Poisoning the Well: Adversarial Poisoning on ML-Based Software-Defined Network Intrusion Detection Systems

Tapadhir Das, Raj Mani Shukla, Shamik Sengupta · IEEE Transactions on Network Science and Engineering · 2024

With the usage of Machine Learning (ML) algorithms in modern-day Network Intrusion Detection Systems (NIDS), contemporary network communications are efficiently protected from cyber threats. However, these ML algorithms are starting to be compromised by adversarial attacks that ambush the ML pipeline. This paper demonstrates the feasibility of an adversarial attack called the Cosine Similarity Label Manipulation (CSLM) which is geared toward compromising training labels for ML-based NIDS. The paper develops two versions of CSLM attacks: Minimum CSLM (Min-CSLM) and Maximum CSLM (Max-CSLM). We demonstrate the attacks' efficacy towards single and multi-controller Software-defined Network (SDN) setups. Results indicate that the proposed attacks provide substantial deterioration of classifier performance in single SDNs, specifically, those that utilize Random Forests (RF), which deteriorate$\approx$50% under Min-CSLM attacks, and Support Vector Machines (SVM), which undergo$\approx$60% deterioration from a Max-CSLM attack. We also note that RF, SVM, and Multi-layer Perceptron (MLP) classifiers are also extensively vulnerable to these attacks in Multi-controller SDN setups (MSDN) as they incur the most observed utility deterioration. MLP-based uniform MSDNs incur the most deterioration under both proposed CSLM attacks with$\approx$28% decrease in performance, while SVM and RF-based variable MSDNs incur the most deterioration under both CSLM attacks with$\approx$30% and$\approx$35% decrease in performance, respectively.

Read the paper · More papers on PaperTik