Network Intrusion Detection Systems (NIDS) heavily utlize Machine Learning (ML) but ML models can be manipulated via adversarial attacks. These attacks add carefully crafted perturbations to network traffic data that leads to misclassifications. While prior work has demonstrated adversarial vulnerabilities in isolated settings, systematic cross-architecture as well as class and category of attack based comparisons under controlled attack conditions remain limited, leaving practitioners without clear guidance on which models to deploy in adversarial environments. This paper asks a simple question: what type of classifier architectures actually hold up when attackers try to manipulate the systems? We put three popular architectures through their paces: a 1D Convolutional Neural Network, a Long Short-Term Memory (LSTM) network, and a Random Forest (RF) ensemble. Using the ACI-IoT-2023 dataset (over 1.2 million samples spanning 12 attack types), we subject each model with FGSM and PGD adversarial attacks, which apply gradient-based perturbations in normalized feature space consistent with established adversarial ML evaluation protocols, at perturbation budgets ranging from $ε=0.01$ to $ε=0.1$. Surprisingly, Random Forest achieved near-perfect baseline accuracy (99.98\%), yet collapsed catastrophically under attack, dropping 73 percentage points at the smallest perturbation we tested. CNN, on the other hand, retained 95.5\% accuracy at $ε=0.01$ and degraded gracefully as perturbations increased. LSTM fell somewhere in between. These findings flip the conventional wisdom where high baseline accuracy means nothing if a model shatters at the first sign of adversarial pressure. For practitioners deploying intrusion detection in adversarial environments, we recommend CNN-based architectures and provide scenario-specific deployment guidance.


翻译:网络入侵检测系统(NIDS)广泛利用机器学习(ML),但ML模型可能遭受对抗性攻击的操纵。这些攻击向网络流量数据添加精心设计的扰动,导致分类错误。尽管已有研究在孤立场景中揭示了对抗性漏洞,但在受控攻击条件下,系统性的跨架构比较以及基于攻击类别与类型的对比仍然有限,这使得实践者在对抗性环境中部署模型时缺乏明确指导。本文提出一个简单问题:当攻击者试图操纵系统时,何种分类器架构实际上能保持稳健?我们对三种流行架构进行了测试:一维卷积神经网络(1D-CNN)、长短期记忆网络(LSTM)和随机森林(RF)集成。使用ACI-IoT-2023数据集(包含超过120万样本,涵盖12种攻击类型),我们分别对每个模型施加FGSM和PGD对抗性攻击,这些攻击在归一化特征空间中应用基于梯度的扰动,遵循已建立的对抗性ML评估协议,扰动预算范围为ε=0.01至ε=0.1。令人惊讶的是,随机森林的基线准确率近乎完美(99.98%),但在攻击下灾难性崩溃,即使在我们测试的最小扰动下,准确率也骤降73个百分点。相比之下,CNN在ε=0.01时保持95.5%的准确率,并随扰动增加而逐渐下降。LSTM的性能则介于两者之间。这些发现颠覆了传统认知:如果模型在对抗压力下瞬间崩溃,高基线准确率毫无意义。对于在对抗性环境中部署入侵检测系统的实践者,我们推荐基于CNN的架构,并提供场景特定的部署指导。

0
下载
关闭预览

相关内容

Networking:IFIP International Conferences on Networking。 Explanation:国际网络会议。 Publisher:IFIP。 SIT: http://dblp.uni-trier.de/db/conf/networking/index.html
基于深度学习的入侵检测系统:综述
专知会员服务
16+阅读 · 2025年4月11日
面向图像分类的对抗鲁棒性评估综述
专知会员服务
59+阅读 · 2022年10月15日
对抗机器学习在网络入侵检测领域的应用
专知会员服务
35+阅读 · 2022年1月4日
模型攻击:鲁棒性联邦学习研究的最新进展
机器之心
35+阅读 · 2020年6月3日
NetworkMiner - 网络取证分析工具
黑白之道
16+阅读 · 2018年6月29日
国家自然科学基金
2+阅读 · 2017年12月31日
国家自然科学基金
6+阅读 · 2015年12月31日
国家自然科学基金
19+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2014年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
4+阅读 · 2014年12月31日
VIP会员
最新内容
致命七类无人机:无人机时代的演进型合成兵种
专知会员服务
1+阅读 · 15分钟前
《异构无人水面艇集群作战自主制导算法》130页
《人工智能能通过美国陆军战争学院吗?》报告
军事域人工智能驱动系统的治理
专知会员服务
4+阅读 · 9月14日
相关基金
国家自然科学基金
2+阅读 · 2017年12月31日
国家自然科学基金
6+阅读 · 2015年12月31日
国家自然科学基金
19+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2014年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
4+阅读 · 2014年12月31日
Top
微信扫码咨询专知VIP会员