Towards Adversarial Realism and Robust Learning for IoT Intrusion Detection and Classification
arXiv:2301.13122 · doi:10.1007/s12243-023-00953-y
Abstract
The Internet of Things (IoT) faces tremendous security challenges. Machine learning models can be used to tackle the growing number of cyber-attack variations targeting IoT systems, but the increasing threat posed by adversarial attacks restates the need for reliable defense strategies. This work describes the types of constraints required for a realistic adversarial cyber-attack example and proposes a methodology for a trustworthy adversarial robustness analysis with a realistic adversarial evasion attack vector. The proposed methodology was used to evaluate three supervised algorithms, Random Forest (RF), Extreme Gradient Boosting (XGB), and Light Gradient Boosting Machine (LGBM), and one unsupervised algorithm, Isolation Forest (IFOR). Constrained adversarial examples were generated with the Adaptative Perturbation Pattern Method (A2PM), and evasion attacks were performed against models created with regular and adversarial training. Even though RF was the least affected in binary classification, XGB consistently achieved the highest accuracy in multi-class classification. The obtained results evidence the inherent susceptibility of tree-based algorithms and ensembles to adversarial evasion attacks and demonstrates the benefits of adversarial training and a security by design approach for a more robust IoT network intrusion detection and cyber-attack classification.
19 pages, 5 tables, 7 figures, Annals of Telecommunications journal
References in corpus (6)
- Security of the Internet of Things: Vulnerabilities, Attacks and Countermeasures
- Security Evaluation of Pattern Classifiers under Attack
- Machine Learning Based Intrusion Detection Systems for IoT Applications
- Modeling Realistic Adversarial Attacks against Network Intrusion Detection Systems
- Launching Adversarial Attacks against Network Intrusion Detection Systems for IoT
- Adaptative Perturbation Patterns: Realistic Adversarial Learning for Robust Intrusion Detection