arXiv:2509.26350cs.CRcs.AI2025-09被引 9

系统分析了SDN-IoT中深度学习异常检测的对抗攻击威胁

SoK: Systematic analysis of adversarial threats against deep learning approaches for autonomous anomaly detection systems in SDN-IoT networks

  • 构建结构化威胁模型,分类数据、模型、混合三类攻击
  • 实测攻击使检测准确率最高下降48.4%,成员推断影响最严重
  • 提出实时防御、增强重训练等对策,适配安全研究者与工程师

将SDN与IoT融合可提升网络控制与灵活性。基于深度学习的异常检测(AAD)系统能实现对SDN-IoT网络中威胁的实时识别,但其仍易受对抗攻击影响,此类攻击通过操纵输入数据或利用模型弱点,显著降低检测精度。现有研究缺乏对深度学习驱动的SDN-IoT异常检测系统在对抗威胁方面的系统性分析。本文提出一种结构化对抗威胁模型,并建立全面攻击分类体系,将攻击分为数据级、模型级与混合级三类。不同于以往研究,我们系统评估了白盒、黑盒与灰盒攻击策略在主流基准数据集上的表现。结果表明,对抗攻击可使检测准确率下降高达48.4%,其中成员推断攻击造成最大降幅;C&W与DeepFool方法表现出高逃避成功率。尽管对抗训练可提升鲁棒性,但其高计算开销限制了其在实时性要求高的SDN-IoT场景中的部署。为此,本文提出自适应防御机制,包括实时对抗干扰缓解、增强重训练策略以及可解释人工智能驱动的安全框架。通过整合结构化威胁模型,本研究在攻击分类、影响评估与防御评价方面较以往研究更具系统性。研究揭示了现有深度学习驱动异常检测模型的关键脆弱点,并为提升韧性、可解释性与计算效率提供了实践建议。本工作为研究人员与从业者提升SDN-IoT环境中深度学习异常检测系统的安全性提供了基础参考。

原文摘要 · Abstract (English)

Integrating SDN and the IoT enhances network control and flexibility. DL-based AAD systems improve security by enabling real-time threat detection in SDN-IoT networks. However, these systems remain vulnerable to adversarial attacks that manipulate input data or exploit model weaknesses, significantly degrading detection accuracy. Existing research lacks a systematic analysis of adversarial vulnerabilities specific to DL-based AAD systems in SDN-IoT environments. This SoK study introduces a structured adversarial threat model and a comprehensive taxonomy of attacks, categorising them into data, model, and hybrid-level threats. Unlike previous studies, we systematically evaluate white, black, and grey-box attack strategies across popular benchmark datasets. Our findings reveal that adversarial attacks can reduce detection accuracy by up to 48.4%, with Membership Inference causing the most significant drop. C&W and DeepFool achieve high evasion success rates. However, adversarial training enhances robustness, and its high computational overhead limits the real-time deployment of SDN-IoT applications. We propose adaptive countermeasures, including real-time adversarial mitigation, enhanced retraining mechanisms, and explainable AI-driven security frameworks. By integrating structured threat models, this study offers a more comprehensive approach to attack categorisation, impact assessment, and defence evaluation than previous research. Our work highlights critical vulnerabilities in existing DL-based AAD models and provides practical recommendations for improving resilience, interpretability, and computational efficiency. This study serves as a foundational reference for researchers and practitioners seeking to enhance DL-based AAD security in SDN-IoT networks, offering a systematic adversarial threat model and conceptual defence evaluation based on prior empirical studies.

对抗攻击SDN-IoT异常检测安全防御

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。