Adversarial Machine Learning and Cognitive AI for Autonomous Defense against Advanced Cyber Threats
DOI:
https://doi.org/10.15680/IJCTECE.2021.0406016Keywords:
adversarial machine learning, network intrusion detection, UNSW-NB15, deep learning, explainable AI, adversarial training, cyber security, robustnessAbstract
Machine learning practice has become the hallmark of contemporary network intrusion detection, but the very models defending these contested networks are vulnerable to attacks using adversarial examples. The threat model for security settings differs in stark contrast to computer vision: An attacker cannot choose perturbations on network features at will, as protocol fields, counters and connection statistics have strict validity conditions [7]. This paper systematically evaluates the adversarial robustness of deep learning-based intrusion detectors on the UNSW-NB15 dataset in both real-world constrained and unconstrained perturbations. We evaluate the performance of four detectors: a deep multilayer perceptron (MLP), a one-dimensional convolutional network (ConvNet), a feature tokenizer Transformer, and a gradient-boosted tree baseline on binary and ten-class detection. Evaluates the transferability between deep detectors and their defenses by attacking each deep detector with five attacks—FGSM, BIM, PGD, DeepFool, and Carlini and Wagner (CW)—over a range of perturbation budgets and defending them using adversarial training, feature squeezing, and Gaussian smoothing.The most powerful clean binary classifier attains 0.906 accuracy and 0.986 ROC area under the curve value. Under unconstrained attack, the same detector collapses to 0.38 accuracy against Carlini and Wagner, while under realistic feature constraints this attack for the same detector only reduces accuracy to 0.748; thus, unconstrained studies overstate the true operational threat by as much as x1.97 (82%). Projected gradient descent boosts robust accuracy with adversarial training from 0.818 to 0.859 at the cost of less than one point loss in clean accuracy. SHAP analysis shows that time to live and connection state features control the surface of decision, while the adversary changes its reliance on these features for evasion. These findings quantitatively delineate a credible threat landscape for deploying learning based defenses on digital battlefields while identifying feasible, inexpensive hardening approaches
References
[1] N. Moustafa and J. Slay, UNSW-NB15: A comprehensive data set for network intrusion detection systems, in Proc. Military Communications and Information Systems Conference (MilCIS), 2015.
[2] C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus, Intriguing properties of neural networks, in Proc. International Conference on Learning Representations (ICLR), 2014.
[3] I. J. Goodfellow, J. Shlens, and C. Szegedy, Explaining and harnessing adversarial examples, in Proc. International Conference on Learning Representations (ICLR), 2015.
[4] A. Kurakin, I. J. Goodfellow, and S. Bengio, Adversarial examples in the physical world, in Proc. ICLR Workshop, 2017.
[5] A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu, Towards deep learning models resistant to adversarial attacks, in Proc. International Conference on Learning Representations (ICLR), 2018.
[6] S. Moosavi-Dezfooli, A. Fawzi, and P. Frossard, DeepFool: A simple and accurate method to fool deep neural networks, in Proc. IEEE Conference on Computer Vision and Pattern Recognition (CVPR), 2016.
[7] N. Carlini and D. Wagner, Towards evaluating the robustness of neural networks, in Proc. IEEE Symposium on Security and Privacy (S&P), 2017.
[8] N. Papernot, P. McDaniel, S. Jha, M. Fredrikson, Z. B. Celik, and A. Swami, The limitations of deep learning in adversarial settings, in Proc. IEEE European Symposium on Security and Privacy (EuroS&P), 2016.
[9] F. Pierazzi, F. Pendlebury, J. Cortellazzi, and L. Cavallaro, Intriguing properties of adversarial ML attacks in the problem space, in Proc. IEEE Symposium on Security and Privacy (S&P), 2020.
[10] S. M. Lundberg and S.-I. Lee, A unified approach to interpreting model predictions, in Proc. Advances in Neural Information Processing Systems (NeurIPS), 2017.
