ELAT: Ensemble Learning with Adversarial Training in defending against evaded intrusions

被引:5
|
作者
Lin, Ying-Dar [1 ]
Pratama, Jehoshua-Hanky [1 ]
Sudyana, Didik [1 ]
Lai, Yuan-Cheng [2 ]
Hwang, Ren-Hung [3 ]
Lin, Po-Ching [4 ]
Lin, Hsuan-Yu [5 ]
Lee, Wei-Bin [6 ]
Chiang, Chen-Kuo [4 ]
机构
[1] Natl Yang Ming Chiao Tung Univ, Hsinchu 300, Taiwan
[2] Natl Taiwan Univ Sci & Technol, Taipei 106, Taiwan
[3] Natl Yang Ming Chiao Tung Univ, Tainan 711, Taiwan
[4] Natl Chung Cheng Univ, Chiayi 621, Taiwan
[5] Telecom Technol Ctr, New Taipei City, Taiwan
[6] Foxconn Res, New Taipei City, Taiwan
关键词
Adversarial attack; Machine learning; Intrusion detection; Ensemble learning; ATTACKS;
D O I
10.1016/j.jisa.2022.103348
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Network intrusion detection systems (NIDSs) now adopt machine learning (ML) for detection of wide attack variants. However, ML is also known vulnerable to adversarial attacks, which can degrade the accuracy of ML. A number of defense strategies have been proposed but mostly in image classification areas. In this work, we propose Ensemble Learning with Adversarial Training (ELAT) to combine adversarial training and ensemble learning into a solution. We compare four approaches: single, ensemble, adversarial and ELAT. In the experiments, several models were developed and tested using different approaches to know which method is robust against adversarial attacks for ML-based NIDSs. The average F1 score for the single models was 0.93 within a wide range (0.82-0.99), but dropped to 0.29 when facing adversarial attacks, particularly dropped to 0.07 caused by the strongest attack, Projected Gradient Descent (PGD). With ensemble, adversarial and ELAT, the average scores were recovered to 0.80, 0.88 and 0.91, respectively. In addition, this work involves prediction of the models and approach implemented behind the system using cosine similarity with an accuracy of 99.9%.
引用
收藏
页数:12
相关论文
共 50 条
  • [21] Generative Adversarial Ensemble Learning for Face Forensics
    Baek, Jae-Yong
    Yoo, Yong-Sang
    Bae, Seung-Hwan
    IEEE ACCESS, 2020, 8 : 45421 - 45431
  • [22] Defending Against Local Adversarial Attacks through Empirical Gradient Optimization
    Sun, Boyang
    Ma, Xiaoxuan
    Wang, Hengyou
    TEHNICKI VJESNIK-TECHNICAL GAZETTE, 2023, 30 (06): : 1888 - 1898
  • [23] Efficacy of Defending Deep Neural Networks against Adversarial Attacks with Randomization
    Zhou, Yan
    Kantarcioglu, Murat
    Xi, Bowei
    ARTIFICIAL INTELLIGENCE AND MACHINE LEARNING FOR MULTI-DOMAIN OPERATIONS APPLICATIONS II, 2020, 11413
  • [24] Defending malware detection models against evasion based adversarial attacks
    Rathore, Hemant
    Sasan, Animesh
    Sahay, Sanjay K.
    Sewak, Mohit
    PATTERN RECOGNITION LETTERS, 2022, 164 : 119 - 125
  • [25] Comparative Analysis of Ensemble Learning Methods in Classifying Network Intrusions
    Moritalho, Francis Jesmar P.
    Festijo, Enrique D.
    2019 IEEE 9TH INTERNATIONAL CONFERENCE ON SYSTEM ENGINEERING AND TECHNOLOGY (ICSET), 2019, : 431 - 436
  • [26] Ensemble adversarial training-based robust model for multi-horizon dynamic line rating forecasting against adversarial attacks
    Alam, Najmul
    Rahman, M. A.
    Islam, Md. Rashidul
    Hossain, M. J.
    ELECTRIC POWER SYSTEMS RESEARCH, 2025, 241
  • [27] Multiview-Ensemble-Learning-Based Robust Graph Convolutional Networks Against Adversarial Attacks
    Wu, Tao
    Luo, Junhui
    Qiao, Shaojie
    Wang, Chao
    Yuan, Lin
    Pu, Xiao
    Xian, Xingping
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (16): : 27700 - 27714
  • [28] Evaluating Pretrained Deep Learning Models for Image Classification Against Individual and Ensemble Adversarial Attacks
    Rahman, Mafizur
    Roy, Prosenjit
    Frizell, Sherri S.
    Qian, Lijun
    IEEE ACCESS, 2025, 13 : 35230 - 35242
  • [29] WASSERTRAIN: AN ADVERSARIAL TRAINING FRAMEWORK AGAINST WASSERSTEIN ADVERSARIAL ATTACKS
    Zhao, Qingye
    Chen, Xin
    Zhao, Zhuoyu
    Tang, Enyi
    Li, Xuandong
    2022 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP), 2022, : 2734 - 2738
  • [30] Negatively correlated ensemble against transfer adversarial attacks
    Zhao, Yunce
    Huang, Wei
    Liu, Wei
    Yao, Xin
    PATTERN RECOGNITION, 2025, 161