arXiv:2606.03430cs.CRcs.AI2026-06

用流模型检测数据无关盗取攻击,不依赖身份信息。

FlowGuard: Flow Matching for Identity-Independent Detection of Data-Free Model Stealing Attacks on Energy System Intrusion Detection Systems

论文配图:FlowGuard: Flow Matching for Identity-Independent Detection of Data-Free Model Stealing Attacks on Energy System Intrusion Detection Systems
图 1 · 摘自论文原文
  • 基于连续归一化流,识别合成查询的低维特征
  • 在单客户端和100节点分布式攻击下保持稳定检测率
  • 适合无身份标识的能源系统入侵检测场景

部署于能源基础设施的基于人工智能的入侵检测系统(IDS)易受模型窃取攻击,攻击者可离线生成逃避流量。现有防御方法或依赖身份绑定查询监控(对分布式攻击无效),或通过软标签扰动实现预测污染(不适用于硬标签部署)。为此,我们提出FlowGuard,一种不依赖身份的防御机制,利用流匹配技术在IDS处理前将输入查询分类为分布外(OOD)。该方法基于合成攻击查询占据更低维流形的事实,导致在合法数据训练的连续归一化流模型上产生显著更低的对数似然值。我们在单客户端与100客户端分布式(Sybil)场景下,针对PRADA和FDINet,使用MAZE和DisGUIDE攻击进行评估。当分布变化时,PRADA检测率降至0%,而我们的防御在两种设置下均保持稳定检测率,且无需身份信息。我们讨论了该方法的适用范围与局限性,并提出了向数据依赖型攻击扩展的可能。

原文摘要 · Abstract (English)

Artificial Intelligence (AI)-based Intrusion Detection Systems (IDS) deployed in energy infrastructure are vulnerable to model theft attacks, which allow adversaries to create evasive traffic offline. Current defences against model extraction rely either on identity-bound query monitoring, which is ineffective against distributed attackers (Sybil), or on prediction poisoning through soft-label perturbation, which is inapplicable to hard-label IDS deployments. Therefore, we propose FlowGuard, an identity-independent defence based on flow matching that classifies incoming queries as out-of-distribution (OOD) prior to IDS processing. This approach exploits the fact that queries generated synthetically for data-free model stealing attacks occupy a lower-dimensional manifold than real network traffic. This results in measurably lower log-likelihoods when using a Continuous Normalizing Flow that has been trained on legitimate data. We evaluate our method against PRADA and FDINet using MAZE and DisGUIDE attacks in single-client and distributed (100-client Sybil) settings. While PRADA's detection rate dropped to 0% when the distribution changed, our defence maintained a stable detection rate across both settings without relying on identity information. We discuss the scope and limitations of the approach, and outline potential applications to data-dependent attacks.

入侵检测模型窃取流模型能源安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。