arXiv2026
Machine Learning-based Network Intrusion Detection Systems (ML-NIDS) can be bypassed by rudimentary adversarial perturbations. Recent work has focused on identifying where such perturbations can realistically be applied by a host-side adversary. Yet every one of these attacks produces perturbations the same way: searching from scratch for every flow. The cost of an attack therefore grows in lockstep with the number of flows it must perturb, and real networks produce them by the tens of millions. In this paper, we show that using reinforcement learning to train lightweight perturbation-generating policies lets an adversary amortize that cost across flows it perturbs. Counting every detector query and every second an attack spends, training included, we compare learned policies against gradient, query-based, and random search across six ML-NIDS environments at two operating points, under both evasion and alert inflation. One successful adversarial example costs a learned policy 1.5 to 18 detector queries against 52 to 1,100 for the strongest search baseline, and the policy amortizes its training cost after 76 to 1,622 examples, a volume a monitored link produces in seconds of traffic. We further find that the RL formulation literature adopts by default is unnecessary for evasion, that the policy conditions on the flow it is given rather than converging on a fixed perturbation, and that it transfers to detectors and traffic it never trained against. The value of learning to attack ML-NIDS is therefore not a matter of effectiveness, but of scale.