arXiv:2512.02276cs.NIcs.CR2025-12中稿 · the 2025 IEEE Inte…被引 1

轻量级网络中输入结构影响流量分类的抗攻击能力

Adversarial Robustness of Traffic Classification under Resource Constraints: Input Structure Matters

  • 对比平铺字节序列与二维包时序两种输入结构
  • 时序输入模型在攻击下准确率骤降至35%以下
  • 输入结构设计对边缘安全部署至关重要

流量分类(TC)在物联网和嵌入式场景中至关重要,需在硬件资源受限条件下本地化检测。本文采用硬件感知神经架构搜索(HW-NAS)构建轻量级TC模型,在保持65k参数与2M FLOPs限制的前提下,于USTC-TFC2016数据集上均实现超过99%的干净数据准确率。比较平铺字节序列与二维包时序两种输入结构,发现二者在对抗攻击下表现差异显著:当扰动强度为0.1时,平铺模型仍保持85%以上准确率,而时序模型准确率低于35%。通过对抗微调,平铺模型鲁棒性提升至96%以上,时序模型鲁棒性提升超60个百分点,且不牺牲效率。结果表明,输入结构直接影响对抗脆弱性,即使紧凑高效模型也可实现强鲁棒性,支持其在边缘安全分类中的实际应用。

原文摘要 · Abstract (English)

Traffic classification (TC) plays a critical role in cybersecurity, particularly in IoT and embedded contexts, where inspection must often occur locally under tight hardware constraints. We use hardware-aware neural architecture search (HW-NAS) to derive lightweight TC models that are accurate, efficient, and deployable on edge platforms. Two input formats are considered: a flattened byte sequence and a 2D packet-wise time series; we examine how input structure affects adversarial vulnerability when using resource-constrained models. Robustness is assessed against white-box attacks, specifically Fast Gradient Sign Method (FGSM) and Projected Gradient Descent (PGD). On USTC-TFC2016, both HW-NAS models achieve over 99% clean-data accuracy while remaining within 65k parameters and 2M FLOPs. Yet under perturbations of strength 0.1, their robustness diverges: the flat model retains over 85% accuracy, while the time-series variant drops below 35%. Adversarial fine-tuning delivers robust gains, with flat-input accuracy exceeding 96% and the time-series variant recovering over 60 percentage points in robustness, all without compromising efficiency. The results underscore how input structure influences adversarial vulnerability, and show that even compact, resource-efficient models can attain strong robustness, supporting their practical deployment in secure edge-based TC.

流量分类对抗鲁棒性边缘计算

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。