arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.17796cs.CRcs.LG

Diff-DDoS:基于表格扩散模型的5G赋能网络物理系统的逼真网络物理攻击合成与鲁棒检测

Diff-DDoS: Realistic Cyber-Physical Attack Synthesis and Robust Detection for 5G-Enabled CPS Using Tabular Diffusion Models

Bilal Hussain, Xiao Tang, Qinghe Du, Tan Li, Muhammad Azhar, Danista Khan

首次发表
浏览论文内容

中文总结 AI 辅助

该研究针对5G赋能CPS的DDoS检测数据稀缺问题,提出Diff-DDoS三阶段框架,采用表格扩散模型生成逼真攻击并通过对抗扩散训练提升ResNet50等检测器的鲁棒性,在米兰CDR数据集上取得优异检测效果。

中文摘要 AI 辅助

针对5G赋能网络物理系统(CPS)的基于深度学习的DDoS检测器面临带标签攻击数据稀缺、合成替代品不逼真的问题,这限制了其对抗自适应对手的鲁棒性。在面对逼真的、保留分布的样本时,基于带固定缩放乘数的手工制作攻击训练的检测器会灾难性地退化,F1分数下降幅度约为47%至100%,具体取决于场景。我们提出Diff-DDoS,这是一个采用表格扩散模型进行逼真攻击合成与鲁棒检测的三阶段框架。第一阶段在来自通话详细记录(CDR)的时空网格上训练基线CNN单元级检测器。第二阶段在正常CDR聚合数据上训练表格去噪扩散概率模型(TabDDPM),以生成逼真的攻击并暴露检测器的漏洞。第三阶段引入对抗扩散训练(ADT),采用逆分类引导生成困难但保留分布的样本,直至检测器收敛。在涵盖短信洪水、静默呼叫、互联网信令和混合场景的米兰CDR数据集上,采用ADT的ResNet50在静默呼叫场景恢复79.62%的F1分数,在互联网场景达到100%,在混合场景达到92.79%。经基于验证的阈值校准后,ADT的短信F1分数达到100%,而CTGAN仅为47.3%,且在静默呼叫场景匹配最强的基于梯度的对抗训练基线。这些结果支持表格扩散模型用于数据稀缺的5G网络物理部署中的压力测试和入侵检测器加固。

英文摘要

Deep learning-based DDoS detectors for 5G-enabled cyber-physical systems face scarce labeled attack data and unrealistic synthetic substitutes, which limit robustness against adaptive adversaries. Detectors trained on hand-crafted attacks with fixed scaling multipliers degrade catastrophically (F1-score drops of about 47 percent to 100 percent, depending on scenario) when confronted with realistic, distribution-preserving samples. We propose Diff-DDoS, a three-phase framework for realistic attack synthesis and robust detection using tabular diffusion models. Phase 1 trains a baseline CNN cell-level detector on spatiotemporal grids from call detail records (CDRs). Phase 2 trains a tabular denoising diffusion probabilistic model (TabDDPM) on normal CDR aggregates to generate realistic attacks and expose detector vulnerabilities. Phase 3 introduces adversarial diffusion training (ADT), using inverse classifier guidance to generate hard yet distribution-preserving samples until the detector converges. On a Milano CDR dataset across SMS-flooding, silent-call, Internet-signaling, and blended scenarios, ResNet50 with ADT recovers F1-scores of 79.62 percent (silent-call), 100 percent (Internet), and 92.79 percent (blended). After validation-based threshold calibration, ADT reaches 100 percent SMS F1 versus 47.3 percent for CTGAN, and matches the strongest gradient-based adversarial-training baseline on silent-call. These results support tabular diffusion models for stress-testing and hardening intrusion detectors in data-scarce 5G cyber-physical deployments.

发表机构

  • The Hong Kong Polytechnic University(香港理工大学)
  • Xi’an Jiaotong University(西安交通大学)
  • The Hang Seng University of Hong Kong(香港恒生大学)
  • Hong Kong Shue Yan University(香港树仁大学)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