The Threat of Adversarial Attacks on Machine Learning in Network Security -- A Survey
arXiv:1911.02621
Abstract
Machine learning models have made many decision support systems to be faster, more accurate, and more efficient. However, applications of machine learning in network security face a more disproportionate threat of active adversarial attacks compared to other domains. This is because machine learning applications in network security such as malware detection, intrusion detection, and spam filtering are by themselves adversarial in nature. In what could be considered an arm's race between attackers and defenders, adversaries constantly probe machine learning systems with inputs that are explicitly designed to bypass the system and induce a wrong prediction. In this survey, we first provide a taxonomy of machine learning techniques, tasks, and depth. We then introduce a classification of machine learning in network security applications. Next, we examine various adversarial attacks against machine learning in network security and introduce two classification approaches for adversarial attacks in network security. First, we classify adversarial attacks in network security based on a taxonomy of network security applications. Secondly, we categorize adversarial attacks in network security into a problem space vs feature space dimensional classification model. We then analyze the various defenses against adversarial attacks on machine learning-based network security applications. We conclude by introducing an adversarial risk grid map and evaluating several existing adversarial attacks against machine learning in network security using the risk grid map. We also identify where each attack classification resides within the adversarial risk grid map.
References in corpus (31)
- Deep Learning in Neural Networks: An Overview
- Distilling the Knowledge in a Neural Network
- Over the Air Deep Learning Based Radio Signal Classification
- Wild Patterns: Ten Years After the Rise of Adversarial Machine Learning
- Theoretical Models of Learning to Learn
- Delving into Transferable Adversarial Examples and Black-box Attacks
- How To Backdoor Federated Learning
- Poisoning Attacks against Support Vector Machines
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks
- On Evaluating Adversarial Robustness
- Adversarially Robust Generalization Requires More Data
- The Space of Transferable Adversarial Examples
- Security Evaluation of Pattern Classifiers under Attack
- Adversarial Risk and the Dangers of Evaluating Against Weak Attacks
- Generating Adversarial Malware Examples for Black-Box Attacks Based on GAN
- Robustness May Be at Odds with Accuracy
- IDSGAN: Generative Adversarial Networks for Attack Generation against Intrusion Detection
- Black-box Adversarial Attacks with Limited Queries and Information
- CryptoDL: Deep Neural Networks over Encrypted Data
- URLNet: Learning a URL Representation with Deep Learning for Malicious URL Detection
- Measuring the tendency of CNNs to Learn Surface Statistical Regularities
- Copycat CNN: Stealing Knowledge by Persuading Confession with Random Non-Labeled Data
- Adversarial vulnerability for any classifier
- Deceiving End-to-End Deep Learning Malware Detectors using Adversarial Examples
- Biologically inspired protection of deep networks from adversarial attacks
- Provable Robustness of ReLU networks via Maximization of Linear Regions
- Logit Pairing Methods Can Fool Gradient-Based Attacks
- Breaking certified defenses: Semantic adversarial examples with spoofed robustness certificates
- Revisiting Adversarial Risk
- Detecting Cyberattacks in Industrial Control Systems Using Convolutional Neural Networks
- Real-Time Adversarial Attacks
Cited by in corpus (4)
- Modeling Realistic Adversarial Attacks against Network Intrusion Detection Systems
- Secure and Trustworthy Artificial Intelligence-Extended Reality (AI-XR) for Metaverses
- DiPSeN: Differentially Private Self-normalizing Neural Networks For Adversarial Robustness in Federated Learning
- Know Your Model (KYM): Increasing Trust in AI and Machine Learning