[11] Y. Gorishniy, I. Rubachev, V. Khrulkov, and A. Babenko, Revisiting deep learning models for tabular data, in Proc. Advances in Neural Information Processing Systems (NeurIPS), 2021.
[12] T. Chen and C. Guestrin, XGBoost: A scalable tree boosting system, in Proc. ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, 2016.
[13] R. Vinayakumar, M. Alazab, K. P. Soman, P. Poornachandran, A. Al-Nemrat, and S. Venkatraman, Deep learning approach for intelligent intrusion detection system, IEEE Access, vol. 7, pp. 41525 to 41550, 2019.
[14] G. Apruzzese, M. Colajanni, L. Ferretti, A. Guido, and M. Marchetti, On the effectiveness of machine and deep learning for cyber security, in Proc. International Conference on Cyber Conflict (CyCon), 2018.
[15] E. Anthi, L. Williams, M. Rhode, P. Burnap, and A. Wedgbury, Adversarial attacks on machine learning cybersecurity defences in industrial control systems, Journal of Information Security and Applications, vol. 58, 2021.
[16] W. Xu, D. Evans, and Y. Qi, Feature squeezing: Detecting adversarial examples in deep neural networks, in Proc. Network and Distributed System Security Symposium (NDSS), 2018.
[17] I. Sharafaldin, A. H. Lashkari, and A. A. Ghorbani, Toward generating a new intrusion detection dataset and intrusion traffic characterization, in Proc. International Conference on Information Systems Security and Privacy (ICISSP), 2018.
[18] N. Moustafa and J. Slay, The evaluation of network anomaly detection systems: Statistical analysis of the UNSW-NB15 data set, Information Security Journal: A Global Perspective, vol. 25, no. 1 to 3, 2016.
[19] O. Ibitoye, O. Shafiq, and A. Matrawy, Analyzing adversarial attacks against deep learning for intrusion detection in IoT networks, in Proc. IEEE Global Communications Conference (GLOBECOM), 2019.
[20] A. M. Sadeghzadeh, S. Shiravi, and R. Jalili, Adversarial network traffic: Towards evaluating the robustness of deep learning-based network traffic classification, IEEE Transactions on Network and Service Management, vol. 18, no. 2, 2021.
[21] I. Rosenberg, A. Shabtai, Y. Elovici, and L. Rokach, Adversarial machine learning attacks and defense methods in the cyber security domain, ACM Computing Surveys, vol. 54, no. 5, 2021.
[22] A. Venturi, G. Apruzzese, M. Andreolini, M. Colajanni, and M. Marchetti, DReLAB: Deep reinforcement learning adversarial botnet, Data in Brief, vol. 34, 2020.
[23] C. Guo, M. Rana, M. Cisse, and L. van der Maaten, Countering adversarial images using input transformations, in Proc. International Conference on Learning Representations (ICLR), 2018.
[24] D. P. Kingma and J. Ba, Adam: A method for stochastic optimization, in Proc. International Conference on Learning Representations (ICLR), 2015.
[25]Alim, M. A., Rahman, M. R., Arif, M. H., & Hossen, M. S. (2020). Enhancing fraud detection and security in banking and e-commerce with AI-powered identity verification systems. World Journal of Advanced Research and Reviews, 2035.
[26]Biswas, B., Chaudhury, T. H., Mohammad, S. N., & Raihan, D. M. (2019). Distributed recommender system using Apache Hadoop. International Conference on Advances in Science, Engineering and Robotics Technology (ICASERT) 2019.
[27] Biswas, B., Chaudhury, T. H., & Mohammad, S. N. (2019). A fast and scalable recommender system using collaborative filtering technique in Python Scikit-learn. International Conference on Engineering Research, Innovation and Education (ICERIE) 2019.
[28] Biswas, B., Mondal, D. K., & Amin, M. R. (2010). Dynamic intrusion detection and prevention system. International Conference on Engineering Research, Innovation and Education (ICERIE) 2010.

