TrojanFlow: A Neural Backdoor Attack to Deep Learning-based Network Traffic Classifiers

TrojanFlow: A Neural Backdoor Attack to Deep Learning-based Network Traffic Classifiers
复制标题

DOI:
10.1109/infocom48880.2022.9796878
复制
发表时间:
2022-05
期刊:
IEEE INFOCOM 2022 - IEEE Conference on Computer Communications
影响因子:
--
通讯作者:
R. Ning;Chunsheng Xin;Hongyi Wu
R. Ning;Chunsheng Xin;Hongyi Wu
中科院分区:
其他
文献类型:
--
作者:
R. Ning;Chunsheng Xin;Hongyi Wu

文献摘要

相似文献

虽然基于深度学习 (DL) 的网络流量分类已在一系列实际应用中取得了成功,例如网络管理和安全控制等,但它很容易受到对抗性攻击。本文报告了 TrojanFlow,这是一种针对基于深度学习的网络流量分类器的新型实用神经后门攻击。与使用指定且与样本无关的触发器来植入后门的传统神经后门攻击相比,TrojanFlow 使用动态且特定于样本的触发器来毒害模型,这些触发器经过优化以有效劫持模型。它具有独特的设计,可以在训练过程中联合优化触发生成器和目标分类器。因此,触发生成器可以根据输入样本制作优化的触发器,以有效地操纵模型的预测。使用 Pytorch 开发了一个精心设计的原型,以演示 TrojanFlow 攻击多个基于深度学习的实用网络流量分类器。进行彻底的分析是为了深入了解 TrojanFlow 的有效性,揭示其有效原因以及它如何有效劫持模型的基本原理。使用三种广泛采用的深度学习网络流量分类器架构,在著名的 ISCXVPN2016 数据集上进行了大量实验。在五种最先进的后门防御下,TrojanFlow 与其他两种后门攻击进行了比较。结果表明,TrojanFlow 攻击是隐秘、高效的,并且针对现有的神经后门缓解方案具有高度鲁棒性。
While deep learning (DL)-based network traffic classification has demonstrated its success in a range of practical applications, such as network management and security control to just name a few, it is vulnerable to adversarial attacks. This paper reports TrojanFlow, a new and practical neural backdoor attack to DL-based network traffic classifiers. In contrast to traditional neural backdoor attacks where a designated and sample-agnostic trigger is used to plant backdoor, TrojanFlow poisons a model using dynamic and sample-specific triggers that are optimized to efficiently hijack the model. It features a unique design to jointly optimize the trigger generator with the target classifier during training. The trigger generator can thus craft optimized triggers based on the input sample to efficiently manipulate the model’s prediction. A well-engineered prototype is developed using Pytorch to demonstrate TrojanFlow attacking multiple practical DL-based network traffic classifiers. Thorough analysis is conducted to gain insights into the effectiveness of TrojanFlow, revealing the fundamentals of why it is effective and what it does to efficiently hijack the model. Extensive experiments are carried out on the well-known ISCXVPN2016 dataset with three widely adopted DL network traffic classifier architectures. TrojanFlow is compared with two other backdoor attacks under five state-of-the-art backdoor defenses. The results show that the TrojanFlow attack is stealthy, efficient, and highly robust against existing neural backdoor mitigation schemes.