提出分层自适应正则化方法,提升网络入侵检测的抗攻击能力。
Enhancing Adversarial Robustness in Network Intrusion Detection: A Layer-wise Adaptive Regularization Approach

- 通过分层分析识别脆弱层,动态调整正则化强度。
- 在UNSW-NB15数据集上达95.01%准确率,有效防御多种攻击。
- 可解释性强,支持早期发现恶意样本,适合安全系统研发者。
基于神经网络的网络入侵检测系统易受梯度相关漏洞的对抗攻击影响。尽管现有对抗训练方法在提升模型鲁棒性方面表现良好,但其可解释性与防御能力受限于对攻击在各网络层传播机制的理解不足。本文提出一种名为LARAR(Layer-wise Adversarial Robustness using Adaptive Regularization)的新方法,融合分层漏洞分析与自适应加权机制,并引入辅助分类器。该方法可生成可解释的分层脆弱性评分,在UNSW-NB15数据集上实现95.01%的干净准确率,显著提升对FGSM、PGD及迁移攻击的防御能力。通过定位脆弱层,框架降低计算开销,支持对抗样本的早期检测,从而增强入侵检测系统的有效性与可解释性。
原文摘要 · Abstract (English)
The new wave of adversarial attacks that utilize gradient-related vulnerabilities in neural network-based classifiers makes Network Intrusion Detection Systems more open to such threats. Although state-of-the-art adversarial training methods have shown promising results in producing more robust classifiers, their interpretability and defense ability are limited due to their lack of understanding of how adversarial attacks propagate in different layers of network classifiers. In this paper, we present an insightful approach, called LARAR (Layer-wise Adversarial Robustness using Adaptive Regularization), that incorporates additional layer-wise vulnerability analysis and adaptive weighting in conventional adversarial training methods. Additionally, we utilize 'Auxiliary Classifiers' in our approach. LARAR provides interpretable layer-wise vulnerability scores, achieves a clean accuracy of 95.01%, and provides better robustness against adversarial attacks (FGSM, PGD, and transfer attacks) on the UNSW-NB15 dataset. Through the identification of vulnerable layers, the proposed framework reduces computational complexity and enables the early detection of adversarial samples, thus enhancing the effectiveness and interpretability of adversarial defense mechanisms in NIDS.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。