arXiv:2409.12472cs.CRcs.AI2024-09被引 12

提出针对RNN的时序对抗攻击模型,揭示攻击与时间步的关联性。

TEAM: Temporal Adversarial Examples Attack Model against Network Intrusion Detection System Applied to RNN

  • 基于特征重构设计时序对抗攻击,利用历史攻击影响后续样本
  • 在黑白盒测试中使误判率超96.68%,后续样本误判率提升超95.57%
  • 引入时间膨胀机制缓解同时间步攻击间的时序干扰,适合安全检测研究者

随着人工智能的发展,神经网络在网络安全入侵检测系统(NIDS)中发挥关键作用。尽管优势显著,神经网络仍易受对抗攻击影响。为提升NIDS可靠性,已有大量研究和解决方案提出,但现有方法很少关注具有时间步的循环神经网络(RNN)所面临的对抗攻击,这严重影响了NIDS在真实场景的应用。为此,本文首次提出一种基于特征重构的新型RNN对抗攻击模型——时序对抗样本攻击模型(TEAM),适用于时间序列数据,并揭示了对抗样本与时间步之间的潜在关联:同一时间步内的历史对抗样本可引发对当前或未来原始样本的进一步攻击。此外,TEAM采用时间膨胀(TD)有效缓解了同一时间步内对抗样本间的时序影响。实验结果表明,在大多数攻击类别中,TEAM使黑白盒环境下NIDS的误判率超过96.68%;同时,对后续原始样本的误判率最大提升超过95.57%。

原文摘要 · Abstract (English)

With the development of artificial intelligence, neural networks play a key role in network intrusion detection systems (NIDS). Despite the tremendous advantages, neural networks are susceptible to adversarial attacks. To improve the reliability of NIDS, many research has been conducted and plenty of solutions have been proposed. However, the existing solutions rarely consider the adversarial attacks against recurrent neural networks (RNN) with time steps, which would greatly affect the application of NIDS in real world. Therefore, we first propose a novel RNN adversarial attack model based on feature reconstruction called \textbf{T}emporal adversarial \textbf{E}xamples \textbf{A}ttack \textbf{M}odel \textbf{(TEAM)}, which applied to time series data and reveals the potential connection between adversarial and time steps in RNN. That is, the past adversarial examples within the same time steps can trigger further attacks on current or future original examples. Moreover, TEAM leverages Time Dilation (TD) to effectively mitigates the effect of temporal among adversarial examples within the same time steps. Experimental results show that in most attack categories, TEAM improves the misjudgment rate of NIDS on both black and white boxes, making the misjudgment rate reach more than 96.68%. Meanwhile, the maximum increase in the misjudgment rate of the NIDS for subsequent original samples exceeds 95.57%.

对抗攻击RNN入侵检测时序建模

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。