"what is the Problem Space?" Defining Host-space Adversarial Perturbations against Network Intrusion Detection Systems
| dc.contributor.author | Verkerken, Miel | |
| dc.contributor.author | D'Hooge, Laurens | |
| dc.contributor.author | Volckaert, Bruno | |
| dc.contributor.author | De Turck, Filip | |
| dc.contributor.author | Apruzzese, Giovanni | |
| dc.contributor.department | Department of Computer Science | |
| dc.date.accessioned | 2026-09-24T14:18:01Z | |
| dc.date.available | 2026-09-24T14:18:01Z | |
| dc.date.issued | 2026-06-01 | |
| dc.description | Publisher Copyright: © 2026 Copyright held by the owner/author(s). | en |
| dc.description.abstract | Network Intrusion Detection Systems (NIDS) are now increasingly leveraging Machine Learning (ML) techniques to detect malicious network activities. Numerous papers have scrutinized the security of ML-based NIDS (ML-NIDS) by testing them against various attacks involving adversarial perturbations. The findings were oftentimes worrying: by making imperceptible changes to a given input, powerful ML models would be bypassed. In this context, we took a step back and wondered: where (i.e., in what "space") have these perturbations been applied?We argue that real-world adversaries can apply adversarial perturbations only by operating on the hosts they can control - a concept which we define as host-space perturbations. To some, such an observation may seem trivial. And yet, through a systematic literature review (n=316), we found that prior work applied perturbations by manipulating pre-collected datapoints (e.g., a packet captured by the router, or a network flow analysed by the ML-NIDS). Such operations, while not impossible, may be outside the reach of an attacker who can only control some (unprivileged) hosts in a network. Hence, to demonstrate how to craft host-space perturbations and study some of their effects, we experimented on well-known benchmarks and a real-world network. We show that ML-NIDS that can detect the SSH-bruteforcing attempts launched via a given command string cannot detect any attempt launched by changing a single character of such a string. We then examined how such a minuscule change in the "problem space"(i.e., the attacker's host) can lead to devastating effects on the "feature space". We derive lessons learned on how to practically assess host-space perturbations. Our stance is that the security of ML-NIDS should be re-assessed. | en |
| dc.description.version | Peer reviewed | en |
| dc.format.extent | 17 | |
| dc.format.extent | 1295236 | |
| dc.format.extent | 1043-1059 | |
| dc.format.extent | ||
| dc.identifier.citation | Verkerken, M, D'Hooge, L, Volckaert, B, De Turck, F & Apruzzese, G 2026, "what is the Problem Space?" Defining Host-space Adversarial Perturbations against Network Intrusion Detection Systems. in ASIA CCS 2026 - Proceedings of the 21st ACM ASIA Conference on Computer and Communications Security. Proceedings of the ACM Asia Conference on Computer and Communications Security, Association for Computing Machinery, Inc, pp. 1043-1059, 21st ACM Asia Conference on Computer and Communications Security, AsiaCCS 2026, Bangalore, India, 1/06/26. https://doi.org/10.1145/3779208.3807482 | en |
| dc.identifier.citation | conference | en |
| dc.identifier.doi | 10.1145/3779208.3807482 | |
| dc.identifier.isbn | 9798400723568 | |
| dc.identifier.other | 250865416 | |
| dc.identifier.other | ff0ba032-e94a-4ce0-84ff-6ec3e50e2fb9 | |
| dc.identifier.other | 105042454866 | |
| dc.identifier.other | unpaywall: 10.1145/3779208.3807482 | |
| dc.identifier.uri | https://hdl.handle.net/20.500.11815/8365 | |
| dc.language.iso | en | |
| dc.publisher | Association for Computing Machinery, Inc | |
| dc.relation.ispartofseries | ASIA CCS 2026 - Proceedings of the 21st ACM ASIA Conference on Computer and Communications Security; () | en |
| dc.relation.ispartofseries | Proceedings of the ACM Asia Conference on Computer and Communications Security; () | en |
| dc.relation.url | https://www.scopus.com/pages/publications/105042454866 | en |
| dc.rights | info:eu-repo/semantics/openAccess | en |
| dc.subject | Adversarial ML Attacks | en |
| dc.subject | Evasion | en |
| dc.subject | Out Of Distribution | en |
| dc.subject | Computational Theory and Mathematics | en |
| dc.subject | Computer Networks and Communications | en |
| dc.subject | Computer Science Applications | en |
| dc.title | "what is the Problem Space?" Defining Host-space Adversarial Perturbations against Network Intrusion Detection Systems | en |
| dc.type | /dk/atira/pure/researchoutput/researchoutputtypes/contributiontobookanthology/conference | en |
Skrár
Original bundle
1 - 1 af 1
- Nafn:
- 3779208.3807482.pdf
- Stærð:
- 1.24 MB
- Snið:
- Adobe Portable Document Format