Self-Configurable Cyber-Physical Intrusion Detection for Smart Homes Using Reinforcement Learning

Self-Configurable Cyber-Physical Intrusion Detection for Smart Homes Using Reinforcement Learning
复制标题

DOI:
10.1109/tifs.2020.3042049
复制
发表时间:
2021-01-01
影响因子:
6.8
通讯作者:
Panaousis, Emmanouil
Panaousis, Emmanouil
中科院分区:
计算机科学1区
文献类型:
--
作者:
Heartfield, Ryan;Loukas, George;Panaousis, Emmanouil

文献摘要

被引文献

相似文献

基于物联网(IoT)的现代智能家居是一个具有挑战性的安全环境:设备变化,新漏洞被发现且通常未修补,不同用户与设备的交互方式不同,对网络风险的态度也不同。安全漏洞的影响不仅限于网络空间,它还可以影响或促进物理空间,例如通过语音。在这种环境中,入侵检测不能仅仅依赖于静态模型,这些模型随着时间的推移保持不变,并且对所有用户都是相同的。我们提出了MAGPIE,这是第一个智能家居入侵检测系统,它能够自主调整其底层异常分类模型的决策函数,以适应智能家居的变化条件(例如,新的设备,新的自动化规则和用户与它们的交互)。该方法通过将一种新的基于概率聚类的奖励机制应用于非平稳多臂强盗强化学习来实现这一目标。MAGPIE根据其输出的聚类轮廓分数奖励其底层隔离森林无监督异常分类器的超参数集。在真实家庭中的实验评估表明,由于两项进一步的创新,MAGPIE表现出很高的准确性:它考虑了网络和物理数据源;它还利用在每种情况下表现出最高准确性的模型来检测人类的存在。MAGPIE以开源格式提供,与其评估数据集一起,因此它可以从无监督和强化学习的未来进步中受益,并能够随着智能家居环境和攻击的发展而进一步丰富数据源。
The modern Internet of Things (IoT)-based smart home is a challenging environment to secure: devices change, new vulnerabilities are discovered and often remain unpatched, and different users interact with their devices differently and have different cyber risk attitudes. A security breach's impact is not limited to cyberspace, as it can also affect or be facilitated in physical space, for example, via voice. In this environment, intrusion detection cannot rely solely on static models that remain the same over time and are the same for all users. We present MAGPIE, the first smart home intrusion detection system that is able to autonomously adjust the decision function of its underlying anomaly classification models to a smart home's changing conditions (e.g., new devices, new automation rules and user interaction with them). The method achieves this goal by applying a novel probabilistic cluster-based reward mechanism to non-stationary multi-armed bandit reinforcement learning. MAGPIE rewards the sets of hyperparameters of its underlying isolation forest unsupervised anomaly classifiers based on the cluster silhouette scores of their output. Experimental evaluation in a real household shows that MAGPIE exhibits high accuracy because of two further innovations: it takes into account both cyber and physical sources of data; and it detects human presence to utilise models that exhibit the highest accuracy in each case. MAGPIE is available in open-source format, together with its evaluation datasets, so it can benefit from future advances in unsupervised and reinforcement learning and be able to be enriched with further sources of data as smart home environments and attacks evolve.