MARS: Robustness Certification for Deep Network Intrusion Detectors via Multi-Order Adaptive Randomized Smoothing

Mengdie Huang, Yingjun Lin, Xiaofeng Chen, Elisa Bertino · 2024

Network intrusion detectors based on deep learning have high detection accuracy and the ability to adapt to evolving cyber threats. However, a serious drawback is their vulnerability to adversarial example attacks aimed at evading detectors and natural corruptions caused by random noise in the network environment. To provide robustness guarantees for deep neural networks against various perturbations, certified defenses against any possible perturbed inputs in the lp-bounded region are gaining attention. mHowever, unlike existing approaches that focus on homogeneous image feature spaces, the progress on certified defense for the network traffic domain, which is characterized by heterogeneous features, has been very limited. To address such a gap, we propose a novel framework, Multi-order Adaptive Randomized Smoothing (MARS), for certifying the robustness of network intrusion detectors. Experiments on various deep learning-based network intrusion detector architectures show that MARS significantly improves the certification tightness (12.23% average increase in the l2certified radius), evasion attack detection accuracy (7.17% improvement on l∞-PGD, 10.11% improvement on l1-EAD), and natural corruption detection accuracy (16.65% enhancement on latency, 18.23% enhancement on packet loss) compared to BARS, the leading and only certified defense for network intrusion detectors.

Read the paper · More papers on PaperTik