arXiv:2601.14505cs.CRcs.LG2026-01

提出针对工业物联网的误报率操纵攻击,让正常流量被误判为攻击。

Uncovering and Understanding FPR Manipulation Attack in Industrial IoT Networks

  • 利用MQTT协议特性,通过简单包级扰动改变良性流量标签。
  • 攻击成功率达80.19%至100%,显著提升误报率。
  • 适合关注工业安全与模型鲁棒性的研究者阅读。

在基于机器学习的网络入侵检测系统(NIDS)中,由于数据不平衡和合法流量异构性等实际问题,传统观点认为对抗攻击仅表现为攻击包被误判为正常流量。本文揭示这一认知存在盲区:恶意扰动的正常包也可能被误判为攻击。为此,我们提出一种新型攻击——误报率操纵攻击(FPR Manipulation Attack, FPA),专门针对工业物联网网络。该攻击利用广泛使用的MQTT协议领域知识,采用系统性、简单的包级别扰动,无需依赖梯度或非梯度方法即可改变良性流量样本标签。实验表明,该攻击成功率达80.19%至100%。此外,在安全运营中心评估中发现,即使少量误报警报,也会在正常运行条件下使真实告警调查延迟高达2小时。进一步通过统计分析与可解释人工智能(XAI)探究其成功关键因素。最后,研究了使用FPA数据进行对抗训练对模型鲁棒性的影响,并分析决策边界变化。

原文摘要 · Abstract (English)

In the network security domain, due to practical issues -- including imbalanced data and heterogeneous legitimate network traffic -- adversarial attacks in machine learning-based NIDSs have been viewed as attack packets misclassified as benign. Due to this prevailing belief, the possibility of (maliciously) perturbed benign packets being misclassified as attack has been largely ignored. In this paper, we demonstrate that this is not only theoretically possible, but also a particular threat to NIDS. In particular, we uncover a practical cyberattack, FPR manipulation attack (FPA), especially targeting industrial IoT networks, where domain-specific knowledge of the widely used MQTT protocol is exploited and a systematic simple packet-level perturbation is performed to alter the labels of benign traffic samples without employing traditional gradient-based or non-gradient-based methods. The experimental evaluations demonstrate that this novel attack results in a success rate of 80.19% to 100%. In addition, while estimating impacts in the Security Operations Center, we observe that even a small fraction of false positive alerts, irrespective of different budget constraints and alert traffic intensities, can increase the delay of genuine alerts investigations up to 2 hr in a single day under normal operating conditions. Furthermore, a series of relevant statistical and XAI analyses is conducted to understand the key factors behind this remarkable success. Finally, we explore the effectiveness of the FPA packets to enhance models' robustness through adversarial training and investigate the changes in decision boundaries accordingly.

网络安全工业物联网对抗攻击误报率

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。