提出一种低交互自适应攻击方法,有效绕过网络入侵检测系统。
Vulnerability Disclosure through Adaptive Black-Box Adversarial Attacks on NIDS
- 通过变化点检测与因果分析动态选择敏感特征进行扰动
- 仅需极少交互即可实现高规避率,计算开销小
- 适合研究网络安全漏洞或防御机制的从业者
对抗攻击通过微小输入扰动误导智能模型,日益受到关注。然而,理论进展与实际应用之间仍存在显著差距,尤其在具有依赖关系的网络流量等结构化数据中,有效生成对抗样本面临挑战。现有方法存在可复现性差、交互频繁等问题,导致防御难以应对持续演化的攻击。本文提出一种严格遵循黑盒约束的新型对抗攻击方法,避免系统访问或反复探测,降低被检测风险,更贴近真实场景。通过变化点检测与因果分析实现自适应特征选择,精准定位易受攻击特征。该轻量级设计具备低计算成本与高部署性。大量实验表明,该方法在极少交互下仍能高效规避检测,显著提升适应性与实用性。本工作深化了对网络流量中对抗攻击的理解,为构建鲁棒防御体系奠定基础。
原文摘要 · Abstract (English)
Adversarial attacks, wherein slight inputs are carefully crafted to mislead intelligent models, have attracted increasing attention. However, a critical gap persists between theoretical advancements and practical application, particularly in structured data like network traffic, where interdependent features complicate effective adversarial manipulations. Moreover, ambiguity in current approaches restricts reproducibility and limits progress in this field. Hence, existing defenses often fail to handle evolving adversarial attacks. This paper proposes a novel approach for black-box adversarial attacks, that addresses these limitations. Unlike prior work, which often assumes system access or relies on repeated probing, our method strictly respect black-box constraints, reducing interaction to avoid detection and better reflect real-world scenarios. We present an adaptive feature selection strategy using change-point detection and causality analysis to identify and target sensitive features to perturbations. This lightweight design ensures low computational cost and high deployability. Our comprehensive experiments show the attack's effectiveness in evading detection with minimal interaction, enhancing its adaptability and applicability in real-world scenarios. By advancing the understanding of adversarial attacks in network traffic, this work lays a foundation for developing robust defenses.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。