A simple framework to enhance the adversarial robustness of deep learning-based intrusion detection system

被引:12
作者
Yuan, Xinwei [1 ]
Han, Shu [1 ]
Huang, Wei [2 ]
Ye, Hongliang [1 ]
Kong, Xianglong [2 ]
Zhang, Fan [3 ]
机构
[1] Southeast Univ, Nanjing, Peoples R China
[2] Purple Mt Labs, Nanjing, Peoples R China
[3] Natl Digital Switching Syst & Engn Technol Res Ctr, Zhengzhou, Peoples R China
关键词
Intrusion detection system; Adversarial example; Adversarial detection; Adversarial defense; Deep learning; Machine learning;
D O I
10.1016/j.cose.2023.103644
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Deep learning based intrusion detection systems (DL-based IDS) have emerged as one of the best choices for providing security solutions against various network intrusion attacks. However, due to the emergence and development of adversarial deep learning technologies, it becomes challenging for the adoption of DL models into IDS. In this paper, we propose a novel IDS architecture that can enhance the robustness of IDS against adversarial attacks by combining conventional machine learning (ML) models and Deep Learning models. The proposed DLL-IDS consists of three components: DL-based IDS, adversarial example (AE) detector, and ML-based IDS. We first develop a novel AE detector based on the local intrinsic dimensionality (LID). Then, we exploit the low attack transferability between DL models and ML models to find a robust ML model that can assist us in determining the maliciousness of AEs. If the input traffic is detected as an AE, the ML-based IDS will predict the maliciousness of input traffic, otherwise the DL-based IDS will work for the prediction. The fusion mechanism can leverage the high prediction accuracy of DL models and low attack transferability between DL models and ML models to improve the robustness of the whole system. In our experiments, we observe a significant improvement in the prediction performance of the IDS when subjected to adversarial attack, achieving high accuracy with low resource consumption.
引用
收藏
页数:12
相关论文
共 44 条
[1]   Network intrusion detection system: A systematic study of machine learning and deep learning approaches [J].
Ahmad, Zeeshan ;
Shahid Khan, Adnan ;
Wai Shiang, Cheah ;
Abdullah, Johari ;
Ahmad, Farhan .
TRANSACTIONS ON EMERGING TELECOMMUNICATIONS TECHNOLOGIES, 2021, 32 (01)
[2]  
Alalousi Alhamza, 2016, INT J ELECT COMPUT E, V6, P778
[3]   Adversarial machine learning in Network Intrusion Detection Systems [J].
Alhajjar, Elie ;
Maxwell, Paul ;
Bastian, Nathaniel .
EXPERT SYSTEMS WITH APPLICATIONS, 2021, 186
[4]   Estimating Local Intrinsic Dimensionality [J].
Amsaleg, Laurent ;
Chelly, Oussama ;
Furon, Teddy ;
Girard, Stephane ;
Houle, Michael E. ;
Kawarabayashi, Ken-ichi ;
Nett, Michael .
KDD'15: PROCEEDINGS OF THE 21ST ACM SIGKDD INTERNATIONAL CONFERENCE ON KNOWLEDGE DISCOVERY AND DATA MINING, 2015, :29-38
[5]  
Nguyen A, 2015, PROC CVPR IEEE, P427, DOI 10.1109/CVPR.2015.7298640
[6]  
Athalye A, 2018, PR MACH LEARN RES, V80
[7]  
Ballet V, 2019, Arxiv, DOI arXiv:1911.03274
[8]  
Carlini N., 2017, P 10 ACM WORKSH ART, P3, DOI DOI 10.1145/3128572.3140444
[9]   Towards Evaluating the Robustness of Neural Networks [J].
Carlini, Nicholas ;
Wagner, David .
2017 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP), 2017, :39-57
[10]   On Local Intrinsic Dimension Estimation and Its Applications [J].
Carter, Kevin M. ;
Raich, Raviv ;
Hero, Alfred O., III .
IEEE TRANSACTIONS ON SIGNAL PROCESSING, 2010, 58 (02) :650-663