Could Min-Max Optimization be a General Defense Against Adversarial Attacks?

Rana Abou Khamis, Ashraf Matrawy · 2024

Adversarial learning based on Min-Max formulations has been broadly employed in deep neural networks (DNNs) as an effective defense approach against adversarial attacks. Motivated by the level of resistance achieved by adversarial trained models against a single type of adversarial attack, in this paper we investigate if utilizing Min-Max formulation in various deep learning-based Intrusion Detection System (IDS) architectures may be considered an optimized defense against different types of state-of-the-art adversarial attacks. To investigate this, we generate adversarial samples using multiple attack methods using two benchmark IDS datasets, UNSW-NB 15 and NSL-KDD. Then, we conduct comprehensive experiments on adversarial trained models, including convolutional neural networks (CNN) and recurrent neural networks (RNN) architectures. Our results demonstrate that the adversarial IDS models that were trained against one type of attack show robustness against different adversarial attacks that could reach up to 40% higher accuracy than IDS models trained by adversarial-free (baseline) datasets. Finally, we demonstrate that training models with Carlini and Wagner (CW) adversarial samples in CNN leads to better robustness against other adversarial attacks.

Read the paper · More papers on PaperTik