4.5 Article

Adversarial Attacks Against Deep Learning-Based Network Intrusion Detection Systems and Defense Mechanisms

Journal

IEEE-ACM TRANSACTIONS ON NETWORKING
Volume 30, Issue 3, Pages 1294-1311

Publisher

IEEE-INST ELECTRICAL ELECTRONICS ENGINEERS INC
DOI: 10.1109/TNET.2021.3137084

Keywords

Feature extraction; Deep learning; Robustness; Perturbation methods; Network intrusion detection; Detectors; Training; Adversarial attacks; network intrusion detection systems; deep learning

Funding

  1. CERCA Programme/Generalitat de Catalunya

Ask authors/readers for more resources

The article introduces a general framework called TIKI-TAKA for assessing and enhancing the adversarial defense capabilities of NIDS. Three defense mechanisms are proposed and their effectiveness is validated through experiments.
Neural networks (NNs) are increasingly popular in developing NIDS, yet can prove vulnerable to adversarial examples. Through these, attackers that may be oblivious to the precise mechanics of the targeted NIDS add subtle perturbations to malicious traffic features, with the aim of evading detection and disrupting critical systems. Defending against such adversarial attacks is of high importance, but requires to address daunting challenges. Here, we introduce TIKI-TAKA, a general framework for (i) assessing the robustness of state-of-the-art deep learning-based NIDS against adversarial manipulations, and which (ii) incorporates defense mechanisms that we propose to increase resistance to attacks employing such evasion techniques. Specifically, we select five cutting-edge adversarial attack types to subvert three popular malicious traffic detectors that employ NNs. We experiment with publicly available datasets and consider both one-to-all and one-to-one classification scenarios, i.e., discriminating illicit vs benign traffic and respectively identifying specific types of anomalous traffic among many observed. The results obtained reveal that attackers can evade NIDS with up to 35.7% success rates, by only altering time-based features of the traffic generated. To counteract these weaknesses, we propose three defense mechanisms: model voting ensembling, ensembling adversarial training, and query detection. We demonstrate that these methods can restore intrusion detection rates to nearly 100% against most types of malicious traffic, and attacks with potentially catastrophic consequences (e.g., botnet) can be thwarted. This confirms the effectiveness of our solutions and makes the case for their adoption when designing robust and reliable deep anomaly detectors.

Authors

I am an author on this paper
Click your name to claim this paper and add it to your profile.

Reviews

Primary Rating

4.5
Not enough ratings

Secondary Ratings

Novelty
-
Significance
-
Scientific rigor
-
Rate this paper

Recommended

Editorial Material Dermatology

An expanding annular plaque on the leg

Alejandro Garcia-Vazquez, Santiago Guillen-Climent, Marti Pons Benavent, Saray Porcar Saura, Maria Dolores Ramon-Quiles

INDIAN JOURNAL OF DERMATOLOGY VENEREOLOGY & LEPROLOGY (2023)

Article Engineering, Electrical & Electronic

ONETS: Online Network Slice Broker From Theory to Practice

Vincenzo Sciancalepore, Lanfranco Zanzi, Xavier Costa-Perez, Antonio Capone

Summary: Virtualization and network slicing provide mobile network operators with the opportunity to deploy multiple logical networks, known as network slices, on their physical network infrastructure. This paper introduces ONETS, an online network slicing solution that incorporates a mathematical model and analytical bounds to maximize multiplexing gains. The feasibility of ONETS is demonstrated through a proof-of-concept implementation on commercial hardware, supporting three network slices and seamless integration with the 3GPP architecture.

IEEE TRANSACTIONS ON WIRELESS COMMUNICATIONS (2022)

Article Computer Science, Information Systems

SARDO: An Automated Search-and-Rescue Drone-Based Solution for Victims Localization

Antonio Albanese, Vincenzo Sciancalepore, Xavier Costa-Perez

Summary: This paper presents SARDO, a drone-based search and rescue solution that leverages mobile phones to localize missing people. SARDO uses pseudo-trilateration and machine-learning techniques to rapidly determine the location of mobile phones with high accuracy and low battery consumption.

