When Adversarial Perturbations meet Concept Drift : an Exploratory Analysis on ML-NIDS

dc.contributor.authorApruzzese, Giovanni
dc.contributor.authorFass, Aurore
dc.contributor.authorPierazzi, Fabio
dc.contributor.departmentDepartment of Computer Science
dc.date.accessioned2026-09-24T14:20:01Z
dc.date.available2026-09-24T14:20:01Z
dc.date.issued2024-11-22
dc.descriptionPublisher Copyright: © 2024 Copyright held by the owner/author(s).en
dc.description.abstractWe scrutinize the effects of “blind” adversarial perturbations against machine learning (ML)-based network intrusion detection systems (NIDS) affected by concept drift. There may be cases in which a real attacker – unable to access and hence unaware that the ML-NIDS is weakened by concept drift – attempts to evade the ML-NIDS with data perturbations. It is currently unknown if the cumulative effect of such adversarial perturbations and concept drift leads to a greater or lower impact on ML-NIDS. In this “open problem” paper, we seek to investigate this unusual, but realistic, setting—we are not interested in perfect knowledge attackers. We begin by retrieving a publicly available dataset of documented network traces captured in a real, large (>300 hosts) organization. Overall, these traces include several years of raw traffic packets—both benign and malicious. Then, we adversarially manipulate malicious packets with problem-space perturbations, representing a physically realizable attack. Finally, we carry out the first exploratory analysis focused on comparing the effects of our “adversarial examples” with their respective unperturbed malicious variants in concept-drift scenarios. Through two case studies (a “short-term” one of 8 days; and a “long-term” one of 4 years) encompassing 48 detector variants, we find that, although our perturbations induce a lower detection rate in concept-drift scenarios, some perturbations yield adverse effects for the attacker in intriguing use cases. Overall, our study shows that the topics we covered are still an open problem which require a re-assessment from future research.en
dc.description.versionPeer revieweden
dc.format.extent12
dc.format.extent1742824
dc.format.extent149-160
dc.format.extent
dc.identifier.citationApruzzese, G, Fass, A & Pierazzi, F 2024, When Adversarial Perturbations meet Concept Drift : an Exploratory Analysis on ML-NIDS. in AISec 2024 - Proceedings of the 2024 Workshop on Artificial Intelligence and Security, Co-Located with : CCS 2024. AISec 2024 - Proceedings of the 2024 Workshop on Artificial Intelligence and Security, Co-Located with: CCS 2024, Association for Computing Machinery, Inc, pp. 149-160, 16th ACM Workshop on Artificial Intelligence and Security, AISec 2024, co-located with CCS 2024, Salt Lake City, United States, 14/10/24. https://doi.org/10.1145/3689932.3694757en
dc.identifier.citationconferenceen
dc.identifier.doi10.1145/3689932.3694757
dc.identifier.isbn9798400712289
dc.identifier.other250866225
dc.identifier.other07b881b8-b639-433b-ae35-46b2c417a361
dc.identifier.other85213132637
dc.identifier.urihttps://hdl.handle.net/20.500.11815/8366
dc.language.isoen
dc.publisherAssociation for Computing Machinery, Inc
dc.relation.ispartofseriesAISec 2024 - Proceedings of the 2024 Workshop on Artificial Intelligence and Security, Co-Located with; ()en
dc.relation.ispartofseriesAISec 2024 - Proceedings of the 2024 Workshop on Artificial Intelligence and Security, Co-Located with: CCS 2024; ()en
dc.relation.urlhttps://www.scopus.com/pages/publications/85213132637en
dc.rightsinfo:eu-repo/semantics/openAccessen
dc.subjectadversarial exampleen
dc.subjectctu13en
dc.subjectdata driften
dc.subjectdistribution shiften
dc.subjectmachine learningen
dc.subjectmcfpen
dc.subjectnetwork intrusion detectionen
dc.subjecttemporal evaluationen
dc.subjectArtificial Intelligenceen
dc.subjectComputer Networks and Communicationsen
dc.subjectSoftwareen
dc.titleWhen Adversarial Perturbations meet Concept Drift : an Exploratory Analysis on ML-NIDSen
dc.type/dk/atira/pure/researchoutput/researchoutputtypes/contributiontobookanthology/conferenceen

Skrár

Original bundle

Niðurstöður 1 - 1 af 1
Nafn:
3689932.3694757.pdf
Stærð:
1.66 MB
Snið:
Adobe Portable Document Format