Adversarial Machine Learning and Cognitive AI for Autonomous Defense against Advanced Cyber Threats

Authors

  • Biswanath Bhattacharjee B.A (Hon's), M.A (double), LL.M; Lecturer, Badda Law College, Dhaka, Bangladesh; Advocate, Dhaka Bar Association, Bangladesh Author
  • Mst Anupa Nasrin Khan Master of Science in Zoology (Entomology Focus), The University of Rajshahi, Bangladesh Author
  • Md Abdullah Enayet Bachelor of Arts in English Humanities, University of Liberal Arts Bangladesh (ULAB), Dhaka, Bangladesh Author
  • Md. Salahuddin Gazi B.S.S. (Honours) – Sociology, Jagannath University, Dhaka, Bangladesh Author
  • Masrufa Tasnim Master of Business Administration (MBA) – Human Resource Management, University of Dhaka, Bangladesh Author
  • Tanaya Jakir Bachelor of Business Administration (Human Resources Management), State University of Bangladesh Author
  • Abidul Alam Bachelor of Business Administration (BBA), Marketing, International University of Business Agriculture and Technology (IUBAT), Dhaka, Bangladesh Author
  • Md Reduanur Rahman Master's in Information Technology, Washington University of Science and Technology, Alexandria, Virginia, USA Author
  • Md Himeluzzaman B.Sc. in Computer Science and Engineering, Leading University, Sylhet, Bangladesh Author

DOI:

https://doi.org/10.15680/IJCTECE.2021.0406016

Keywords:

adversarial machine learning, network intrusion detection, UNSW-NB15, deep learning, explainable AI, adversarial training, cyber security, robustness

Abstract

Machine learning practice has become the hallmark of contemporary network intrusion detection, but the very models defending these contested networks are vulnerable to attacks using adversarial examples. The threat model for security settings differs in stark contrast to computer vision: An attacker cannot choose perturbations on network features at will, as protocol fields, counters and connection statistics have strict validity conditions [7]. This paper systematically evaluates the adversarial robustness of deep learning-based intrusion detectors on the UNSW-NB15 dataset in both real-world constrained and unconstrained perturbations. We evaluate the performance of four detectors: a deep multilayer perceptron (MLP), a one-dimensional convolutional network (ConvNet), a feature tokenizer Transformer, and a gradient-boosted tree baseline on binary and ten-class detection. Evaluates the transferability between deep detectors and their defenses by attacking each deep detector with five attacks—FGSM, BIM, PGD, DeepFool, and Carlini and Wagner (CW)—over a range of perturbation budgets and defending them using adversarial training, feature squeezing, and Gaussian smoothing.The most powerful clean binary classifier attains 0.906 accuracy and 0.986 ROC area under the curve value. Under unconstrained attack, the same detector collapses to 0.38 accuracy against Carlini and Wagner, while under realistic feature constraints this attack for the same detector only reduces accuracy to 0.748; thus, unconstrained studies overstate the true operational threat by as much as x1.97 (82%). Projected gradient descent boosts robust accuracy with adversarial training from 0.818 to 0.859 at the cost of less than one point loss in clean accuracy. SHAP analysis shows that time to live and connection state features control the surface of decision, while the adversary changes its reliance on these features for evasion. These findings quantitatively delineate a credible threat landscape for deploying learning based defenses on digital battlefields while identifying feasible, inexpensive hardening approaches

References

[1] N. Moustafa and J. Slay, UNSW-NB15: A comprehensive data set for network intrusion detection systems, in Proc. Military Communications and Information Systems Conference (MilCIS), 2015.

[2] C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus, Intriguing properties of neural networks, in Proc. International Conference on Learning Representations (ICLR), 2014.

[3] I. J. Goodfellow, J. Shlens, and C. Szegedy, Explaining and harnessing adversarial examples, in Proc. International Conference on Learning Representations (ICLR), 2015.

[4] A. Kurakin, I. J. Goodfellow, and S. Bengio, Adversarial examples in the physical world, in Proc. ICLR Workshop, 2017.

[5] A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu, Towards deep learning models resistant to adversarial attacks, in Proc. International Conference on Learning Representations (ICLR), 2018.

[6] S. Moosavi-Dezfooli, A. Fawzi, and P. Frossard, DeepFool: A simple and accurate method to fool deep neural networks, in Proc. IEEE Conference on Computer Vision and Pattern Recognition (CVPR), 2016.

[7] N. Carlini and D. Wagner, Towards evaluating the robustness of neural networks, in Proc. IEEE Symposium on Security and Privacy (S&P), 2017.

[8] N. Papernot, P. McDaniel, S. Jha, M. Fredrikson, Z. B. Celik, and A. Swami, The limitations of deep learning in adversarial settings, in Proc. IEEE European Symposium on Security and Privacy (EuroS&P), 2016.

