AppCon : Mitigating evasion attacks to ML cyber detectors

dc.contributor.authorApruzzese, Giovanni
dc.contributor.authorAndreolini, Mauro
dc.contributor.authorMarchetti, Mirco
dc.contributor.authorColacino, Vincenzo Giuseppe
dc.contributor.authorRusso, Giacomo
dc.contributor.departmentDepartment of Computer Science
dc.date.accessioned2026-09-21T15:23:01Z
dc.date.available2026-09-21T15:23:01Z
dc.date.issued2020-04-01
dc.descriptionPublisher Copyright: © 2020 by the authors.en
dc.description.abstractAdversarial attacks represent a critical issue that prevents the reliable integration of machine learning methods into cyber defense systems. Past work has shown that even proficient detectors are highly affected just by small perturbations to malicious samples, and that existing countermeasures are immature. We address this problem by presenting AppCon, an original approach to harden intrusion detectors against adversarial evasion attacks. Our proposal leverages the integration of ensemble learning to realistic network environments, by combining layers of detectors devoted to monitor the behavior of the applications employed by the organization. Our proposal is validated through extensive experiments performed in heterogeneous network settings simulating botnet detection scenarios, and consider detectors based on distinct machine-and deep-learning algorithms. The results demonstrate the effectiveness of AppCon in mitigating the dangerous threat of adversarial attacks in over 75% of the considered evasion attempts, while not being affected by the limitations of existing countermeasures, such as performance degradation in non-adversarial settings. For these reasons, our proposal represents a valuable contribution to the development of more secure cyber defense platforms.en
dc.description.versionPeer revieweden
dc.format.extent1662843
dc.format.extent
dc.identifier.citationApruzzese, G, Andreolini, M, Marchetti, M, Colacino, V G & Russo, G 2020, 'AppCon : Mitigating evasion attacks to ML cyber detectors', Symmetry, vol. 12, no. 4, 653. https://doi.org/10.3390/SYM12040653en
dc.identifier.doi10.3390/SYM12040653
dc.identifier.issn2073-8994
dc.identifier.other250864797
dc.identifier.otherf63f5c86-ba5a-4e9e-b04d-8b62a451ea37
dc.identifier.other85084581778
dc.identifier.urihttps://hdl.handle.net/20.500.11815/8304
dc.language.isoen
dc.relation.ispartofseriesSymmetry; 12(4)en
dc.relation.urlhttps://www.scopus.com/pages/publications/85084581778en
dc.rightsinfo:eu-repo/semantics/openAccessen
dc.subjectAdversarial attacksen
dc.subjectCyber securityen
dc.subjectEvasion attacksen
dc.subjectMachine learningen
dc.subjectNetwork intrusion detectionen
dc.subjectComputer Science (miscellaneous)en
dc.subjectChemistry (miscellaneous)en
dc.subjectGeneral Mathematicsen
dc.subjectPhysics and Astronomy (miscellaneous)en
dc.titleAppCon : Mitigating evasion attacks to ML cyber detectorsen
dc.type/dk/atira/pure/researchoutput/researchoutputtypes/contributiontojournal/articleen

Skrár

Original bundle

Niðurstöður 1 - 1 af 1
Nafn:
symmetry-12-00653-with-cover.pdf
Stærð:
1.59 MB
Snið:
Adobe Portable Document Format