TY - GEN
T1 - Rallying Adversarial Techniques against Deep Learning for Network Security
AU - Clements, Joseph
AU - Yang, Yuzhe
AU - Sharma, Ankur A.
AU - Hu, Hongxin
AU - Lao, Yingjie
N1 - Publisher Copyright:
© 2021 IEEE.
PY - 2021
Y1 - 2021
N2 - Recent advances in artificial intelligence and the increasing need for robust defensive measures in network security have led to the adoption of deep learning approaches for network intrusion detection systems (NIDS). These methods have achieved superior performance against conventional network attacks, enabling unique and dynamic security systems in realworld applications. Adversarial machine learning, unfortunately, has recently shown that deep learning models are inherently vulnerable to adversarial modifications on their input data. In this work, we explore the potential of adversarial entities to compromise such vulnerabilities to compromise deep learning-based NIDS systems. Specifically, we show that by modifying on average as little as 1.38 of an observed packet's input features, an adversary can generate malicious inputs that effectively fool a target deep learning-based NIDS. Therefore, it is crucial to consider the performance from the conventional network security perspective and the adversarial machine learning domain when designing such systems.
AB - Recent advances in artificial intelligence and the increasing need for robust defensive measures in network security have led to the adoption of deep learning approaches for network intrusion detection systems (NIDS). These methods have achieved superior performance against conventional network attacks, enabling unique and dynamic security systems in realworld applications. Adversarial machine learning, unfortunately, has recently shown that deep learning models are inherently vulnerable to adversarial modifications on their input data. In this work, we explore the potential of adversarial entities to compromise such vulnerabilities to compromise deep learning-based NIDS systems. Specifically, we show that by modifying on average as little as 1.38 of an observed packet's input features, an adversary can generate malicious inputs that effectively fool a target deep learning-based NIDS. Therefore, it is crucial to consider the performance from the conventional network security perspective and the adversarial machine learning domain when designing such systems.
KW - Adversarial Examples
KW - Adversarial Machine Learning
KW - Deep Learning
KW - Network Intrusion Detection System
UR - https://www.scopus.com/pages/publications/85125814568
U2 - 10.1109/SSCI50451.2021.9660011
DO - 10.1109/SSCI50451.2021.9660011
M3 - Conference contribution
AN - SCOPUS:85125814568
T3 - 2021 IEEE Symposium Series on Computational Intelligence, SSCI 2021 - Proceedings
BT - 2021 IEEE Symposium Series on Computational Intelligence, SSCI 2021 - Proceedings
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 2021 IEEE Symposium Series on Computational Intelligence, SSCI 2021
Y2 - 5 December 2021 through 7 December 2021
ER -