Knowledge Distillation for Improved Resilience in Network Intrusion Detection Systems

Truc-Ngan Vo Dinh, Nam-Phuong Hoai Nguyen, Anh-Duy Tran, Kim-Hung Le · 2024

The essential role of Internet in providing daily crucial services and resources has led to an increased risk of cyberattacks. Machine learning based-network intrusion detection system (NIDS) are increasingly popular as a potential solution for enhancing security. However, these systems remain vulnerable to adversarial attacks that can evade detection and disrupt the network operations. Preventing such attacks is highly challenging due to its variation and complexity. In this paper, we first evaluate the impact of recent adversarial attacks on NIDS and then propose a defense strategy using knowledge distillation (KD) to construct a lightweight and robust NIDS. Our experimental results demonstrate that the KD-trained model significantly improves robustness and efficiency in mitigating accuracy drops compared to traditional training methods, with performance gains of up to 26.18% on the CIC-DDoS2019 dataset and 9.18% on the IoTID20 dataset under poisoning attacks. Moreover, our KD-trained models maintain high accuracy, with the best accuracy being 94.46% on the CIC-DDoS2019 dataset and 93.41% on the IoTID20 dataset, demonstrating that our approach enhances robustness without sacrificing detection performance.

Read the paper · More papers on PaperTik