arXiv:2505.01328cs.CRcs.AI2025-05被引 6

提出考虑物联网约束的对抗攻击方法,发现旧方法80.3%样本无效

Constrained Network Adversarial Attacks: Validity, Robustness, and Transferability

  • 引入物联网数据约束,生成符合实际的对抗样本
  • 80.3%现有对抗样本因违反约束而无效,误导安全评估
  • MLP作为代理模型生成更有效且可迁移的攻击,适合安全研究者

尽管机器学习显著提升了网络入侵检测系统(NIDS)性能,尤其在生成大量数据且易受攻击的物联网(IoT)环境中,这些模型仍易受对抗攻击影响。本研究揭示现有对抗攻击方法的关键缺陷:频繁违反物联网与网络流量固有的数值和类别约束。这导致高达80.3%的对抗样本无效,严重夸大真实世界中的漏洞风险。这些无效样本虽能欺骗模型,却无法在实际物联网部署中实施,依赖此类结果可能导致防御资源错配,误判模型脆弱性。此外,我们发现较简单的替代模型(如多层感知机,MLP)比复杂架构(如CNN、LSTM)生成更多有效对抗样本。以MLP为代理,分析了对抗严重性向其他常用物联网机器学习/深度学习模型的迁移能力。本工作强调在评估和设计安全关键的物联网与网络应用中,必须同时考虑领域约束与模型架构。

原文摘要 · Abstract (English)

While machine learning has significantly advanced Network Intrusion Detection Systems (NIDS), particularly within IoT environments where devices generate large volumes of data and are increasingly susceptible to cyber threats, these models remain vulnerable to adversarial attacks. Our research reveals a critical flaw in existing adversarial attack methodologies: the frequent violation of domain-specific constraints, such as numerical and categorical limits, inherent to IoT and network traffic. This leads to up to 80.3% of adversarial examples being invalid, significantly overstating real-world vulnerabilities. These invalid examples, though effective in fooling models, do not represent feasible attacks within practical IoT deployments. Consequently, relying on these results can mislead resource allocation for defense, inflating the perceived susceptibility of IoT-enabled NIDS models to adversarial manipulation. Furthermore, we demonstrate that simpler surrogate models like Multi-Layer Perceptron (MLP) generate more valid adversarial examples compared to complex architectures such as CNNs and LSTMs. Using the MLP as a surrogate, we analyze the transferability of adversarial severity to other ML/DL models commonly used in IoT contexts. This work underscores the importance of considering both domain constraints and model architecture when evaluating and designing robust ML/DL models for security-critical IoT and network applications.

对抗攻击物联网安全约束生成模型迁移

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。