发表机构
University of Warwick; Loughborough University; Swansea University(华威大学; 拉夫堡大学; 斯旺西大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对深度强化学习入侵检测系统,提出基于概率鲁棒性的通用对抗扰动生成方法PX-UAP,利用可解释人工智能指导扰动塑造,实验证明其攻击有效性优于现有方法。
AI 中文摘要
深度强化学习(DRL)能够在动态网络环境中实现自适应入侵检测,但也使入侵检测系统(IDS)面临对抗性威胁,例如通用对抗扰动(UAP),它通过施加单一与输入无关的扰动来降低跨流量的检测性能。概率鲁棒性(PR)作为一种事后评估指标,提供了一种基于原则的、群体层面的对抗影响度量,其概念上与UAP的通用性目标一致,即PR量化了输入空间中误分类的普遍性,使其成为指导UAP生成的天然信号。因此,我们提出了基于PR的UAP,这代表了首次将显式的PR驱动目标整合到针对基于DRL的IDS生成UAP中。基于此公式,我们引入了PX-UAP,它利用可解释人工智能(XAI)在现实领域约束下指导扰动塑造,并对其设计提供了严格的理论分析。大量实验表明,PX-UAP在攻击有效性方面持续优于最先进的UAP方法。
英文摘要
Deep reinforcement learning (DRL) enables adaptive intrusion detection in dynamic network environments but also exposes intrusion detection systems (IDS) to adversarial threats such as universal adversarial perturbations (UAPs), which apply a single input-agnostic perturbation to degrade detection performance across traffic. Probabilistic Robustness (PR), as a post-hoc evaluation metric, provides a principled, population-level measure of adversarial impact that conceptually aligns with the universality objective of UAPs, i.e., PR quantifies the prevalence of misclassification in the input space, making it a natural signal for guiding UAP generation. Hence, we propose PR-based UAP, which represents the first integration of an explicit PR-driven objective into generating UAPs against DRL-based IDS. Building on this formulation, we introduce PX-UAP, which leverages explainable artificial intelligence (XAI) to guide perturbation shaping under realistic domain constraints, and provides a rigorous theoretical analysis of its design. Extensive experiments demonstrate that PX-UAP consistently outperforms state-of-the-art UAP methods in attack effectiveness.
Comments20pages,10figues