节点文献

针对流量异常检测的对抗性攻击防御研究

Research on Adversarial Attack Defense for Traffic Anomaly Detection

【作者】 田力;

【导师】 秦华;

【作者基本信息】 北京工业大学 , 计算机科学与技术, 2023, 硕士

【摘要】 随着互联网的发展与普及,网络安全成为继海、陆、空外的“第四战略空间”。在网络安全领域,入侵检测系统是监控网络流量,防止恶意流量访问的有效机制。然而,当前入侵检测系统的精度依赖于已建立的网络行为模型。若对恶意流量添加适当扰动,可轻易绕过入侵检测系统的识别,从而实现攻击目的。这种对抗性攻击算法对以机器学习和深度学习为基础的入侵检测系统构成了严重的威胁,降低了系统的可靠性和准确性。虽然当前已有工作开展了对抗性攻击防御研究,但多数研究只关注流量数据的空间特征,忽略了数据中存在的时序特征,导致无法准确防御对抗性攻击。此外,模型的鲁棒性优化可以在一定程度上防御对抗性攻击,但现有研究只考虑了最大化对抗训练样本的攻击能力,忽略了最小化模型误分类的对抗训练目标,导致模型产生严重的过拟合,影响防御效果。为解决以上问题,本文开展网络流量对抗性攻击防御研究。本文研究思路从模型搭建和模型参数优化两个方面入手,主要内容总结如下:针对现有流量分类模型在对抗性攻击环境下分类能力不足的问题,本文提出基于时序特征分析的对抗性攻击防御模型。该模型充分考虑网络流量的时序关系,采用时序卷积网络提取网络流量时序序列数据的空间特征和局部时序特征,加入注意力机制计算特征权重,利用双向长短期记忆网络对带权特征进行建模,在对抗性攻击场景下,降低扰动对模型分类准确率的影响。实验结果表明,在有限训练数据下,多阶段提取流量样本的时序特征可以提升模型的分类准确率并且可以提高模型在对抗性攻击场景下的鲁棒性。针对现有鲁棒优化策略对异常流量识别模型低效的问题,本文提出基于深度强化学习的模型鲁棒优化算法。该算法将对抗训练样本构造问题转化为搜索梯度优化问题,利用强化学习自适应特点,通过与目标模型交互搜索最优对抗训练样本,优化模型参数,提升模型在对抗性攻击场景下的鲁棒性。实验结果表明,训练后的智能体可以给出梯度投影下降算法的最优动作参数,相比于直接人为设置参数,构造的对抗训练样本对目标模型的鲁棒性提升更为有效。最后,比较了几种常用的对抗性攻击防御策略,实验证明该算法在一阶攻击场景下防御效果明显优于其它算法,在Deep Fool攻击、C&W攻击场景下,防御效果依然有明显的优势。

【Abstract】 With the development and popularization of the Internet,cyber security has become the “fourth strategic space” after sea,road and air.In the field of cyber security,intrusion detection system is an effective mechanism to monitor network traffic and prevent malicious traffic from accessing.However,the accuracy of current intrusion detection systems depends on the established network behavior model.The attacker can achieve attacking purpose by disturbing malicious traffic to make its data characteristics different from known malicious traffic to bypass the identification of intrusion detection system.This adversarial attack algorithm poses serious threat to the intrusion detection system that based on artificial intelligence and reduces the reliability and accuracy of the system.Although current work has carried out the research on adversarial attack defense,most of the research only focuses on spatial features of the data and ignores the temporal features in the data,which results in the inability to accurately defend against adversarial attacks.In addition,robustness optimization of model can partly protect against adversative attacks.However,existing studies only consider maximizing the attack ability of adversative training samples and ignoring the adversative training goal of minimizing model misclassification rate,which results in serious overfitting problem.In order to solve the above problems,this thesis studies adversarial attack defense of network traffic from model building and model parameter optimization.The main research contents are as follows:To solve the problem of low classification accuracy of current traffic identification model under adversarial environment,this thesis proposes an adversarial attack defense model based on sequential feature analysis.The model analyzes temporal relationship among network traffic,and uses temporal convolution network to extract the global and local temporal features of network traffic.Attention mechanism is added to the model to calculate important feature weights.The bidirectional long short-term memory network is used to model the temporal features and reduce the effect of perturbation on the classification accuracy under the adversarial environment.The experimental results show that under limited training data,the proposed model can extract both global and local temporal features to improve the accuracy of classification model and enhance the robustness of the model in adversarial attack scenario.To solve the effectiveness problem of existing robust optimization strategies on abnormal traffic identification model,this thesis proposes an adversarial attack defense algorithm based on deep reinforcement learning.In the algorithm,the construction problem of adversarial training samples is transformed into a gradient optimization problem of search strategy.The adaptive characteristics of reinforcement learning is utilized to search the optimal adversarial training samples by interacting with the target model.Such the step can optimize the model parameters and improve the robustness of the model in adversarial scenarios.The experimental results showed that the trained agent can provide optimal parameter action of gradient projection descent algorithm.Compared with the artificial parameter setting,the constructed adversarial training samples can improve the robustness of the target model significantly.In addition,compared with existing adversarial attack defense methods,the defense effect of PG-AAG algorithm is obviously better than other algorithms under first order attack scenario.The performance of PG-AAG is still well under Deep Fool attack and C&W attack.

  • 【分类号】TP393.08
节点文献中: 

本文链接的文献网络图示:

本文的引文网络