arXiv:2506.21142cs.LGcs.AI2025-06被引 3

用生成模型制造能骗过无人机入侵检测的隐蔽攻击,并设计新方法识别这类攻击。

Generative Adversarial Evasion and Out-of-Distribution Detection for UAV Cyber-Attacks

  • 用条件GAN生成能伪装成正常数据的隐蔽攻击样本。
  • 生成的攻击样本在测试中92%以上成功绕过检测,且与异常数据统计特征相似。
  • 提出基于CVAE的新检测器,比传统方法更擅长区分恶意攻击和真实异常。

无人机日益融入民用空域,亟需具备抗干扰能力的智能入侵检测系统(IDS),因传统异常检测难以识别新型威胁。通常将未知攻击视为分布外(OOD)样本,但若应对不足则系统仍易受攻击。此外,传统OOD检测器难以区分隐蔽对抗攻击与真实OOD事件。本文提出一种基于条件生成对抗网络(cGAN)的框架,用于生成可逃避IDS机制的隐蔽对抗攻击。首先训练一个鲁棒的多类IDS分类器,基于正常无人机遥测数据及已知攻击(包括拒绝服务、虚假数据注入、中间人攻击和重放攻击)。利用该分类器,cGAN对已知攻击进行扰动,生成被误判为正常的对抗样本,同时保持其统计特性与OOD分布一致。通过迭代优化,提升攻击的隐蔽性与成功率。为检测此类扰动,我们实现了一种条件变分自编码器(CVAE),利用负对数似然区分对抗输入与真实OOD样本。对比实验表明,基于CVAE的后悔分数显著优于传统马氏距离检测器,在识别隐蔽对抗威胁方面表现更佳。研究强调了先进概率建模对抵御生成式自适应网络攻击的重要性。

原文摘要 · Abstract (English)

The growing integration of UAVs into civilian airspace underscores the need for resilient and intelligent intrusion detection systems (IDS), as traditional anomaly detection methods often fail to identify novel threats. A common approach treats unfamiliar attacks as out-of-distribution (OOD) samples; however, this leaves systems vulnerable when mitigation is inadequate. Moreover, conventional OOD detectors struggle to distinguish stealthy adversarial attacks from genuine OOD events. This paper introduces a conditional generative adversarial network (cGAN)-based framework for crafting stealthy adversarial attacks that evade IDS mechanisms. We first design a robust multi-class IDS classifier trained on benign UAV telemetry and known cyber-attacks, including Denial of Service (DoS), false data injection (FDI), man-in-the-middle (MiTM), and replay attacks. Using this classifier, our cGAN perturbs known attacks to generate adversarial samples that misclassify as benign while retaining statistical resemblance to OOD distributions. These adversarial samples are iteratively refined to achieve high stealth and success rates. To detect such perturbations, we implement a conditional variational autoencoder (CVAE), leveraging negative log-likelihood to separate adversarial inputs from authentic OOD samples. Comparative evaluation shows that CVAE-based regret scores significantly outperform traditional Mahalanobis distance-based detectors in identifying stealthy adversarial threats. Our findings emphasize the importance of advanced probabilistic modeling to strengthen IDS capabilities against adaptive, generative-model-based cyber intrusions.

无人机安全对抗攻击生成模型入侵检测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。