🤖 AI Summary
Synthetic network traffic data is critical for security testing and model training, yet existing generation methods exhibit inconsistent performance in statistical fidelity, classification utility, and class balance. This paper systematically evaluates 12 generative techniques—including statistical approaches (e.g., SMOTE), classical AI models, and modern generative AI (e.g., CTGAN, CopulaGAN, diffusion models)—across NSL-KDD and CIC-IDS2017 datasets, using unified metrics for fidelity, downstream classification performance, class balance, and scalability. We introduce the first multi-dimensional benchmarking framework tailored to network traffic synthesis. Results show CTGAN and CopulaGAN achieve the best trade-off between fidelity and classification utility; statistical methods yield superior class balance but limited modeling capacity; diffusion models, while promising, suffer from prohibitive computational overhead, hindering practical scalability. The study provides empirically grounded guidance for selecting synthetic data generation methods in cybersecurity applications.
📝 Abstract
The generation of synthetic network traffic data is essential for network security testing, machine learning model training, and performance analysis. However, existing methods for synthetic data generation differ significantly in their ability to maintain statistical fidelity, utility for classification tasks, and class balance. This study presents a comparative analysis of twelve synthetic network traffic data generation methods, encompassing non-AI (statistical), classical AI, and generative AI techniques. Using NSL-KDD and CIC-IDS2017 datasets, we evaluate the fidelity, utility, class balance, and scalability of these methods under standardized performance metrics. Results demonstrate that GAN-based models, particularly CTGAN and CopulaGAN, achieve superior fidelity and utility, making them ideal for high-quality synthetic data generation. Statistical methods such as SMOTE and Cluster Centroid effectively maintain class balance but fail to capture complex traffic structures. Meanwhile, diffusion models exhibit computational inefficiencies, limiting their scalability. Our findings provide a structured benchmarking framework for selecting the most suitable synthetic data generation techniques for network traffic analysis and cybersecurity applications.