arXiv:2603.00859cs.CRcs.AI2026-03

针对网络入侵检测的对抗攻击,提出分阶段自适应防御机制。

AMDS: Attack-Aware Multi-Stage Defense System for Network Intrusion Detection with Two-Stage Adaptive Weight Learning

  • 根据攻击特征动态调整检测策略,融合多种异常信号。
  • 在基准数据集上达到94.2% AUC,F1提升9.0点。
  • 适合关注模型抗攻击能力的网络安全研究者。

基于机器学习的网络入侵检测系统易受对抗攻击影响,导致在梯度攻击和分布偏移威胁下性能下降。现有防御多采用统一检测策略,难以应对攻击特性差异。本文提出一种攻击感知的多阶段防御框架,通过集成分歧、预测不确定性和分布异常信号的加权组合,学习攻击特定的检测策略。七类对抗攻击的实证分析揭示了不同的检测特征,支持两级自适应检测机制。在基准入侵检测数据集上的实验表明,该系统在受训集成模型基础上,分类准确率提升4.5个百分点,F1分数提升9.0点,达到94.2%的ROC曲线下面积。面对具备完整架构知识的自适应白盒攻击时,系统仍保持94.4%的准确率,攻击成功率仅为4.2%,但该评估仅限于两种变体,未构成正式鲁棒性证明。跨数据集验证进一步表明,防御效果依赖于基础分类器能力,并随特征维度变化。结果表明,结合攻击特异性优化与多信号融合,可为提升机器学习入侵检测系统的对抗鲁棒性提供可行路径。

原文摘要 · Abstract (English)

Machine learning based network intrusion detection systems are vulnerable to adversarial attacks that degrade classification performance under both gradient-based and distribution shift threat models. Existing defenses typically apply uniform detection strategies, which may not account for heterogeneous attack characteristics. This paper proposes an attack-aware multi-stage defense framework that learns attack-specific detection strategies through a weighted combination of ensemble disagreement, predictive uncertainty, and distributional anomaly signals. Empirical analysis across seven adversarial attack types reveals distinct detection signatures, enabling a two-stage adaptive detection mechanism. Experimental evaluation on a benchmark intrusion detection dataset indicates that the proposed system attains 94.2% area under the receiver operating characteristic curve and improves classification accuracy by 4.5 percentage points and F1-score by 9.0 points over adversarially trained ensembles. Under adaptive white-box attacks with full architectural knowledge, the system appears to maintain 94.4% accuracy with a 4.2% attack success rate, though this evaluation is limited to two adaptive variants and does not constitute a formal robustness guarantee. Cross-dataset validation further suggests that defense effectiveness depends on baseline classifier competence and may vary with feature dimensionality. These results suggest that attack-specific optimization combined with multi-signal integration can provide a practical approach to improving adversarial robustness in machine learning-based intrusion detection systems.

入侵检测对抗防御自适应多信号融合

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。