arXiv:2606.28439cs.CRcs.AI2026-06

针对网络检测系统设计新型包级对抗攻击,有效避检且保持恶意流量语义。

PLAA: Packet-level Adversarial Attacks in Network Traffic Detection

论文配图:PLAA: Packet-level Adversarial Attacks in Network Traffic Detection
图 1 · 摘自论文原文
  • 在包级别逐步生成对抗流量,避免流级特征直接生成的缺陷。
  • 在三个数据集上平均逃逸成功率92.78%,且流量语义保持一致。
  • 适合研究网络对抗攻防或提升检测系统鲁棒性的研究人员使用。

深度神经网络(DNN)因高准确率被广泛应用于基于网络的入侵检测系统(NIDS)。然而,DNN极易受到对抗攻击,攻击者可生成恶意流量以逃避检测。现有方法多从计算机视觉任务迁移对抗攻击至NIDS领域,忽视了两者根本差异,导致两个问题:1)生成的网络流量可能无效;2)原始攻击语义丢失。为此,本文提出一种专为NIDS设计的对抗攻击方法。不同于直接生成流级特征,本方法逐包生成特征,并在生成过程中实时监控流量语义完整性,有效避免了现有方法中的无效流量和语义损失问题。我们在CIC-UNSW-NB15、CIC-DDoS2019和CIC-IDS-2017数据集上评估该算法,对当前NIDS模型的平均逃逸成功率达到92.78%,同时确保生成的对抗流量与原恶意流量语义一致。

原文摘要 · Abstract (English)

Deep neural networks (DNNs) are widely applied in Network-based Intrusion Detection System (NIDS) due to their high accuracy. However, DNNs are highly susceptible to adversarial attacks, which generate malicious traffic to evade NIDS detection. Existing approaches often adapt adversarial attacks from computer vision (CV) tasks to the NIDS domain, overlooking the fundamental differences between CV and NIDS. This results in two major issues: 1) The generated network traffic may become invalid, 2) The generated traffic may lose its original attack semantics. To address these issues, this paper proposes an adversarial attack specifically designed for NIDS. Instead of directly generating flow-level features, our approach incrementally generates packet-level features to construct adversarial traffic. During the generation process, the semantic integrity of the traffic is monitored at each stage, effectively avoiding the issues of invalid traffic and semantic loss observed in existing methods. We evaluate our attack algorithm against current NIDS models using the CIC-UNSW-NB15, CIC-DDoS2019, and CIC-IDS-2017 datasets. The proposed method achieves an average evasion success rate of 92.78%, while ensuring that the generated adversarial traffic remains semantically consistent with the original malicious traffic.

对抗攻击网络检测流量生成

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。