Evading IoT Intrusion Detection Systems with GAN
Mariama Mbow, Rodrigo Román, Takeshi Takahashi, Kouichi Sakurai · 2024
Network intrusion detection systems are essential tools used in cybersecurity to detect malicious traffic. They are used in the Internet of Things (IoT) to monitor the network traffic and identify infected IoT devices. Recently, machine learning and deep learning models have been increasingly adopted to enhance detection systems. However, these model-based detectors are vulnerable to adversarial attacks. This paper investigates the vulnerability of these machine learning-based NIDS models in the IoT environment. We propose a practical targeted black-box attack based on Generative Adversarial Networks to generate adversarial DDoS and Mirai traffic that can evade the detector. Experimental results show that the proposed approach deceived the detector to misclassify the attack traffic as benign and achieved a 100% evasion success rate. Also, the proposed approach can be transferred to other models, achieving different levels of effectiveness.