用SHAP指纹识别恶意数据,提升物联网入侵检测抗攻击能力
Enhancing Adversarial Robustness of IoT Intrusion Detection via SHAP-Based Attribution Fingerprinting
- 通过SHAP提取网络特征的归因指纹,识别异常输入
- 在标准数据集上检测准确率显著优于现有方法
- 既增强防御力又提升模型可解释性,适合安全可信场景
物联网设备的快速普及推动了各行业的连接与自动化,但也带来了日益复杂的网络安全威胁,尤其是针对基于人工智能和机器学习的入侵检测系统(IDS)的对抗攻击,可能诱使系统误判并破坏安全防线。为应对这一挑战,本文提出一种新型对抗检测模型,利用SHapley Additive exPlanations(SHAP)中的DeepExplainer提取网络流量特征的归因指纹,使IDS能够可靠区分正常与对抗扰动输入。通过捕捉细微的归因模式,模型对逃避检测和对抗操纵更具鲁棒性。在标准物联网基准数据集上的实验表明,该方法显著优于当前最优方法。此外,该方案还提升了模型透明度与可解释性,增强了用户对入侵检测系统的信任。
原文摘要 · Abstract (English)
The rapid proliferation of Internet of Things (IoT) devices has transformed numerous industries by enabling seamless connectivity and data-driven automation. However, this expansion has also exposed IoT networks to increasingly sophisticated security threats, including adversarial attacks targeting artificial intelligence (AI) and machine learning (ML)-based intrusion detection systems (IDS) to deliberately evade detection, induce misclassification, and systematically undermine the reliability and integrity of security defenses. To address these challenges, we propose a novel adversarial detection model that enhances the robustness of IoT IDS against adversarial attacks through SHapley Additive exPlanations (SHAP)-based fingerprinting. Using SHAP's DeepExplainer, we extract attribution fingerprints from network traffic features, enabling the IDS to reliably distinguish between clean and adversarially perturbed inputs. By capturing subtle attribution patterns, the model becomes more resilient to evasion attempts and adversarial manipulations. We evaluated the model on a standard IoT benchmark dataset, where it significantly outperformed a state-of-the-art method in detecting adversarial attacks. In addition to enhanced robustness, this approach improves model transparency and interpretability, thereby increasing trust in the IDS through explainable AI.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。