发表机构
University of Tabuk(塔布克大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对ML-based NIDS,本文评估多种对抗攻击与防御,提出鲁棒性指数RI和两阶段框架AR-NIDS,显著降低平均攻击成功率至0.03并获高RI。
AI 中文摘要
基于机器学习的网络入侵检测系统(ML-based NIDS)容易受到对抗性规避攻击的影响,在这种攻击中,恶意样本被扰动以逃避检测并被误分类为良性。尽管针对ML-based NIDS的对抗攻击和防御研究日益增多,但在统一设置下对多种攻击类型、检测模型和防御策略进行比较评估的研究仍然有限。本文使用NF-UQ-NIDS数据集评估了八种对抗性规避攻击、十五种检测模型和三种代表性防御策略,该数据集包含近期传统和物联网网络流量,涵盖二十种不同的攻击类别。评估比较了模型在干净测试数据和包含对抗样本的鲁棒性评估集上的性能,分析了攻击成功率在模型间的一致性,并考察了防御策略对对抗鲁棒性的影响。为支持模型比较,我们引入了鲁棒性指数(RI),这是一种紧凑的比较指标,奖励在鲁棒性评估集上计算的高平衡准确率和宏F1分数,同时惩罚高攻击成功率(ASR)。我们进一步提出了AR-NIDS,这是一个两阶段框架,首先使用对抗训练的集成模型区分正常、攻击和对抗样本,然后通过对抗攻击分类器识别攻击类型。在评估的基于迁移的设置下,所提出的对抗训练集成模型在鲁棒性评估集上的分类性能与规避抵抗之间实现了最强的整体权衡,将平均ASR从0.41降至0.03,并实现了0.98的RI。
英文摘要
Machine learning-based network intrusion detection systems (ML-based NIDS) are vulnerable to adversarial evasion, where malicious samples are perturbed to evade detection and be misclassified as benign. Despite growing research on adversarial attacks and defenses for ML-based NIDS, comparative evaluations of multiple attack types, detection models, and defense strategies under a common setting remain limited. In this paper, we evaluate eight adversarial evasion attacks, fifteen detection models, and three representative defense strategies using the NF-UQ-NIDS dataset, which includes recent traditional and IoT network traffic with twenty distinct attack categories. The evaluation compares model performance on clean test data and on robustness evaluation sets that include adversarial samples, analyzes attack success consistency across models, and examines the effect of defense strategies on adversarial robustness. To support model comparison, we introduce the Robustness Index (RI), a compact comparative metric that rewards high balanced accuracy and macro-F1 score computed on the robustness evaluation set while penalizing high attack success rate (ASR). We further present AR-NIDS, a two-stage framework that uses an adversarially trained ensemble to distinguish normal, attack, and adversarial samples, followed by an adversarial attack classifier to identify the attack type. Under the evaluated transfer-based setting, the proposed adversarially trained ensemble achieves the strongest overall trade-off between classification performance on the robustness evaluation set and evasion resistance, reducing the average ASR from 0.41 to 0.03 and achieving an RI of 0.98.