arXiv:2409.18244cs.CRcs.LG2024-09中稿 · Dynamic Data Drive…被引 2

提出边缘机器学习架构reML,抵御工业控制系统中的对抗攻击。

Development of an Edge Resilient ML Ensemble to Tolerate ICS Adversarial Attacks

  • 用深度神经网络对数据特征空间进行匿名化处理,实现数据空气间隙转换。
  • 通过随机化预测模型提升系统鲁棒性,在真实ICS数据集上验证有效。
  • 适合资源受限设备部署,兼具低功耗与隐私保护优势,适用于工业场景。

在动态数据驱动应用系统(DDDAS)中部署机器学习(ML)可提升工业控制系统的安全性。然而,基于ML的DDDAS易受对抗攻击:攻击者仅需微调输入数据,即可诱导模型输出错误结果。本文旨在构建一种抗干扰边缘机器学习(reML)架构,通过数据空气间隙转换(DAGT)技术,利用深度神经网络对数据特征空间进行匿名化,并随机化用于预测的模型,从而增强系统韧性。reML基于弹性DDDAS范式、移动目标防御(MTD)理论及TinyML,适配工业控制系统安全需求。该方案具备低功耗与隐私保护特性,可在资源受限设备上部署,将计算从高能耗平台迁移至边缘端。结合TensorFlow Lite的TinyML确保高效资源利用,使reML适用于多种工业控制环境。其动态特性依托弹性DDDAS开发环境,可持续适应新型威胁。实验基于真实ICS数据集,验证了reML在边缘端实现稳健机器学习推理的可行性与有效性。

原文摘要 · Abstract (English)

Deploying machine learning (ML) in dynamic data-driven applications systems (DDDAS) can improve the security of industrial control systems (ICS). However, ML-based DDDAS are vulnerable to adversarial attacks because adversaries can alter the input data slightly so that the ML models predict a different result. In this paper, our goal is to build a resilient edge machine learning (reML) architecture that is designed to withstand adversarial attacks by performing Data Air Gap Transformation (DAGT) to anonymize data feature spaces using deep neural networks and randomize the ML models used for predictions. The reML is based on the Resilient DDDAS paradigm, Moving Target Defense (MTD) theory, and TinyML and is applied to combat adversarial attacks on ICS. Furthermore, the proposed approach is power-efficient and privacy-preserving and, therefore, can be deployed on power-constrained devices to enhance ICS security. This approach enables resilient ML inference at the edge by shifting the computation from the computing-intensive platforms to the resource-constrained edge devices. The incorporation of TinyML with TensorFlow Lite ensures efficient resource utilization and, consequently, makes reML suitable for deployment in various industrial control environments. Furthermore, the dynamic nature of reML, facilitated by the resilient DDDAS development environment, allows for continuous adaptation and improvement in response to emerging threats. Lastly, we evaluate our approach on an ICS dataset and demonstrate that reML provides a viable and effective solution for resilient ML inference at the edge devices.

边缘计算对抗攻击工业安全TinyML

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。