Omni: automated ensemble with unexpected models against adversarial evasion attack

Omni: automated ensemble with unexpected models against adversarial evasion attack
复制标题

DOI:
10.1007/s10664-021-10064-8
复制
发表时间:
2020-11
影响因子:
4.1
通讯作者:
Rui Shu;Tianpei Xia;L. Williams;T. Menzies
Rui Shu;Tianpei Xia;L. Williams;T. Menzies
中科院分区:
计算机科学2区
文献类型:
--
作者:
Rui Shu;Tianpei Xia;L. Williams;T. Menzies

文献摘要

被引文献

相似文献

基于机器学习的安全检测模型在现代恶意软件和入侵检测系统中已经变得普遍。然而,以前的研究表明,这种模型容易受到对抗性逃避攻击。在这种类型的攻击中,输入(即,对抗性示例)是由智能恶意对手特别制作的,目的是被现有技术水平的模型错误分类(例如,深度神经网络)。一旦攻击者可以欺骗分类器认为恶意输入实际上是良性的,他们可以使基于机器学习的恶意软件或入侵检测系统失效。目的通过集成模型的思想,帮助安全从业者和研究人员建立一个更强大的模型来抵御非自适应,白盒和非针对性的对抗性逃避攻击。其主要思想是探索创建“意外模型”的集合的方法;即,模型的控制超参数与对手的目标模型的超参数有很大的距离,然后我们用它来做一个优化的加权集成预测(FGSM、BIM、JSMA、DeepFool和Carlini-Wagner)(NSL-KDD,CIC-IDS-2017,CSE-CIC-IDS 2018,CICAndMal 2017和Contagio PDF数据集),我们展示了Omni作为对抗性攻击的防御策略与其他基线治疗相比是一种很有前途的方法。我们建议用远离攻击者的预期模型的非预期模型来创建系综(即,目标模型)通过超参数优化等方法。
ContextMachine learning-based security detection models have become prevalent in modern malware and intrusion detection systems. However, previous studies show that such models are susceptible to adversarial evasion attacks. In this type of attack, inputs (i.e., adversarial examples) are specially crafted by intelligent malicious adversaries, with the aim of being misclassified by existing state-of-the-art models (e.g., deep neural networks). Once the attackers can fool a classifier to think that a malicious input is actually benign, they can render a machine learning-based malware or intrusion detection system ineffective.ObjectiveTo help security practitioners and researchers build a more robust model against non-adaptive, white-box and non-targeted adversarial evasion attacks through the idea of ensemble model.MethodWe propose an approach calledOmni, the main idea of which is to explore methods that create an ensemble of “unexpected models”; i.e., models whose control hyperparameters have a large distance to the hyperparameters of an adversary’s target model, with which we then make an optimized weighted ensemble prediction.ResultsIn studies with five types of adversarial evasion attacks (FGSM, BIM, JSMA, DeepFool and Carlini-Wagner) on five security datasets (NSL-KDD, CIC-IDS-2017, CSE-CIC-IDS2018, CICAndMal2017 and the Contagio PDF dataset), we showOmniis a promising approach as a defense strategy against adversarial attacks when compared with other baseline treatments.ConclusionsWhen employing ensemble defense against adversarial evasion attacks, we suggest to create ensemble with unexpected models that are distant from the attacker’s expected model (i.e., target model) through methods such as hyperparameter optimization.