IDS-GAN: Adversarial Attack against Intrusion Detection Based on Generative Adversarial Networks

Di Wang, Xuemeng Wang, Jinlong Fei · 2024

Intrusion detection protects network security and data integrity by monitoring and identifying malicious activities and abnormal behaviors in the network. With the increasing volume of network data, machine learning-based intrusion detection has gained popularity as the predominant approach. However, research has demonstrated that machine learning is susceptible to adversarial samples, where even a small, intentionally crafted perturbation can result in incorrect model outputs. In this paper, the idea of adversarial samples is applied to traffic obfuscation in IDS, and an adversarial obfuscation method based on generative adversarial network is proposed. This method clearly divides functional and nonfunctional features, and only adds perturbation to nonfunctional features, so as to avoid model detection while maintaining functionality of traffic. In addition, this method does not require structure and internal parameters of the model, which is a black box obfuscation method. In the experiment, the NSL-KDD dataset was employed to assess the obfuscation performance of the method on two target models. The results indicate that the method demonstrates effective obfuscation capabilities for both DoS and Probe malicious traffic.

Read the paper · More papers on PaperTik