arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

对抗强化学习用于端口扫描规避:边缘部署IDS中的攻击者特征可见性

Adversarial RL for Port-Scan Evasion: Attacker Feature Visibility in Edge-Deployed IDS

Logan Andrew North, Priya Sanjay Kaluskar, Shasi Kumar Ramachandran Prabhu, Peilong Li, Suman Saha

arXiv 2610.08864首次发表:更新:

发表机构

Pennsylvania State University; Elizabethtown College(宾夕法尼亚州立大学; 伊丽莎白敦学院)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究通过DQN对抗者在黑盒、灰盒和白盒设置下学习规避组合,证明有限特征知识即可有效规避边缘部署的ML-IDS模型,凸显了加强物联网边缘防御的必要性。

AI 中文摘要

基于机器学习的入侵检测系统(IDS)越来越多地用于资源受限的物联网(IoT)环境中,然而其鲁棒性通常是在静态攻击下进行评估,而非针对能适应检测反馈的对抗者。本文研究了在树莓派3B+上部署的基于ML的IDS模型下的自适应端口扫描规避问题。我们实现了一个基于Zeek的实时IDS流水线,使用XGBoost、多层感知器和一维卷积神经网络,这些模型在TON_IoT遥测数据上训练,并使用深度Q网络(DQN)对抗者在黑盒、灰盒和白盒特征可见性设置下学习探测时序、TCP标志和负载大小的规避组合。尽管部署的IDS模型对常规端口扫描的检测率为91.1%至99.8%,但DQN最后50个回合的规避率在不同特征可见性设置下介于61.9%至98.3%之间。更高的特征可见性并不单调地提高规避效果,其影响因模型而异:针对XGBoost,黑盒智能体达到92.9%的规避率,而灰盒和白盒智能体分别为61.9%和76.9%;而一维CNN在白盒访问下最脆弱,规避率为98.1%。由于标准DQN可能高估动作值,我们额外使用Double DQN对代表性条件进行了抽查。灰盒条件在此检查中仍不稳定,没有证据表明高估偏差单独能解释观察到的稳定性问题。这些结果表明,有限的特征知识仍能对静态边缘部署的IDS模型实现有效的自适应规避,这促使需要为物联网边缘环境设计更鲁棒的防御措施。

英文摘要

Machine learning-based intrusion detection systems (IDS) are increasingly used in resource-constrained Internet of Things (IoT) environments, yet their robustness is often evaluated against static attacks rather than adversaries that adapt to detection feedback. This paper investigates adaptive port-scan evasion against ML-based IDS models deployed on a Raspberry Pi 3B+. We implement a live Zeek-based IDS pipeline with XGBoost, a multi-layer perceptron, and a 1D convolutional neural network trained on TON_IoT telemetry, and use a Deep Q-Network (DQN) adversary to learn evasive combinations of probe timing, TCP flags, and payload size under black-box, gray-box, and white-box feature-visibility settings. Although the deployed IDS models detect conventional port scans at 91.1--99.8%, DQN final-50-episode evasion rates range from 61.9% to 98.3% across feature-visibility settings. Greater feature visibility does not monotonically improve evasion, and its effect is model-dependent: against XGBoost, the black-box agent achieves 92.9% evasion, compared with 61.9% and 76.9% for gray-box and white-box agents, respectively, whereas 1D-CNN is most vulnerable under white-box access at 98.1%. Because standard DQN can overestimate action values, we additionally spot-check representative conditions using Double DQN. The gray-box condition remains unstable in this check, providing no evidence that overestimation bias alone explains the observed instability. These results show that limited feature knowledge can still enable effective adaptive evasion against static edge-deployed IDS models, motivating more robust defenses for IoT edge environments.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