arXiv:2510.19761cs.CRcs.LG2025-10被引 2

深度神经网络在入侵检测中越深越不抗攻击,与图像领域相反。

Exploring the Effect of DNN Depth on Adversarial Attacks in Network Intrusion Detection Systems

  • 对比不同深度的DNN在入侵检测中的抗攻击能力
  • 深度增加会显著降低NIDS系统的鲁棒性
  • 研究结果对安全领域模型设计有重要指导意义

对抗攻击对机器学习系统特别是深度神经网络(DNN)构成重大挑战,通过细微输入扰动诱导错误预测。本文探究增加DNN层深是否影响其在网络入侵检测系统(NIDS)中对抗攻击的鲁棒性。我们在NIDS与计算机视觉领域对比多种深度神经网络的抗攻击表现。实验发现,在NIDS领域,增加层数虽未必提升性能,却可能显著降低模型鲁棒性;而在计算机视觉领域,深度增加对鲁棒性影响较温和。该结果为构建面向NIDS的稳健神经网络提供依据,并揭示了网络安全领域在机器学习中的独特性。

原文摘要 · Abstract (English)

Adversarial attacks pose significant challenges to Machine Learning (ML) systems and especially Deep Neural Networks (DNNs) by subtly manipulating inputs to induce incorrect predictions. This paper investigates whether increasing the layer depth of deep neural networks affects their robustness against adversarial attacks in the Network Intrusion Detection System (NIDS) domain. We compare the adversarial robustness of various deep neural networks across both \ac{NIDS} and computer vision domains (the latter being widely used in adversarial attack experiments). Our experimental results reveal that in the NIDS domain, adding more layers does not necessarily improve their performance, yet it may actually significantly degrade their robustness against adversarial attacks. Conversely, in the computer vision domain, adding more layers exhibits a more modest impact on robustness. These findings can guide the development of robust neural networks for (NIDS) applications and highlight the unique characteristics of network security domains within the (ML) landscape.

入侵检测对抗攻击深度学习鲁棒性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。