Adversarial attacks on machine learning cybersecurity defences in Industrial Control Systems

Adversarial attacks on machine learning cybersecurity defences in Industrial Control Systems
复制标题

DOI:
10.1016/j.jisa.2020.102717
复制
发表时间:
2021-02-02
影响因子:
5.6
通讯作者:
Wedgbury, Adam
Wedgbury, Adam
中科院分区:
计算机科学3区
文献类型:
--
作者:
Anthi, Eirini;Williams, Lowri;Wedgbury, Adam

文献摘要

被引文献

相似文献

基于机器学习的入侵检测系统(IDS)的普及和应用使得工业控制系统(ICS)中的网络攻击自动检测更加灵活和高效。然而,这种IDS的引入也产生了额外的攻击向量;学习模型也可能受到网络攻击,也称为对抗性机器学习(AML)。这种攻击可能会在ICS系统中产生严重后果,因为对手可能会绕过IDS。这可能导致延迟的攻击检测,从而可能导致基础设施损坏,财务损失,甚至生命损失。本文探讨了如何通过使用基于雅可比的显着性图攻击生成对抗样本并探索分类行为,将对抗学习用于目标监督模型。该分析还包括探索此类样本如何支持使用对抗训练的监督模型的鲁棒性。一个真实的电力系统数据集被用来支持本文提出的实验。总体而言,当存在对抗样本时,两种广泛使用的分类器随机森林和J 48的分类性能分别下降了6个和11个百分点。他们的表现在对抗性训练后有所改善,证明了他们对这种攻击的鲁棒性。
The proliferation and application of machine learning-based Intrusion Detection Systems (IDS) have allowed for more flexibility and efficiency in the automated detection of cyber attacks in Industrial Control Systems (ICS). However, the introduction of such IDSs has also created an additional attack vector; the learning models may also be subject to cyber attacks, otherwise referred to as Adversarial Machine Learning (AML). Such attacks may have severe consequences in ICS systems, as adversaries could potentially bypass the IDS. This could lead to delayed attack detection which may result in infrastructure damages, financial loss, and even loss of life. This paper explores how adversarial learning can be used to target supervised models by generating adversarial samples using the Jacobian-based Saliency Map attack and exploring classification behaviours. The analysis also includes the exploration of how such samples can support the robustness of supervised models using adversarial training. An authentic power system dataset was used to support the experiments presented herein. Overall, the classification performance of two widely used classifiers, Random Forest and J48, decreased by 6 and 11 percentage points when adversarial samples were present. Their performances improved following adversarial training, demonstrating their robustness towards such attacks.