针对物联网网络中在线AutoML的基于成本效用的对抗训练规避攻击
Evasion Attacks on Cost-Utility-Based Adversarial Training for Online AutoML in IoT Networks
浏览论文内容
中文总结 AI 辅助
本研究评估物联网网络中在线AutoML下黑盒规避攻击对基于成本效用的对抗训练的影响,发现LB和SRP的对抗训练版本在最高成本预算下达到最佳对抗准确率0.985,最大准确率下降仅0.8%。
中文摘要 AI 辅助
随着物联网(IoT)网络越来越依赖机器学习进行异常检测、恶意软件检测、入侵检测和网络监控,这些系统已成为规避攻击的诱人目标。规避攻击构成重大安全风险,因为攻击者故意修改输入数据,以误导训练好的模型产生不正确的预测,同时逃避检测。本研究评估了在物联网网络的在线AutoML背景下,黑盒规避攻击对基于成本效用的对抗训练防御策略的影响。具体而言,规避攻击被应用于在线学习器,包括Hoeffding树(HT)、Leveraging Bagging(LB)、流式随机补丁(SRP)、Hoeffding自适应树(HAT)和自适应随机森林(ARF)。通过开发这些在线学习器的朴素版本和对抗训练(AT)版本,我们生成了每个模型的干净准确率和对抗准确率。结果表明,LB和SRP的AT版本表现最佳,在最高成本预算1.00下实现了最高的对抗准确率(0.985)和较高的干净准确率(0.993),最大准确率下降仅为0.8%。最后,使用早期漂移检测方法(EDDM)进行了漂移检测。
英文摘要
As Internet of Things (IoT) networks increasingly depend on machine learning for anomaly, malware, intrusion detection, and network monitoring, such systems have become attractive targets for evasion attacks. Evasion attacks pose a major security risk because an adversary intentionally modifies input data to mislead a trained model into producing incorrect predictions while evading detection. This study evaluates the impact of black-box evasion attacks on a cost-utility-based adversarial training defense strategy in an Online AutoML context for IoT networks. Specifically, evasion attacks were applied to online learners, including Hoeffding Tree (HT), Leveraging Bagging (LB), Streaming Random Patches (SRP), Hoeffding Adaptive Tree (HAT), and Adaptive Random Forest (ARF). By developing naive and adversarially trained (AT) versions of these online learners, we generated clean and adversarial accuracies for each model. The results show that the AT versions of LB and SRP performed best, achieving the highest adversarial accuracy (0.985) and high clean accuracy (0.993) at the highest cost budget of 1.00, with a maximum accuracy reduction of only 0.8%. Finally, drift detection was conducted using the Early Drift Detection Method (EDDM).
发表机构
- Ontario Tech University(安大略理工大学)
- Alex Ekwueme Federal University(亚历克·埃克韦梅联邦大学)
机构由 AI 辅助整理,请以论文原文为准。