arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

一种针对计算机网络流量中白盒对抗攻击的多模型混合防御方法

A Multi-Model Hybrid Defense Approach Against White-box Adversarial Attacks in Computer Network Traffic

Khushnaseeb Roshan

arXiv 2607.17105首次发表:更新:

发表机构

Aligarh Muslim University(阿里格尔穆斯林大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

研究针对计算机网络流量白盒对抗攻击,提出多模型混合防御方法,结合对抗训练和高斯数据增强,有效减轻FGSM和C&W攻击影响,提升攻击后NIDS准确率,为对抗机器学习安全研究提供方向。

AI 中文摘要

保护计算机网络免受不断演变的网络安全威胁和未知网络攻击至关重要。网络入侵检测系统(NIDS)是保护计算机网络免受未知网络威胁的重要工具,但易受对抗攻击。对抗攻击旨在通过在系统中精心制作和注入对抗样本欺骗NIDS,使良性网络流量被误分类为恶意。我们开发了一种弹性混合防御机制来减轻快速梯度符号法(FGSM)和卡利尼与瓦格纳(C&W)攻击的影响。该混合防御方法利用对抗训练(AT)和高斯数据增强(GDA)两种启发式防御方法的组合力量。GDA提供多方向防御,AT增强NIDS对特定对抗向量的鲁棒性。在攻击前场景下,NIDS表现出良好的准确率和F1分数,但在攻击后场景下,FGSM和C&W攻击使其准确率显著下降。我们提出的混合防御方法有效减轻了这些对抗威胁,FGSM和C&W攻击的防御后准确率分别为96.57%和89.20%。我们在一系列ε和置信度噪声因子值(从0.0001到0.0009)范围内评估了防御策略。本研究从安全角度为对抗机器学习新兴领域的未来研究提供了良好方向。

英文摘要

It is crucial to safeguard computer networks from evolving network security threats and unknown cyberattacks. An essential tool for protecting computer networks against unknown cyber threats is Network Intrusion Detection System (NIDS). However, NIDS faces a major security concern due to its susceptibility to adversarial attacks. Adversarial attacks aim to deceive NIDS by crafting and injecting adversarial examples into the system. These adversarial inputs can deceive the NIDS into misclassifying benign network traffic as malicious. We developed a resilient hybrid defense mechanism aimed to mitigate the impact of two potent adversarial attacks: Fast Gradient Sign Method (FGSM) and Carlini & Wagner (C&W) attack. Our hybrid defense approach leverages the combined strength of two heuristic defense methods: Adversarial Training (AT) and Gaussian Data Augmentation (GDA). GDA provides multi-directional defense, while AT enhances NIDS robustness against specific adversarial vectors. Under pre-attack scenarios, NIDS demonstrated good accuracy and f1-score. However, in the post-attack scenario, its accuracy significantly dropped under FGSM and C&W attacks (0.2649 and 0.4961, respectively). Our proposed hybrid defense method effectively mitigated these adversarial threats, with post-defense accuracy of 96.57% and 89.20% for FGSM and C&W attacks. We evaluated the defense strategy across a range of epsilon and confidence noise factor values (ranging from 0.0001 to 0.0009). This research provides a good direction for future researchers in the emerging area of adversarial machine learning from a security perspective.

Comments40 Pages, 11 Tables and 9 Figures

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