When Adversarial Perturbations meet Concept Drift : an Exploratory Analysis on ML-NIDS
| dc.contributor.author | Apruzzese, Giovanni | |
| dc.contributor.author | Fass, Aurore | |
| dc.contributor.author | Pierazzi, Fabio | |
| dc.contributor.department | Department of Computer Science | |
| dc.date.accessioned | 2026-09-24T14:20:01Z | |
| dc.date.available | 2026-09-24T14:20:01Z | |
| dc.date.issued | 2024-11-22 | |
| dc.description | Publisher Copyright: © 2024 Copyright held by the owner/author(s). | en |
| dc.description.abstract | We scrutinize the effects of “blind” adversarial perturbations against machine learning (ML)-based network intrusion detection systems (NIDS) affected by concept drift. There may be cases in which a real attacker – unable to access and hence unaware that the ML-NIDS is weakened by concept drift – attempts to evade the ML-NIDS with data perturbations. It is currently unknown if the cumulative effect of such adversarial perturbations and concept drift leads to a greater or lower impact on ML-NIDS. In this “open problem” paper, we seek to investigate this unusual, but realistic, setting—we are not interested in perfect knowledge attackers. We begin by retrieving a publicly available dataset of documented network traces captured in a real, large (>300 hosts) organization. Overall, these traces include several years of raw traffic packets—both benign and malicious. Then, we adversarially manipulate malicious packets with problem-space perturbations, representing a physically realizable attack. Finally, we carry out the first exploratory analysis focused on comparing the effects of our “adversarial examples” with their respective unperturbed malicious variants in concept-drift scenarios. Through two case studies (a “short-term” one of 8 days; and a “long-term” one of 4 years) encompassing 48 detector variants, we find that, although our perturbations induce a lower detection rate in concept-drift scenarios, some perturbations yield adverse effects for the attacker in intriguing use cases. Overall, our study shows that the topics we covered are still an open problem which require a re-assessment from future research. | en |
| dc.description.version | Peer reviewed | en |
| dc.format.extent | 12 | |
| dc.format.extent | 1742824 | |
| dc.format.extent | 149-160 | |
| dc.format.extent | ||
| dc.identifier.citation | Apruzzese, G, Fass, A & Pierazzi, F 2024, When Adversarial Perturbations meet Concept Drift : an Exploratory Analysis on ML-NIDS. in AISec 2024 - Proceedings of the 2024 Workshop on Artificial Intelligence and Security, Co-Located with : CCS 2024. AISec 2024 - Proceedings of the 2024 Workshop on Artificial Intelligence and Security, Co-Located with: CCS 2024, Association for Computing Machinery, Inc, pp. 149-160, 16th ACM Workshop on Artificial Intelligence and Security, AISec 2024, co-located with CCS 2024, Salt Lake City, United States, 14/10/24. https://doi.org/10.1145/3689932.3694757 | en |
| dc.identifier.citation | conference | en |
| dc.identifier.doi | 10.1145/3689932.3694757 | |
| dc.identifier.isbn | 9798400712289 | |
| dc.identifier.other | 250866225 | |
| dc.identifier.other | 07b881b8-b639-433b-ae35-46b2c417a361 | |
| dc.identifier.other | 85213132637 | |
| dc.identifier.uri | https://hdl.handle.net/20.500.11815/8366 | |
| dc.language.iso | en | |
| dc.publisher | Association for Computing Machinery, Inc | |
| dc.relation.ispartofseries | AISec 2024 - Proceedings of the 2024 Workshop on Artificial Intelligence and Security, Co-Located with; () | en |
| dc.relation.ispartofseries | AISec 2024 - Proceedings of the 2024 Workshop on Artificial Intelligence and Security, Co-Located with: CCS 2024; () | en |
| dc.relation.url | https://www.scopus.com/pages/publications/85213132637 | en |
| dc.rights | info:eu-repo/semantics/openAccess | en |
| dc.subject | adversarial example | en |
| dc.subject | ctu13 | en |
| dc.subject | data drift | en |
| dc.subject | distribution shift | en |
| dc.subject | machine learning | en |
| dc.subject | mcfp | en |
| dc.subject | network intrusion detection | en |
| dc.subject | temporal evaluation | en |
| dc.subject | Artificial Intelligence | en |
| dc.subject | Computer Networks and Communications | en |
| dc.subject | Software | en |
| dc.title | When Adversarial Perturbations meet Concept Drift : an Exploratory Analysis on ML-NIDS | en |
| dc.type | /dk/atira/pure/researchoutput/researchoutputtypes/contributiontobookanthology/conference | en |
Skrár
Original bundle
1 - 1 af 1
- Nafn:
- 3689932.3694757.pdf
- Stærð:
- 1.66 MB
- Snið:
- Adobe Portable Document Format