In the past few years, Convolutional Neural Networks (CNN) have demonstrated promising performance in various real-world cybersecurity applications, such as network and multimedia security. However, the underlying fragility of CNN structures poses major security problems, making them inappropriate for use in security-oriented applications including such computer networks. Protecting these architectures from adversarial attacks necessitates using security-wise architectures that are challenging to attack. In this study, we present a novel architecture based on an ensemble classifier that combines the enhanced security of 1-Class classification (known as 1C) with the high performance of conventional 2-Class classification (known as 2C) in the absence of attacks.Our architecture is referred to as the 1.5-Class (SPRITZ-1.5C) classifier and constructed using a final dense classifier, one 2C classifier (i.e., CNNs), and two parallel 1C classifiers (i.e., auto-encoders). In our experiments, we evaluated the robustness of our proposed architecture by considering eight possible adversarial attacks in various scenarios. We performed these attacks on the 2C and SPRITZ-1.5C architectures separately. The experimental results of our study showed that the Attack Success Rate (ASR) of the I-FGSM attack against a 2C classifier trained with the N-BaIoT dataset is 0.9900. In contrast, the ASR is 0.0000 for the SPRITZ-1.5C classifier.
翻译:在过去几年中,卷积神经网络(CNN)在网络和多媒体安全等多种真实世界网络安全应用中展现了良好的性能。然而,CNN结构固有的脆弱性带来了重大安全问题,使其不适用于包括计算机网络在内的安全导向型应用。保护这些架构免受对抗攻击需要采用难以被攻击的安全型架构。在本研究中,我们提出了一种基于集成分类器的新颖架构,该架构结合了一类分类(简称1C)的增强安全性与传统二类分类(简称2C)在无攻击情况下的高性能。我们的架构被称为1.5类(SPRITZ-1.5C)分类器,由最终密集分类器、一个2C分类器(即CNN)和两个并行1C分类器(即自编码器)构成。在实验中,我们通过考虑多种场景下的八种可能的对抗攻击,评估了所提架构的鲁棒性。我们分别对2C和SPRITZ-1.5C架构实施了这些攻击。实验结果表明,针对使用N-BaIoT数据集训练的2C分类器,I-FGSM攻击的成功率(ASR)为0.9900。相比之下,SPRITZ-1.5C分类器的ASR为0.0000。