arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

基于大语言模型的网络入侵检测的流量感知随机平滑

Traffic-Aware Randomized Smoothing for LLM-Based Network Intrusion Detection

Zhenpeng Li

arXiv 2607.13801首次发表:更新:

发表机构

Guangzhou Health Science College(广州健康科学学院)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

研究基于大语言模型的网络入侵检测系统对流量操纵的鲁棒性,提出流量感知随机平滑方法TA-RS,通过在特定子空间注入噪声,提升认证准确率,不同数据集表现有差异,还探究了方法局限性及改进策略。

AI 中文摘要

基于大语言模型(LLM)的入侵检测系统(IDS)越来越多地用于安全监控,但其对可行流量操纵的鲁棒性在很大程度上仍基于经验。我们提出了流量感知随机平滑(TA-RS),这是一种与分类器无关的经过认证的防御方法,在微调与认证期间仅将高斯噪声注入直接可控(DC)子空间(即远程攻击者可修改的特征),使平滑分布与攻击者可控子空间对齐。我们发现一个关键前提:对干净训练的LLM-IDS应用标准随机平滑,在测试的四组(模型、数据集)对中有三组认证准确率较低(14%-33%,等于或低于随机水平),第四组仅为57%(比噪声增强结果低43个百分点);噪声增强微调在三个基准数据集中的两个上恢复到68%-100%(在sigma=0.25时)。在L_inf等效阈值R_inf = epsilon*sqrt(|DC|)(epsilon=0.05)下,TA-RS在CIC-IDS-2018和HIKARI-2021上实现了55%-100%的认证准确率,中位数认证半径(R约为0.45-0.96)比R_inf高1.8-5倍(在sigma=0.25-1.00范围内)。与经过公平训练的等训练RS基线相比,剩余优势取决于数据集(在CIC-IDS-2018上为4-19个百分点)。与共享DC噪声增强训练方法的各向同性RS基线相比,更大的差距(高达72个百分点)主要反映了训练-认证不匹配,而非仅DC对齐:各向同性测试时噪声会干扰攻击者无法利用的不可控特征,导致弃权率高达68%。RT-IoT2022探究了该方法的局限性:在默认微调方法下失败,但当增加噪声增强时恢复到76%/69%的认证准确率(LLaMA3-8B/Qwen3-8B)。

英文摘要

Large language model (LLM)-based intrusion detection systems (IDS) are increasingly studied for security monitoring, yet their robustness against feasible traffic manipulation remains largely empirical. We present Traffic-Aware Randomized Smoothing (TA-RS), a classifier-agnostic certified defense that injects Gaussian noise exclusively into the directly controllable (DC) subspace -- features a remote attacker can modify -- during both fine-tuning and certification, aligning the smoothing distribution with the attacker-controllable subspace. We identify a critical prerequisite: applying standard randomized smoothing to clean-trained LLM-IDS yields weak certified accuracy in three of four (model, dataset) pairs tested (14-33%, at or below random) and only 57% in the fourth (43 pp below the noise-augmented result); noise-augmented fine-tuning recovers to 68-100% on two of three benchmark datasets (at sigma=0.25). At the L_inf-equivalent threshold R_inf = epsilon*sqrt(|DC|) (epsilon=0.05), TA-RS achieves 55-100% certified accuracy on CIC-IDS-2018 and HIKARI-2021, with median certified radii (R approx 0.45-0.96) exceeding R_inf by 1.8-5x (across sigma=0.25-1.00). Against a fairly trained iso-trained RS baseline the residual advantage is dataset-dependent (4-19 pp on CIC-IDS-2018). The larger gap -- up to 72 pp against an isotropic RS baseline that shares the DC-noise-augmented training recipe -- primarily reflects the training-certification mismatch rather than DC alignment alone: isotropic test-time noise perturbs uncontrollable features the attacker cannot exploit, triggering abstention rates up to 68%. RT-IoT2022 probes the limits of the method: it fails under the default fine-tuning recipe but recovers to 76%/69% certified accuracy (LLaMA3-8B/Qwen3-8B) when noise augmentation is increased.

Comments44 pages, 14 figures, 14 tables. Submitted to Expert Systems with Applications

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