Defending the Defender: Detecting Adversarial Examples for Network Intrusion Detection Systems
Dalila Khettaf, Lydia Bouzar-Benlabiod · 2024
The advancement in network security threats led to the development of new intrusion detection systems(IDS) that rely on deep learning (DL). Along with other systems based on DL, deep IDS suffer from adversarial examples: malicious inputs aiming to change the prediction of a model. Protecting DL against adversarial examples remains an open challenge. In this paper, we propose “NIDS-Defend” a framework to enhance the robustness of a network IDS against adversarial attacks. Our framework is composed of two layers: a statistical test and a classifier, together they detect adversarial examples in real-time. The detection process consists of two steps: (1) flagging flows that contain adversarial examples with a statistical test, and (2) extracting individual adversarial examples in the previously flagged flows with a classifier. Our approach is evaluated on a network IDS trained with the NSL-KDD dataset against (1) Boundary attack and (2) HopSkipJumpAttack.