IEEE TRANSACTIONS ON MOBILE COMPUTING (2022)

Article Computer Science, Information Systems

LOKO: Localization-Aware Roll-Out Planning for Future Mobile Networks

Antonio Albanese, Vincenzo Sciancalepore, Albert Banchs, Xavier Costa-Perez

Summary: This paper proposes a new base station placement solution that maximizes throughput and localization accuracy by selecting the location of new-generation base stations. This solution enables the provision of location-based services in 5G networks and can be readily applied to current and future roll-out processes.

IEEE TRANSACTIONS ON MOBILE COMPUTING (2023)

Proceedings Paper Computer Science, Hardware & Architecture

MARISA: A Self-configuring Metasurfaces Absorption and Reflection Solution Towards 6G

Antonio Albanese, Francesco Devoti, Vincenzo Sciancalepore, Marco Di Renzo, Xavier Costa-Perez

Summary: Reconfigurable Intelligent Surfaces (RISs) are considered a key disruptive technology for future 6G networks that revolutionize wireless communication by controlling wave propagation properties. However, the need for fast and complex control channels to adapt to changing wireless conditions is a challenge. This paper proposes a self-configuring smart surface solution that can be easily installed in the environment.

IEEE CONFERENCE ON COMPUTER COMMUNICATIONS (IEEE INFOCOM 2022) (2022)

Proceedings Paper Telecommunications

RIS-Aware Indoor Network Planning: The Rennes Railway Station Case

Antonio Alhanese, Guillermo Encinas-Lago, Vincenzo Sciancalepore, Xavier Costa-Perez, Dinh-Thuy Phan-Huy, Stephane Ros

Summary: This paper discusses the application of reconfigurable intelligent surface (RIS) technology in wireless networks. By controlling the propagation environment, RIS can improve communication performance and solve dead-zone problems. The authors showcase the capabilities of RIS through theoretical analysis and practical validation in synthetic topologies and real indoor scenarios.

IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC 2022) (2022)

Proceedings Paper Computer Science, Interdisciplinary Applications

Forecasting for Network Management with Joint Statistical Modelling and Machine Learning

Leonardo Lo Schiavo, Marco Fiore, Marco Gramaglia, Albert Banchs, Xavier Costa-Perez

Summary: Forecasting is becoming increasingly important for mobile network operations, enabling anticipatory decisions and supporting zerotouch service and network management models. This research presents a hybrid approach that combines statistical modeling and machine learning for predictor design in mobile networks. Experimental results demonstrate that the new model outperforms current state-of-the-art predictors in network resource allocation and mobile traffic anomaly prediction.

2022 IEEE 23RD INTERNATIONAL SYMPOSIUM ON A WORLD OF WIRELESS, MOBILE AND MULTIMEDIA NETWORKS (WOWMOM 2022) (2022)

Proceedings Paper Computer Science, Interdisciplinary Applications

OROS: Orchestrating ROS-driven Collaborative Connected Robots in Mission-Critical Operations

Carmen Delgado, Lanfranco Zanzi, Xi Li, Xavier Costa-Perez

Summary: Battery life is a key challenge for collaborative robotics, especially in mission-critical tasks. This paper proposes a novel orchestration approach called OROS, which optimizes robotic navigation, sensing, and infrastructure resources to significantly reduce task completion time.

2022 IEEE 23RD INTERNATIONAL SYMPOSIUM ON A WORLD OF WIRELESS, MOBILE AND MULTIMEDIA NETWORKS (WOWMOM 2022) (2022)

Article Computer Science, Information Systems

vrAIn: Deep Learning Based Orchestration for Computing and Radio Resources in vRANs

Jose A. Ayala-Romero, Andres Garcia-Saavedra, Marco Gramaglia, Xavier Costa-Perez, Albert Banchs, Juan J. Alcaraz

Summary: This paper presents vrAIn, a resource orchestrator for vRANs based on deep reinforcement learning. By using an autoencoder to project high-dimensional context data and employing a deep deterministic policy gradient algorithm, vrAIn effectively maps contexts into resource control decisions. Experimental evaluation demonstrates the superior performance of vrAIn in terms of saving computing capacity, improving QoS targets, and increasing throughput.

