通过动态扰动流量特征,让攻击者无法获取有效反馈。
Behavior-Aware and Generalizable Defense Against Black-Box Adversarial Attacks for ML-Based IDS
- 根据流量异常动态选择并扰动关键特征,干扰攻击反馈
- 在多种黑盒攻击下使攻击成功率下降超过70%,检测率保持95%以上
- 无需模型内部信息,适合真实网络环境实时部署
基于机器学习的入侵检测系统日益面临黑盒对抗攻击威胁,攻击者通过二元输出或响应时间、资源使用等行为信号间接反馈来构造逃避输入。现有防御方法如输入变换、对抗训练和代理检测常存在局限:多针对特定攻击类型,需访问模型内部结构,或依赖静态机制难以适应演化中的攻击策略。此外,输入变换可能损害检测性能,不适合实时部署。为此,本文提出自适应特征污染(Adaptive Feature Poisoning),一种轻量级、主动式的防御机制,专为真实黑盒场景设计。该方法假设探测可静默持续进行,通过流量画像、变化点检测与自适应缩放,动态选择并扰动攻击者可能利用的流量特征,破坏其反馈回路而不影响检测能力。在包括静默探测、迁移性攻击和决策边界攻击在内的多种真实攻击策略下评估表明,该方法能有效混淆攻击者,显著降低攻击成功率,同时维持95%以上的检测率。其通用性、攻击无关性和不可检测性,为提升机器学习入侵检测系统的实际鲁棒性提供了重要进展。
原文摘要 · Abstract (English)
Machine learning based intrusion detection systems are increasingly targeted by black box adversarial attacks, where attackers craft evasive inputs using indirect feedback such as binary outputs or behavioral signals like response time and resource usage. While several defenses have been proposed, including input transformation, adversarial training, and surrogate detection, they often fall short in practice. Most are tailored to specific attack types, require internal model access, or rely on static mechanisms that fail to generalize across evolving attack strategies. Furthermore, defenses such as input transformation can degrade intrusion detection system performance, making them unsuitable for real time deployment. To address these limitations, we propose Adaptive Feature Poisoning, a lightweight and proactive defense mechanism designed specifically for realistic black box scenarios. Adaptive Feature Poisoning assumes that probing can occur silently and continuously, and introduces dynamic and context aware perturbations to selected traffic features, corrupting the attacker feedback loop without impacting detection capabilities. The method leverages traffic profiling, change point detection, and adaptive scaling to selectively perturb features that an attacker is likely exploiting, based on observed deviations. We evaluate Adaptive Feature Poisoning against multiple realistic adversarial attack strategies, including silent probing, transferability based attacks, and decision boundary based attacks. The results demonstrate its ability to confuse attackers, degrade attack effectiveness, and preserve detection performance. By offering a generalizable, attack agnostic, and undetectable defense, Adaptive Feature Poisoning represents a significant step toward practical and robust adversarial resilience in machine learning based intrusion detection systems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。