A Multi-Layered Defense Framework Against Adversarial Attacks on ML-based Web Application Firewalls
Information Systems Technologies, Wilmington University, New Castle, Delaware, USA.
Research Article
Open Access Research Journal of Science and Technology, 2025, 15(02), 063-078.
Article DOI: 10.53022/oarjst.2025.15.2.0137
Publication history:
Received on 18 October 2025; revised on 25 November 2025; accepted on 28 November 2025
Abstract:
Machine learning-based Web Application Firewalls (WAFs) have emerged as powerful alternatives to traditional signature-based systems, achieving superior detection accuracy through automated learning from traffic patterns. However, recent research demonstrates that these ML-based WAFs are vulnerable to adversarial attacks, where attackers craft malicious payloads that evade detection through carefully designed perturbations. This paper presents a comprehensive three-layer defense framework that addresses adversarial threats across the entire machine learning lifecycle while maintaining production-grade performance. Our framework integrates detection mechanisms for identifying adversarial inputs, prevention strategies including adversarial training and certified defenses, and adaptive response capabilities through online learning. We evaluate the framework extensively across five benchmark datasets (CSIC 2010, HTTPParams, CSE-CIC-IDS2018, SQLiV5, XSS-Dataset) against ten adversarial attack methods spanning gradient-based attacks (FGSM, PGD, C&W), mutation-based attacks (WAF-A-MoLE), and transfer attacks. Results demonstrate that our framework achieves 87.2% average robust accuracy across diverse attacks, outperforming single-defense baselines by 15-20%, while certified defenses provide formal robustness guarantees for 78.5% of samples at perturbation radius ε = 0.1. The risk-adaptive activation strategy maintains 28.7ms average latency and 2,847 requests/second throughput, meeting real-time requirements for production deployment. Ablation studies confirm that each framework component contributes meaningfully to overall robustness, with ensemble methods providing the largest individual improvement. This work advances the state-of-the-art in adversarial robust web application security by demonstrating that strong security and acceptable performance can coexist through careful architectural design, providing both theoretical foundations through certified defenses and practical effectiveness through empirical validation.
Keywords:
Adversarial machine learning; Web application firewall; Certified robustness; Ensemble defense; Adversarial training; Web security
Full text article in PDF:
Copyright information:
Copyright © 2025 Author(s) retain the copyright of this article. This article is published under the terms of the Creative Commons Attribution Liscense 4.0
