DRL-Aided Trust Evaluation for Malicious Host Detection in Artificial Intelligence of Things
Yu Xia, Ying Liu, Weiting Zhang, Jianhui Yin, Jinju Hu, Tong Liang, Hongke Zhang · IEEE Transactions on Network Science and Engineering · 2025
Artificial Intelligence of Things (AIoT), built upon the AI-empowered Internet of Things, provides powerful perception and decision-making support for smart applications. However, network openness, host diversity, and the high security of the computing center motivate attackers to target links to the computing center due to the low operational cost. The link flooding attack (LFA) is a stealthy attack targeting critical links by aggregating distributed attack traffic to cause congestion, characterized by rolling attack patterns and attack traffic disguised as legitimate. To defend against this threat, this paper proposes a malicious host detection scheme based on dynamic trust management, namedAttSF, to effectively detect malicious hosts and proactively block traffic for long-term defense. First, to address the ineffectiveness of traffic classification due to the similarity between attack and benign traffic, we capture the host's behavior within network events and define multi-dimensional trust evidence, including participation, behavior consistency, and variation, to obtain robust and direct host trust estimation. Second, to adapt to the dynamic participation of malicious hosts caused by the rolling attack pattern, we introduce a sliding window and the historical influence factor to mitigate the effect of intermittently low-participation malicious hosts on trust estimation. Finally, to withstand changing attack patterns, we propose an adaptive trust penalty thresholding approach based on deep reinforcement learning (DRL) to improve malicious host detection while actively enforcing traffic restriction. Simulation results demonstrate thatAttSFhas advantages in malicious host detection accuracy and in reducing false positives in AIoT.