IEEE TRANSACTIONS ON MOBILE COMPUTING (2022)

Proceedings Paper Computer Science, Information Systems

OTFS-superimposed PRACH-aided Localization for UAV Safety Applications

Francesco Linsalata, Antonio Albanese, Vincenzo Sciancalepore, Francesca Roveda, Maurizio Magarini, Xavier Costa-Perez

Summary: This paper explores a novel localization technique for UAVs equipped with cellular base stations in emergency scenarios using OTFS modulation for ToA measurements. The optimal UAV speed is determined as a trade-off between accuracy of ranging technique and power consumption. Results show that the proposed solution outperforms standard PRACH-based localization techniques in terms of RMSE.

2021 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM) (2021)

Proceedings Paper Telecommunications

Experimental Evaluation of Power Consumption in Virtualized Base Stations

Jose A. Ayala-Romero, Ihtisham Khalid, Andres Garcia-Saavedra, Xavier Costa-Perez, George Iosifidis

Summary: This study evaluates and analyzes the power consumption of virtualized Base Stations (vBS) experimentally, identifying interesting tradeoffs between power savings and performance. Two linear mixed-effect models are proposed to approximate the experimental data, helping to understand the power behavior of vBS and select power-efficient configurations. The release of the experimental dataset aims to encourage further research efforts in this area.

IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC 2021) (2021)

Article Computer Science, Information Systems

Multi-Domain Solutions for the Deployment of Private 5G Networks

Xi Li, Carlos Guimaraes, Giada Landi, Juan Brenes, Josep Mangues-Bafalluy, Jorge Baranda, Daniel Corujo, Vitor Cunha, Joao Fonseca, Joao Alegria, Aitor Zabala Orive, Jose Ordonez-Lucena, Paola Iovanna, Carlos J. Bernardos, Alain Mourad, Xavier Costa-Perez

Summary: This article proposes multiple multi-domain solutions for deploying private 5G networks in vertical industries and interconnecting them with public networks. The solutions have been validated in real industry verticals, demonstrating feasibility and efficiency.

IEEE ACCESS (2021)

Article Engineering, Electrical & Electronic

RISe of Flight: RIS-Empowered UAV Communications for Robust and Reliable Air-to-Ground Networks

Placido Mursia, Francesco Devoti, Vincenzo Sciancalepore, Xavier Costa-Perez

Summary: This study focuses on air-to-ground networks where UAVs equipped with Reconfigurable Intelligent Surfaces (RIS) can provide connectivity over selected areas. By compensating for flight effects, the proposed RiFe algorithm and its practical implementation Fair-RiFe automatically configure RIS parameters to account for undesired UAV oscillations due to adverse atmospheric conditions. Results show that both algorithms provide robustness and reliability, outperforming state-of-the-art solutions in various conditions.

IEEE OPEN JOURNAL OF THE COMMUNICATIONS SOCIETY (2021)

Proceedings Paper Computer Science, Hardware & Architecture

Bayesian Online Learning for Energy-Aware Resource Orchestration in Virtualized RANs

Jose A. Ayala-Romero, Andres Garcia-Saavedra, Xavier Costa-Perez, George Iosifidis

Summary: Radio Access Network Virtualization (vRAN) technology will lead the development of flexible radio stacks that adapt to various infrastructure. Research shows that analyzing the energy consumption of virtualized Base Stations (vBSs) is complex and influenced by human behavior, network load, and user mobility, highlighting the potential of machine learning in improving control over virtual base stations.

IEEE CONFERENCE ON COMPUTER COMMUNICATIONS (IEEE INFOCOM 2021) (2021)

No Data Available