防御基于图神经网络的网络入侵检测系统对抗结构性对抗攻击
Defending Network Intrusion Detection Systems Based on Graph Neural Networks Against Structural Adversarial Attacks
浏览论文内容
中文总结 AI 辅助
本文提出基于对抗训练的防御框架,以E-GraphSAGE为基础GNN,在CTU-13和TON-IoT数据集上,增强了基于GNN的NIDS对抗结构性攻击的能力,同时保持了干净图上的检测性能。
中文摘要 AI 辅助
图神经网络(GNN)凭借其利用网络流特征和拓扑模式的能力,成为基于机器学习(ML)的网络入侵检测系统(NIDS)的有前景解决方案。尽管GNN分类器相比其他ML检测器对基于特征的对抗攻击表现出更出色的鲁棒性,但它们仍易受结构性对抗攻击影响,攻击者通过注入边或插入节点扰动底层网络图拓扑。此类攻击构成现实且严重的威胁,破坏基于GNN的NIDS在实际部署中的可靠性。文献中虽已提出防御措施,但往往依赖于现实网络安全场景中不切实际的假设。本文提出一种基于对抗训练的防御框架,以增强基于GNN的NIDS对抗结构性攻击的能力。我们通过策略性替换良性网络流中的源节点和目标节点来生成对抗样本,从而有效模拟边注入攻击。我们在两个广泛使用的数据集(CTU-13和TON-IoT)上,以E-GraphSAGE作为基础GNN分类器评估我们的方法。实验结果表明,我们的方法生成的加固检测器在干净图上具有出色的检测性能,且对结构性对抗攻击的鲁棒性得到增强。
英文摘要
Graph Neural Networks (GNNs) represent a promising solution for Machine Learning (ML) based Network Intrusion Detection Systems (NIDS), thanks to their ability to leverage both network flow features and topological patterns. While GNN classifiers demonstrate superior robustness against feature-based adversarial attacks compared to other ML detectors, they remain vulnerable to structural adversarial attacks, where an attacker perturbs the underlying network graph topology by injecting edges or inserting nodes. Such attacks pose a realistic and severe threat, undermining the reliability of GNN-based NIDS in practical deployments. While countermeasures have been proposed in the literature, they often rely on assumptions that are unrealistic in real-world cybersecurity scenarios. In this paper, we propose a defense framework based on adversarial training to strengthen GNN-based NIDS against structural attacks. We generate adversarial samples by strategically replacing the source and destination nodes in benign network flows, thereby efficiently mimicking edge injection attacks. We evaluate our approach on two widely used datasets (CTU-13 and TON-IoT) using E-GraphSAGE as the base GNN classifier. Experimental results show that our approach produces hardened detectors with superior detection performance on clean graphs and enhanced robustness against structural adversarial attacks.