Realism versus Performance for Adversarial Examples Against DL-based NIDS

10Citations
Citations of this article
24Readers
Mendeley users who have this article in their library.
Get full text

Abstract

The application of deep learning-based (DL) network intrusion detection systems (NIDS) enables effective automated detection of cyberattacks. Such models can extract valuable features from high-dimensional and heterogeneous network traffic with minimal feature engineering and provide high accuracy detection rates. However, it has been shown that DL can be vulnerable to adversarial examples (AEs), which mislead classification decisions at inference time, and several works have shown that AEs are indeed a threat against DL-based NIDS. In this work, we argue that these threats are not necessarily realistic. Indeed, some general techniques used to generate AE manipulate features in a way that would be inconsistent with actual network traffic. In this paper, we first implement the main AE attacks selected from the literature (FGSM, BIM, PGD, NewtonFool, CW, DeepFool, EN, Boundary, HSJ, ZOO) for two different datasets (WSN-DS and BoT-IoT) and we compare their relative performance. We then analyze the perturbation generated by these attacks and use the metrics to establish a notion of "attack unrealism". We conclude that, for these datasets, some of these attacks are performant but not realistic.

Cite

CITATION STYLE

APA

Alatwi, H. A., & Morisset, C. (2023). Realism versus Performance for Adversarial Examples Against DL-based NIDS. In Proceedings of the ACM Symposium on Applied Computing (pp. 1549–1557). Association for Computing Machinery. https://doi.org/10.1145/3555776.3577671

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free