Strategic Games and Zero Shot Attacks on Heavy-Hitter Network Flow Monitoring
Francesco Da Dalt, Adrian Perrig
Abstract
—Heavy–hitter detection underpins line-rate DDoS mitigation and rate-limiting, yet its resilience against adaptive adversaries is largely unexplored. We build an end-to-end evaluation framework that embeds heavy-hitter detection logic in a switch-level simulator, and auto-tunes its parameters using reinforcement learning to rate-limit elephant flows in the network. We subsequently confront the protection system with an adaptive adversary that learns to maximize throughput while evading detection and show that it manages to breach the configured bandwidth cap by up to 299%, exposing systematic blind spots. To harden the monitoring system we apply a form of joint adversarial training: detector and adversary co-evolve and reach an attack-defense Nash equilibrium in which the attacker’s ability to exploit network bandwidth has been reduced by a factor 2.2 × . Lastly, we show that it is possible to use machine learning to create smart packet-synthesizers which are able to perform bandwidth exploits on 8 out of 9 tested systems, without any prior knowledge on the targeted detection system. We refer to this as a zero-shot attack as it does not require knowledge about the targeted heavy-hitter detection system to perform its function. Our open-source framework helps quantify underilluminated attack surfaces and provides a constructive approach towards adversarially robust data-plane flow monitoring.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 1de3d286-c6ce-4f99-ad48-0c22d49b0253Builds on4
- Jaqen: A High-Performance Switch-Native Approach for Detecting and Mitigating Volumetric DDoS Attacks with Programmable SwitchesZaoxing Liu, Hun Namkung, Georgios Nikolaidis, Jeongkeun Lee et al.USENIX Security 2021 · 221 citations
- TorchRL: A data-driven decision-making library for PyTorchAlbert Bou, Matteo Bettini, Sebastian Dittert, Vikash Kumar et al.ICLR 2024 · 77 citations
- Bayesian Sketches for Volume Estimation in Data StreamsFrancesco Da Dalt, Simon Scherrer, Adrian PerrigVLDB 2023 · 5 citations
- Poseidon: Mitigating Volumetric DDoS Attacks with Programmable SwitchesMenghao Zhang, Guanyu Li, Shicheng Wang, Chang Liu et al.NDSS 2020
Related papers
- A Hard-Label Black-Box Evasion Attack against ML-based Malicious Traffic Detection SystemsZixuan Liu, Yi Zhao, Zhuotao Liu, Qi Li et al.NDSS 2026 · 3 citations
- Flash: Query-Efficient Black-Box Static Malware Evasion through Transferable GAN-Guided Modification SequencesAnyuan Sang, Li Yang, Lu Zhou, Junbo Jia et al.FSE 2026
- ADVeRL-ELF: ADVersarial ELF Malware Generation using Reinforcement LearningAkshara Ravi, Vivek Chaturvedi, Muhammad ShafiqueDAC 2025 · 2 citations
- AdvTG: An Adversarial Traffic Generation Framework to Deceive DL-Based Malicious Traffic Detection ModelsPeishuai Sun, Xiaochun Yun, Shuhao Li, Tao Yin et al.WWW 2025 · 5 citations
- Throwing Darts in the Dark? Detecting Bots with Limited Data using Neural Data AugmentationSteve T. K. Jan, Qingying Hao, Tianrui Hu, Jiameng Pu et al.S&P 2020 · 88 citations
