MODELING ATTACKS AGAINST MACHINE LEARNING COMPONENTS OF INTRUSION DETECTION SYSTEMS
Igor Vitalievich Kotenko, Egor Ichetovkin · Informatization and communication · 2025
The objective of the study is to develop models of adversarial attacks against machine learning components of intrusion detection systems, such as the Fast Gradient Sign Method and Boiling frog attacks. The research methods consist of modeling the attack impacts in Python. For poisoning attacks, malicious traffic is mixed into the training data. Evasion attacks are modeled by adding noise. The F-measure, Precision, and Recall metrics were used for assessment of effectiveness of the detection models under attacks. The experiments were conducted on three different intrusion detection systems based on different classification models: random forest, multilayer perceptron, deep machine learning, and operant vector machine learning. As a result of the study, evasion and poisoning attacks against machine learning components were modeled. As a result of the modeling, low stability of all studied classifier models to adversarial attacks was revealed. Further research will be devoted to studying methods of protection against attacks of these classes.