Multi-Stage Adversarial Defense for Online DDoS Attack Detection System in IoT

Yonas Kibret Beshah, Surafel Lemma Abebe, Henock Mulugeta Melaku · IEEE Access · 2025

Machine learning-based Distributed Denial of Service (DDoS) attack detection systems have proven effective in detecting and preventing DDoD attacks in Internet of Things (IoT) systems. However, these DDoS attack-detection models are vulnerable to adversarial attacks. Adversarial attacks are small, crafted adversarial perturbations that are designed to fool machine learning model, leading misclassification of input. The existing defence technique primarily focuses on batch learning-based DDoS attack detection systems, that are not equipped to handle multiple and unknown adversarial attacks in real time. To address this challenge, a novel Multistage Adversarial Attack Defense (MSAAD) framework has been developed to protect online DDoS attack detection systems from adversarial attacks. The framework consists three defense layers: (1) the Resilient Adversarial Detector and Purification (RADP), which detects and purifies adversarial attacks targeting online DDoS attack detection systems against multiple and unknown adversarial attacks. (2) a multiple classifier, that increase complexity for an attacker to replicate the DDoS attack detection model. (3) the Multi-Armed Bandit (MAB) with Thompson Sampling (MLBTSE), which dynamically selects the optimal classifier or ensemble of classifiers for each incoming traffic request. MLBTSE improves detection accuracy and robustness in dynamic IoT environment. The experiment result shows the effectiveness of the proposed MSAAD framework using the IOTID20 and CICIoT2023 datasets. The accuracy of the MLBTSE based DDoS attack detection model improved from a range of 32.38%-60.58% to 99.39%-99.48% for the IOTID20 dataset and from range of 66.60%-86.20% to 99.01%-99.14% for the CICIoT2023 datasets, respectively, in the adversarial attack scenario.

Read the paper · More papers on PaperTik