提出针对DRL入侵检测系统的新型通用扰动攻击,更贴近真实网络环境。
A Novel and Practical Universal Adversarial Perturbations against Deep Reinforcement Learning based Intrusion Detection Systems
- 基于网络数据规则与特征关系设计约束下的通用扰动生成方法。
- 新损失函数结合皮尔逊相关系数,提升攻击在真实场景的逃逸率。
- 首次在DRL-IDS中应用皮尔逊系数优化扰动,适合安全研究者参考。
入侵检测系统(IDS)在防御现代网络物理系统日益复杂的网络威胁中发挥关键作用。基于深度强化学习的IDS因其自适应与泛化能力展现出潜力,但近期研究揭示其易受对抗攻击影响,包括通用对抗扰动(UAP),即用单一、输入无关的扰动即可欺骗模型。本文提出一种针对基于深度强化学习的入侵检测系统(DRL-based IDS)的新UAP攻击方法,该方法在由网络数据规则和特征间数学关系构成的领域特定约束下进行。据我们所知,这是首个研究面向DRL-IDS的UAP生成的工作。此外,本工作首次在真实域约束下,结合基础规则与特征间数学关系构建UAP。为提升逃逸性能,引入基于皮尔逊相关系数(PCC)的定制化损失函数,称为Customized UAP。据我们所知,这也是首个在UAP生成中使用PCC值的工作。对比四种现有UAP基线及两种输入依赖型攻击(FGSM、BIM),实验结果表明,所提Customized UAP在真实对抗场景中显著优于其他方法,验证了其有效性。
原文摘要 · Abstract (English)
Intrusion Detection Systems (IDS) play a vital role in defending modern cyber physical systems against increasingly sophisticated cyber threats. Deep Reinforcement Learning-based IDS, have shown promise due to their adaptive and generalization capabilities. However, recent studies reveal their vulnerability to adversarial attacks, including Universal Adversarial Perturbations (UAPs), which can deceive models with a single, input-agnostic perturbation. In this work, we propose a novel UAP attack against Deep Reinforcement Learning (DRL)-based IDS under the domain-specific constraints derived from network data rules and feature relationships. To the best of our knowledge, there is no existing study that has explored UAP generation for the DRL-based IDS. In addition, this is the first work that focuses on developing a UAP against a DRL-based IDS under realistic domain constraints based on not only the basic domain rules but also mathematical relations between the features. Furthermore, we enhance the evasion performance of the proposed UAP, by introducing a customized loss function based on the Pearson Correlation Coefficient, and we denote it as Customized UAP. To the best of our knowledge, this is also the first work using the PCC value in the UAP generation, even in the broader context. Four additional established UAP baselines are implemented for a comprehensive comparison. Experimental results demonstrate that our proposed Customized UAP outperforms two input-dependent attacks including Fast Gradient Sign Method (FGSM), Basic Iterative Method (BIM), and four UAP baselines, highlighting its effectiveness for real-world adversarial scenarios.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。