IDEAS home Printed from https://ideas.repec.org/a/plo/pone00/0331443.html
   My bibliography  Save this article

A machine learning approach for detecting WPA3 downgrade attacks in next-generation Wi-Fi systems

Author

Listed:
  • Aya Tareef
  • Yazan M Allawi
  • Anas A Alkasasbeh
  • Ahmad Abadleh
  • Wasan Alamro
  • Mansoor Alghamdi
  • Aymen I Zreikat
  • Hunseok Kang

Abstract

This paper presents a hybrid adaptive approach based on machine learning (ML) for classifying incoming traffic, feature selection and thresholding, aimed at enhancing downgrade attack detection in Wi-Fi Protected Access 3 (WPA3) networks. The fast proliferation of WPA3 is regarded critical for securing modern Wi-Fi systems, which have become integral to 5G and Beyond (5G&B) Radio Access Networks (RAN) architecture. However, the wireless communication channel remains inherently susceptible to downgrade attacks, where adversaries intentionally cause networks to revert from WPA3 to WPA2, with the malicious intent of exploiting known security flaws. Traditional Intrusion Detection Systems (IDS), which rely on fixed-threshold statistical methods, often fail to adapt to changing network environments and new, sophisticated attack strategies. To address this limitation, we introduce a novel ML-based Feature Selection and Thresholding for Downgrade Attacks Detection (MFST-DAD) approach, which comprises three stages: traffic data preprocessing, baseline adaptive feature selection, and real-time detection and prevention using ML algorithms. Experimental results on a specially generated dataset demonstrate that the proposed approach detects downgrade attacks in WPA3 networks, achieving 99.8% accuracy with a Naive Bayes classifier in both WPA3 personal and enterprise transition modes. These findings confirm the effectiveness of our proposed approach in securing next-generation Wi-Fi systems.

Suggested Citation

  • Aya Tareef & Yazan M Allawi & Anas A Alkasasbeh & Ahmad Abadleh & Wasan Alamro & Mansoor Alghamdi & Aymen I Zreikat & Hunseok Kang, 2025. "A machine learning approach for detecting WPA3 downgrade attacks in next-generation Wi-Fi systems," PLOS ONE, Public Library of Science, vol. 20(9), pages 1-21, September.
  • Handle: RePEc:plo:pone00:0331443
    DOI: 10.1371/journal.pone.0331443
    as

    Download full text from publisher

    File URL: https://journals.plos.org/plosone/article?id=10.1371/journal.pone.0331443
    Download Restriction: no

    File URL: https://journals.plos.org/plosone/article/file?id=10.1371/journal.pone.0331443&type=printable
    Download Restriction: no

    File URL: https://libkey.io/10.1371/journal.pone.0331443?utm_source=ideas
    LibKey link: if access is restricted and if your library uses this service, LibKey will redirect you to where you can use your library subscription to access this item
    ---><---

    More about this item

    Statistics

    Access and download statistics

    Corrections

    All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:plo:pone00:0331443. See general information about how to correct material in RePEc.

    If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.

    We have no bibliographic references for this item. You can help adding them by using this form .

    If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.

    For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: plosone (email available below). General contact details of provider: https://journals.plos.org/plosone/ .

    Please note that corrections may take a couple of weeks to filter through the various RePEc services.

    IDEAS is a RePEc service. RePEc uses bibliographic data supplied by the respective publishers.