Verifying the Robustness of Machine Learning based Intrusion Detection Against Adversarial Perturbation
Ehsan Nowroozi, Rahim Taheri, Mehrdad Hajizadeh, Thomas Bauschert · 2024
Neural networks (NNs) have been extensively adapted to various security tasks, such as spam detection, phishing, and intrusion detection. Particularly in IDS, NNs face significant vulnerabilities to adversarial attacks, where the adversary attempts to exploit the fragilities within machine-learning (ML) models. This study introduces a novel approach using interval-bound propagation (IBP) to formally verify and enhance the resilience of both shallow and deep NNs. We also investigated the effectiveness of various activation functions using benchmark IDS datasets. Our findings show that ReLu and Leaky-ReLu functions enhance resistance in shallow networks, whereas Tanh functions perform better in deep networks. We provide certified accuracies for models subjected to various input perturbations ranging from 0.0001 to 0.9, marking a significant advancement in verifying the security of NNs.