arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.19241cs.CRcs.AI

鲁棒共形入侵检测:基于流量感知校准与攻击轨道不变性

Robust Conformal Intrusion Detection via Traffic-Aware Calibration and Attack-Orbit Invariance

  • Guangzhou Health Science College(广州卫生健康职业学院)

机构由 AI 辅助整理,请以论文原文为准。

Zhenpeng Li

AI总结:

针对网络入侵检测中LLM预测缺乏统计保证的问题,提出流量感知共形预测与攻击轨道不变性,在攻击下恢复覆盖保证,并牺牲少量干净准确率以抵御自适应攻击。

AI中文摘要:

针对网络入侵检测进行微调的大型语言模型会输出单点预测,且不具备统计有效性保证。共形预测提供了有限样本覆盖保证,但一旦攻击者扰动可控的网络特征,在干净流量上校准的阈值便会失效。我们在三个入侵检测基准上证明了这一失效现象,并提出了流量感知共形预测方法,该方法在攻击者预期使用的扰动机制所生成的流量上进行校准,并且在该机制已知且可采样时,可证明地恢复覆盖保证。一个更强的自适应攻击者,通过查询目标模型自身的分数,仍可能削弱这种匹配校准的保证。我们通过将攻击者可控特征及其确定性后代从评分表示中排除,来应对这第二种威胁模型,并证明这能产生精确的、路径式的覆盖保证,而非概率性界限。在三个独立微调的语言模型架构上,该表示在评估的所有攻击尝试下保持完全不变,相对于不受限制的特征集,在干净准确率上付出了量化的七到十四个百分点的代价。

英文摘要:

Large language models fine-tuned for network intrusion detection emit single-point predictions without statistical validity guarantees. Conformal prediction supplies a finite-sample coverage guarantee, but a threshold calibrated on clean traffic fails once an adversary perturbs controllable network features. We demonstrate this failure across three intrusion detection benchmarks and propose traffic-aware conformal prediction, which calibrates on traffic drawn from the perturbation mechanism an attacker is expected to use and provably restores coverage whenever that mechanism is known and can be sampled. A stronger, adaptive attacker that queries the target model's own score can still degrade this matched-calibration guarantee. We address this second threat model by excluding attacker-controllable features and their deterministic descendants from the scored representation, and prove that this yields an exact, pathwise coverage guarantee rather than a probabilistic bound. Across three independently fine-tuned language model architectures, this representation remains completely unchanged under every evaluated attack attempt, at a quantified seven-to-fourteen-point cost in clean accuracy relative to the unrestricted feature set.

补充信息

↑