"what is the Problem Space?" Defining Host-space Adversarial Perturbations against Network Intrusion Detection Systems

dc.contributor.authorVerkerken, Miel
dc.contributor.authorD'Hooge, Laurens
dc.contributor.authorVolckaert, Bruno
dc.contributor.authorDe Turck, Filip
dc.contributor.authorApruzzese, Giovanni
dc.contributor.departmentDepartment of Computer Science
dc.date.accessioned2026-09-24T14:18:01Z
dc.date.available2026-09-24T14:18:01Z
dc.date.issued2026-06-01
dc.descriptionPublisher Copyright: © 2026 Copyright held by the owner/author(s).en
dc.description.abstractNetwork Intrusion Detection Systems (NIDS) are now increasingly leveraging Machine Learning (ML) techniques to detect malicious network activities. Numerous papers have scrutinized the security of ML-based NIDS (ML-NIDS) by testing them against various attacks involving adversarial perturbations. The findings were oftentimes worrying: by making imperceptible changes to a given input, powerful ML models would be bypassed. In this context, we took a step back and wondered: where (i.e., in what "space") have these perturbations been applied?We argue that real-world adversaries can apply adversarial perturbations only by operating on the hosts they can control - a concept which we define as host-space perturbations. To some, such an observation may seem trivial. And yet, through a systematic literature review (n=316), we found that prior work applied perturbations by manipulating pre-collected datapoints (e.g., a packet captured by the router, or a network flow analysed by the ML-NIDS). Such operations, while not impossible, may be outside the reach of an attacker who can only control some (unprivileged) hosts in a network. Hence, to demonstrate how to craft host-space perturbations and study some of their effects, we experimented on well-known benchmarks and a real-world network. We show that ML-NIDS that can detect the SSH-bruteforcing attempts launched via a given command string cannot detect any attempt launched by changing a single character of such a string. We then examined how such a minuscule change in the "problem space"(i.e., the attacker's host) can lead to devastating effects on the "feature space". We derive lessons learned on how to practically assess host-space perturbations. Our stance is that the security of ML-NIDS should be re-assessed.en
dc.description.versionPeer revieweden
dc.format.extent17
dc.format.extent1295236
dc.format.extent1043-1059
dc.format.extent
dc.identifier.citationVerkerken, M, D'Hooge, L, Volckaert, B, De Turck, F & Apruzzese, G 2026, "what is the Problem Space?" Defining Host-space Adversarial Perturbations against Network Intrusion Detection Systems. in ASIA CCS 2026 - Proceedings of the 21st ACM ASIA Conference on Computer and Communications Security. Proceedings of the ACM Asia Conference on Computer and Communications Security, Association for Computing Machinery, Inc, pp. 1043-1059, 21st ACM Asia Conference on Computer and Communications Security, AsiaCCS 2026, Bangalore, India, 1/06/26. https://doi.org/10.1145/3779208.3807482en
dc.identifier.citationconferenceen
dc.identifier.doi10.1145/3779208.3807482
dc.identifier.isbn9798400723568
dc.identifier.other250865416
dc.identifier.otherff0ba032-e94a-4ce0-84ff-6ec3e50e2fb9
dc.identifier.other105042454866
dc.identifier.otherunpaywall: 10.1145/3779208.3807482
dc.identifier.urihttps://hdl.handle.net/20.500.11815/8365
dc.language.isoen
dc.publisherAssociation for Computing Machinery, Inc
dc.relation.ispartofseriesASIA CCS 2026 - Proceedings of the 21st ACM ASIA Conference on Computer and Communications Security; ()en
dc.relation.ispartofseriesProceedings of the ACM Asia Conference on Computer and Communications Security; ()en
dc.relation.urlhttps://www.scopus.com/pages/publications/105042454866en
dc.rightsinfo:eu-repo/semantics/openAccessen
dc.subjectAdversarial ML Attacksen
dc.subjectEvasionen
dc.subjectOut Of Distributionen
dc.subjectComputational Theory and Mathematicsen
dc.subjectComputer Networks and Communicationsen
dc.subjectComputer Science Applicationsen
dc.title"what is the Problem Space?" Defining Host-space Adversarial Perturbations against Network Intrusion Detection Systemsen
dc.type/dk/atira/pure/researchoutput/researchoutputtypes/contributiontobookanthology/conferenceen

Skrár

Original bundle

Niðurstöður 1 - 1 af 1
Nafn:
3779208.3807482.pdf
Stærð:
1.24 MB
Snið:
Adobe Portable Document Format