2021/04/23 by Sensen Guo, Jinxiong Zhao, Xiaoyu Li +3 · 1 citation
Computer Science · #Adversarial Robustness in Machine Learning #Network Security and Intrusion Detection #Advanced Malware Detection Techniques #Computer science #Adversarial machine learning #Adversarial system #Machine learning #Artificial intelligence #Anomaly detection #Black box #Attack model #Deep learning #Computer security
paper · pdf · doi:10.1155/2021/5578335
openalex publication_date 2021/04/23 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/29
In recent years, machine learning has made tremendous progress in the fields of computer vision, natural language processing, and cybersecurity; however, we cannot ignore that machine learning models are vulnerable to adversarial examples, with some minor malicious input modifications, while appearing unmodified to human observers, the outputs of machine learning-based model can be misled easily. Likewise, attackers can bypass machine-learning-based security defenses model to attack systems in real time by generating adversarial examples. In this paper, we propose a black-box attack method against machine-learning-based anomaly network flow detection algorithms. Our attack strategy consists in training another model to substitute for the target machine learning model. Based on the overall understanding of the substitute model and the migration of the adversarial examples, we use the substitute model to craft adversarial examples. The experiment has shown that our method can attack the target model effectively. We attack several kinds of network flow detection models, which are based on different kinds of machine learning methods, and we find that the adversarial examples crafted by our method can bypass the detection of the target model with high probability.