[9] F. Pierazzi, F. Pendlebury, J. Cortellazzi, and L. Cavallaro, Intriguing properties of adversarial ML attacks in the problem space, in Proc. IEEE Symposium on Security and Privacy (S&P), 2020.

[10] S. M. Lundberg and S.-I. Lee, A unified approach to interpreting model predictions, in Proc. Advances in Neural Information Processing Systems (NeurIPS), 2017.

[11] Y. Gorishniy, I. Rubachev, V. Khrulkov, and A. Babenko, Revisiting deep learning models for tabular data, in Proc. Advances in Neural Information Processing Systems (NeurIPS), 2021.

[12] T. Chen and C. Guestrin, XGBoost: A scalable tree boosting system, in Proc. ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, 2016.

[13] R. Vinayakumar, M. Alazab, K. P. Soman, P. Poornachandran, A. Al-Nemrat, and S. Venkatraman, Deep learning approach for intelligent intrusion detection system, IEEE Access, vol. 7, pp. 41525 to 41550, 2019.

[14] G. Apruzzese, M. Colajanni, L. Ferretti, A. Guido, and M. Marchetti, On the effectiveness of machine and deep learning for cyber security, in Proc. International Conference on Cyber Conflict (CyCon), 2018.

[15] E. Anthi, L. Williams, M. Rhode, P. Burnap, and A. Wedgbury, Adversarial attacks on machine learning cybersecurity defences in industrial control systems, Journal of Information Security and Applications, vol. 58, 2021.

[16] W. Xu, D. Evans, and Y. Qi, Feature squeezing: Detecting adversarial examples in deep neural networks, in Proc. Network and Distributed System Security Symposium (NDSS), 2018.

[17] I. Sharafaldin, A. H. Lashkari, and A. A. Ghorbani, Toward generating a new intrusion detection dataset and intrusion traffic characterization, in Proc. International Conference on Information Systems Security and Privacy (ICISSP), 2018.

[18] N. Moustafa and J. Slay, The evaluation of network anomaly detection systems: Statistical analysis of the UNSW-NB15 data set, Information Security Journal: A Global Perspective, vol. 25, no. 1 to 3, 2016.

[19] O. Ibitoye, O. Shafiq, and A. Matrawy, Analyzing adversarial attacks against deep learning for intrusion detection in IoT networks, in Proc. IEEE Global Communications Conference (GLOBECOM), 2019.

[20] A. M. Sadeghzadeh, S. Shiravi, and R. Jalili, Adversarial network traffic: Towards evaluating the robustness of deep learning-based network traffic classification, IEEE Transactions on Network and Service Management, vol. 18, no. 2, 2021.

[21] I. Rosenberg, A. Shabtai, Y. Elovici, and L. Rokach, Adversarial machine learning attacks and defense methods in the cyber security domain, ACM Computing Surveys, vol. 54, no. 5, 2021.

[22] A. Venturi, G. Apruzzese, M. Andreolini, M. Colajanni, and M. Marchetti, DReLAB: Deep reinforcement learning adversarial botnet, Data in Brief, vol. 34, 2020.

[23] C. Guo, M. Rana, M. Cisse, and L. van der Maaten, Countering adversarial images using input transformations, in Proc. International Conference on Learning Representations (ICLR), 2018.

[24] D. P. Kingma and J. Ba, Adam: A method for stochastic optimization, in Proc. International Conference on Learning Representations (ICLR), 2015.

[25]Alim, M. A., Rahman, M. R., Arif, M. H., & Hossen, M. S. (2020). Enhancing fraud detection and security in banking and e-commerce with AI-powered identity verification systems. World Journal of Advanced Research and Reviews, 2035.

[26]Biswas, B., Chaudhury, T. H., Mohammad, S. N., & Raihan, D. M. (2019). Distributed recommender system using Apache Hadoop. International Conference on Advances in Science, Engineering and Robotics Technology (ICASERT) 2019.

[27] Biswas, B., Chaudhury, T. H., & Mohammad, S. N. (2019). A fast and scalable recommender system using collaborative filtering technique in Python Scikit-learn. International Conference on Engineering Research, Innovation and Education (ICERIE) 2019.

[28] Biswas, B., Mondal, D. K., & Amin, M. R. (2010). Dynamic intrusion detection and prevention system. International Conference on Engineering Research, Innovation and Education (ICERIE) 2010.

Downloads

Published

2021-11-15

How to Cite

Adversarial Machine Learning and Cognitive AI for Autonomous Defense against Advanced Cyber Threats. (2021). International Journal of Computer Technology and Electronics Communication, 4(6), 4327-4337. https://doi.org/10.15680/IJCTECE.2021.0406016

Most read articles by the same author(s)