用表格扩散模型生成真实攻击,提升5G系统检测器的抗攻击能力。
Diff-DDoS: Realistic Cyber-Physical Attack Synthesis and Robust Detection for 5G-Enabled CPS Using Tabular Diffusion Models

- 基于表格扩散模型生成分布保持的真实攻击样本
- 对抗训练使检测器在多种攻击下F1得分最高达100%
- 适合缺乏标注数据的5G网络安全研究与检测系统加固
基于深度学习的5G网络攻击检测器面临标注攻击数据稀缺和合成数据不真实的问题,导致对自适应攻击者鲁棒性不足。使用固定放大倍数手工构造的攻击训练的检测器,在面对真实分布保持的攻击样本时性能急剧下降(F1分数下降约47%至100%,视场景而定)。本文提出Diff-DDoS,一个三阶段框架:第一阶段在呼叫明细记录(CDRs)的时空网格上训练基线CNN细胞级检测器;第二阶段使用表格去噪扩散概率模型(TabDDPM)在正常CDRs聚合数据上训练,生成真实攻击以暴露检测器漏洞;第三阶段引入对抗扩散训练(ADT),通过逆向分类器引导生成难但分布一致的样本,直至检测器收敛。在米兰CDR数据集上,采用ADT的ResNet50在短信洪泛、静默呼叫、互联网信令及混合场景中分别恢复至79.62%、100%、92.79%的F1分数。经验证阈值校准后,ADT在短信攻击中达到100% F1,远超CTGAN的47.3%;在静默呼叫场景中与最强梯度对抗训练基线持平。结果表明,表格扩散模型可用于数据稀缺环境下对入侵检测器的应力测试与强化。
原文摘要 · Abstract (English)
Deep learning-based DDoS detectors for 5G-enabled cyber-physical systems face scarce labeled attack data and unrealistic synthetic substitutes, which limit robustness against adaptive adversaries. Detectors trained on hand-crafted attacks with fixed scaling multipliers degrade catastrophically (F1-score drops of about 47 percent to 100 percent, depending on scenario) when confronted with realistic, distribution-preserving samples. We propose Diff-DDoS, a three-phase framework for realistic attack synthesis and robust detection using tabular diffusion models. Phase 1 trains a baseline CNN cell-level detector on spatiotemporal grids from call detail records (CDRs). Phase 2 trains a tabular denoising diffusion probabilistic model (TabDDPM) on normal CDR aggregates to generate realistic attacks and expose detector vulnerabilities. Phase 3 introduces adversarial diffusion training (ADT), using inverse classifier guidance to generate hard yet distribution-preserving samples until the detector converges. On a Milano CDR dataset across SMS-flooding, silent-call, Internet-signaling, and blended scenarios, ResNet50 with ADT recovers F1-scores of 79.62 percent (silent-call), 100 percent (Internet), and 92.79 percent (blended). After validation-based threshold calibration, ADT reaches 100 percent SMS F1 versus 47.3 percent for CTGAN, and matches the strongest gradient-based adversarial-training baseline on silent-call. These results support tabular diffusion models for stress-testing and hardening intrusion detectors in data-scarce 5G cyber-physical deployments.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。