Cross-site scripting (XSS) poses a significant threat to web application security. While Deep Learning (DL) has shown remarkable success in detecting XSS attacks, it remains vulnerable to adversarial attacks due to the discontinuous nature of the mapping between the input (i.e., the attack) and the output (i.e., the prediction of the model whether an input is classified as XSS or benign). These adversarial attacks employ mutation-based strategies for different components of XSS attack vectors, allowing adversarial agents to iteratively select mutations to evade detection. Our work replicates a state-of-the-art XSS adversarial attack, highlighting threats to validity in the reference work and extending it towards a more effective evaluation strategy. Moreover, we introduce an XSS Oracle to mitigate these threats. The experimental results show that our approach achieves an escape rate above 96% when the threats to validity of the replicated technique are addressed.


翻译:跨站脚本攻击对Web应用安全构成重大威胁。尽管深度学习在检测XSS攻击方面取得了显著成功,但由于输入(即攻击)与输出(即模型预测输入被分类为XSS或良性)之间映射的非连续性,其仍易受对抗攻击。这些对抗攻击对XSS攻击向量的不同组件采用基于变异的策略,使对抗代理能够迭代选择变异以逃避检测。我们的工作复现了一种最先进的XSS对抗攻击,揭示了原始研究中的效度威胁,并将其扩展为更有效的评估策略。此外,我们引入了一种XSS预言机以缓解这些威胁。实验结果表明,当复现技术的效度威胁得到解决时,我们的方法实现了超过96%的逃逸率。

0
下载
关闭预览

相关内容

面向深度学习的后门攻击及防御研究综述
专知会员服务
13+阅读 · 2025年7月4日
深度学习模型反演攻击与防御:全面综述
专知会员服务
27+阅读 · 2025年2月3日
面向深度强化学习的对抗攻防综述
专知会员服务
66+阅读 · 2023年8月2日
对抗机器学习在网络入侵检测领域的应用
专知会员服务
35+阅读 · 2022年1月4日
专知会员服务
49+阅读 · 2021年5月17日
深度学习赋能的恶意代码攻防研究进展
专知会员服务
31+阅读 · 2021年4月11日
专知会员服务
97+阅读 · 2021年1月17日
专知会员服务
100+阅读 · 2020年12月8日
国家自然科学基金
6+阅读 · 2017年12月31日
国家自然科学基金
43+阅读 · 2015年12月31日
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
19+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
31+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
4+阅读 · 2014年12月31日
VIP会员
最新内容
非对称防御中的自组织临界性:俄乌战争
专知会员服务
6+阅读 · 8月10日
《战争中的大语言模型监管》
专知会员服务
5+阅读 · 8月10日
《边缘计算关键技术分析及美军作战实践应用》
边缘计算的军事应用
专知会员服务
9+阅读 · 8月9日
一种考虑资源机动性的武器目标分配混合算法
专知会员服务
11+阅读 · 8月8日
相关VIP内容
面向深度学习的后门攻击及防御研究综述
专知会员服务
13+阅读 · 2025年7月4日
深度学习模型反演攻击与防御:全面综述
专知会员服务
27+阅读 · 2025年2月3日
面向深度强化学习的对抗攻防综述
专知会员服务
66+阅读 · 2023年8月2日
对抗机器学习在网络入侵检测领域的应用
专知会员服务
35+阅读 · 2022年1月4日
专知会员服务
49+阅读 · 2021年5月17日
深度学习赋能的恶意代码攻防研究进展
专知会员服务
31+阅读 · 2021年4月11日
专知会员服务
97+阅读 · 2021年1月17日
专知会员服务
100+阅读 · 2020年12月8日
相关基金
国家自然科学基金
6+阅读 · 2017年12月31日
国家自然科学基金
43+阅读 · 2015年12月31日
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
19+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
31+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
4+阅读 · 2014年12月31日
Top
微信扫码咨询专知VIP会员