectively, this thesis advances the development of secure, efficient, and practical next-generation GenAI-driven IDS for modern cybersecurity environments.

Back to top

© Concordia University