arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2610.02552cs.CRcs.AI

不同步,不可见:针对IIoT入侵检测的幻影状态攻击

Out of Sync, Out of Sight: Phantom State Attacks against IIoT Intrusion Detection

Sabrine Ennaji, Elhadj Benkhelifa, Nadia Kabachi

首次发表
浏览论文内容

中文总结 AI 辅助

针对IIoT入侵检测,提出幻影状态攻击(PSA),利用时间同步假设,通过有界时序漂移移动观测跨窗口边界,无需查询或修改流量,在ToN-IoT和CIC IIoT 2025上降低检测性能,揭示时间聚合攻击面。

中文摘要 AI 辅助

基于机器学习的入侵检测系统(IDS)对于保障工业物联网(IIoT)环境的安全至关重要。针对它们的大多数对抗性研究要么扰动特征向量或产生特征向量的流量,要么依赖于梯度访问、重复的模型查询或对良性流量的学习模型。另一小部分工作在不查询检测器的情况下重塑数据包时序,但使恶意流量模仿学习到的良性时序模型。在这些方法中,工业监控管道的一个假设很少受到关注:时间同步。IDS通过将遥测数据聚合到滑动或翻滚窗口中重建运行状态,因此其视图不仅取决于观察到什么,还取决于每个观察相对于窗口边界的时间位置。我们引入了幻影状态攻击(PSA),该攻击在被动、零查询威胁模型下利用这种依赖性。PSA不修改数据包、扰动特征、查询分类器或拟合任何良性流量模型,而是注入受攻击流自身到达间隔变异性校准的有界时序漂移,以最小所需偏移将观察移动到最近的窗口边界之外。然后,IDS重建出与真实过程状态不同的幻影状态。我们在ToN-IoT和CIC IIoT 2025(DataSense)数据集上,针对随机森林、MLP和XGBoost评估了PSA,测量了检测退化、同步失真、隐蔽性和攻击者成本。PSA会降低携带足够数据包以进行窗口边界重新分配的流的检测性能,而对其他流几乎不产生影响,因此其效果是有条件的。基于查询的基线方法达到更高的原始成功率,但每个窗口需要多次查询,而PSA则无需任何查询。结果表明,时间聚合是一个攻击面,可在比先前逃避技术更弱的假设下被利用。

英文摘要

Machine learning-based intrusion detection systems (IDS) are critical for securing Industrial Internet of Things (IIoT) environments. Most adversarial research against them perturbs the feature vector or the traffic that produces it, and depends on gradient access, repeated model queries, or a learned model of benign traffic. A smaller line of work reshapes packet timing without querying the detector, but makes malicious traffic mimic a learned model of benign timing. Across these approaches, one assumption of industrial monitoring pipelines has received little attention: temporal synchronization. An IDS reconstructs operational state by aggregating telemetry into sliding or tumbling windows, so its view depends not only on what is observed but on when each observation falls relative to a window boundary. We introduce the Phantom State Attack (PSA), which exploits that dependence under a passive, zero-query threat model. Rather than modifying packets, perturbing features, querying the classifier, or fitting any model of benign traffic, PSA injects bounded timing drift calibrated to the attack flow's own inter-arrival variability, moving observations across the nearest window boundary by the minimal shift needed. The IDS then reconstructs a phantom state that diverges from the true process state. We evaluate PSA on ToN-IoT and CIC IIoT 2025 (DataSense), against Random Forest, MLP and XGBoost, measuring detection degradation, synchronization distortion, stealth, and attacker cost. PSA degrades detection on flows carrying enough packets for window-boundary redistribution, and leaves others almost unchanged, so its effect is conditional. A query-based baseline reaches higher raw success but needs many queries per window, while PSA needs none. The results identify temporal aggregation as an attack surface reachable under weaker assumptions than prior evasion techniques.

发表机构

  • Université Lyon 1(里昂第一大学)
  • Université Lumière Lyon 2(里昂第二大学)
  • Liverpool John Moores University(利物浦约翰摩尔斯大学)

机构由 AI 辅助整理,请以论文原文为准。

↑