AIセキュリティポータル K Program
Categorical Robustness Assessment for Machine Learning based Network Intrusion Detection Systems
Share
Abstract
Network Intrusion Detection Systems (NIDS) heavily utlize Machine Learning (ML) but ML models can be manipulated via adversarial attacks. These attacks add carefully crafted perturbations to network traffic data that leads to misclassifications. While prior work has demonstrated adversarial vulnerabilities in isolated settings, systematic cross-architecture as well as class and category of attack based comparisons under controlled attack conditions remain limited, leaving practitioners without clear guidance on which models to deploy in adversarial environments. This paper asks a simple question: what type of classifier architectures actually hold up when attackers try to manipulate the systems? We put three popular architectures through their paces: a 1D Convolutional Neural Network, a Long Short-Term Memory (LSTM) network, and a Random Forest (RF) ensemble. Using the ACI-IoT-2023 dataset (over 1.2 million samples spanning 12 attack types), we subject each model with FGSM and PGD adversarial attacks, which apply gradient-based perturbations in normalized feature space consistent with established adversarial ML evaluation protocols, at perturbation budgets ranging from $ε=0.01$ to $ε=0.1$. Surprisingly, Random Forest achieved near-perfect baseline accuracy (99.98\%), yet collapsed catastrophically under attack, dropping 73 percentage points at the smallest perturbation we tested. CNN, on the other hand, retained 95.5\% accuracy at $ε=0.01$ and degraded gracefully as perturbations increased. LSTM fell somewhere in between. These findings flip the conventional wisdom where high baseline accuracy means nothing if a model shatters at the first sign of adversarial pressure. For practitioners deploying intrusion detection in adversarial environments, we recommend CNN-based architectures and provide scenario-specific deployment guidance.
A novel hierarchical intrusion detection system based on decision tree and rules-based models
Ahmim A, Maglaras L, Ferrag MA
Published: 2019
Toward generating a new intrusion detection dataset and intrusion traffic characterization
Iman Sharafaldin, Arash Habibi Lashkari, Ali A Ghorbani
Published: 2018
Towards Deep Learning Models Resistant to Adversarial Attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, Adrian Vladu
Published: 2017.6.20
Towards Evaluating the Robustness of Neural Networks
Nicholas Carlini, David Wagner
Published: 2016.8.17
Classifying iot devices in smart environments using network traffic characteristics
Arunan Sivanathan, Hassan Habibi Gharakheili, Franco Loi, Adam Radford, Chamith Wijenayake, Arun Vishwanath, Vijay Sivaraman
Published: 2019
Understanding the Mirai botnet
Manos Antonakakis, Tim April, Michael Bailey
Published: 2017
The Internet of Things: A survey
L. Atzori, A. Iera, G. Morabito
Published: 2010
Adversarial attacks against intrusion detection systems: Taxonomy, solutions and open issues
I. Corona, G. Giacinto, F. Roli
Published: 2013
Intrusion detection systems vulnerability on adversarial examples
A. Warzynski, G. Kolaczek
Published: 2018
Modeling realistic adversarial attacks against network intrusion detection systems
G. Apruzzese, M. Andreolini, L. Ferretti, M. Marchetti, M. Colajanni
Published: 2022
Deep learning
Yann LeCun, Yoshua Bengio, Geoffrey Hinton
Published: 2015
Long short-term memory
S. Hochreiter, J. Schmidhuber
Published: 1997
Random forests
Breiman L
Published: 2001
ACI-IoT-2023: A comprehensive IoT network traffic dataset
E. C. P. Neto, S. Dadkhah, R. Ferreira, A. Zohourian, R. Lu, A. A. Ghorbani
Published: 2023
Transferability in Machine Learning: from Phenomena to Black-Box Attacks using Adversarial Samples
Nicolas Papernot, Patrick McDaniel, Ian Goodfellow
Published: 2016.5.24
Evaluating the Robustness of Neural Networks: An Extreme Value Theory Approach
Tsui-Wei Weng, Huan Zhang, Pin-Yu Chen, Jinfeng Yi, Dong Su, Yupeng Gao, Cho-Jui Hsieh, Luca Daniel
Published: 2018.2.1
Intriguing properties of neural networks
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, R. Fergus
Published: 2014
Dataset Shift in Machine Learning
J. Quiñonero-Candela, M. Sugiyama, A. Schwaighofer, N. D. Lawrence
Published: 2008
Batch normalization: Accelerating deep network training by reducing internal covariate shift
S. Ioffe, C. Szegedy
Published: 2015
Adversarial machine learning in network intrusion detection systems
E. Alhajjar, P. Maxwell, N. Bastian
Published: 2021
Share