Affiliation:
1. Northeastern University, Boston, MA, USA
Abstract
As advances in
Deep Neural Networks (DNNs)
demonstrate unprecedented levels of performance in many critical applications, their vulnerability to attacks is still an open question. We consider evasion attacks at testing time against Deep Learning in constrained environments, in which dependencies between features need to be satisfied. These situations may arise naturally in tabular data or may be the result of feature engineering in specific application domains, such as threat detection in cyber security. We propose a general iterative gradient-based framework called FENCE for crafting evasion attacks that take into consideration the specifics of constrained domains and application requirements. We apply it against Feed-Forward Neural Networks trained for two cyber security applications: network traffic botnet classification and malicious domain classification, to generate feasible adversarial examples. We extensively evaluate the success rate and performance of our attacks, compare their improvement over several baselines, and analyze factors that impact the attack success rate, including the optimization objective and the data imbalance. We show that with minimal effort (e.g., generating 12 additional network connections), an attacker can change the model’s prediction from the Malicious class to Benign and evade the classifier. We show that models trained on datasets with higher imbalance are more vulnerable to our FENCE attacks. Finally, we demonstrate the potential of performing adversarial training in constrained domains to increase the model resilience against these evasion attacks.
Funder
NSF
Google Security and Privacy Award
U.S. Army Combat Capabilities Development Command Army Research Laboratory under Cooperative Agreement
U.S. Army Contracting Command - Aberdeen Proving Ground (ACC-APG) and the Defense Advanced Research Projects Agency
Publisher
Association for Computing Machinery (ACM)
Subject
Safety, Risk, Reliability and Quality,General Computer Science
Reference85 articles.
1. Examining the Robustness of Learning-Based DDoS Detection in Software Defined Networks
2. Adversarial machine learning in network intrusion detection systems;Alhajjar Elie;arXiv preprint arXiv:2004.11898,2020
3. Generating natural language adversarial examples;Alzantot Moustafa;arXiv preprint arXiv:1804.07998,2018
4. Learning to evade static PE machine learning malware models via reinforcement learning;Anderson Hyrum S.;arXiv preprint arXiv:1801.08917,2018
5. Evading Botnet Detectors Based on Flows and Random Forest with Adversarial Samples
Cited by
13 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献