MANDA: On Adversarial Example Detection for Network Intrusion Detection System
Ning Wang, Yimin Chen, Yang Hu, Wenjing Lou, Y. Thomas Hou
Abstract
With the rapid advancement in machine learning (ML), ML-based Intrusion Detection Systems (IDSs) are widely deployed to protect networks from various attacks. Yet one of the biggest challenges is that ML-based IDSs suffer from adversarial example (AE) attacks. By applying small perturbations (e.g. slightly increasing packet inter-arrival time) to the intrusion traffic, an AE attack can flip the prediction of a well-trained IDS. We address this challenge by proposing MANDA, a MANifold and Decision boundary-based AE detection system. Through analyzing AE attacks, we notice that 1) an AE tends to be close to its original manifold (i.e., the cluster of samples in its original class) regardless which class it is misclassified into; and 2) AEs tend to be close to the decision boundary so as to minimize the perturbation scale. Based on the two observations, we design MANDA for accurate AE detection by exploiting inconsistency between manifold evaluation and IDS model inference and evaluating model uncertainty on small perturbations. We evaluate MANDA on NSL-KDD under three state-of-the-art AE attacks. Our experimental results show that MANDA achieves as high as 98.41% true-positive rate with 5% false-positive rate and can be applied to other problem spaces such as image recognition.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3e443ef1-8368-4aee-93d8-545223b98b5fCited by top-tier papers3
- FeCo: Boosting Intrusion Detection Capability in IoT Networks via Contrastive LearningNing Wang, Yimin Chen, Yang Hu, Wenjing Lou et al.INFOCOM 2022 · 36 citations
- Federated PCA on Grassmann Manifold for Anomaly Detection in IoT NetworksTung-Anh Nguyen, Jiayu He, Long Tan Le, Wei Bao et al.INFOCOM 2023 · 19 citations
- A Hard-Label Black-Box Evasion Attack against ML-based Malicious Traffic Detection SystemsZixuan Liu, Yi Zhao, Zhuotao Liu, Qi Li et al.NDSS 2026 · 3 citations
Builds on2
Related papers
- Adaptive Clustering-based Malicious Traffic Classification at the Network EdgeAlec F. Diallo, Paul PatrasINFOCOM 2021 · 64 citations
- Detecting Adversarial Examples from Sensitivity Inconsistency of Spatial-Transform DomainJinyu Tian, Jiantao Zhou, Yuanman Li, Jia DuanAAAI 2021 · 72 citations
- On the Need for Topology-Aware Generative Models for Manifold-Based DefensesUyeong Jang, Susmit Jha, Somesh JhaICLR 2020 · 15 citations
- CADE: Detecting and Explaining Concept Drift Samples for Security ApplicationsLimin Yang, Wenbo Guo, Qingying Hao, Arridhana Ciptadi et al.USENIX Security 2021 · 241 citations
- Multi-Expert Adversarial Attack Detection in Person Re-identification Using Context InconsistencyXueping Wang, Shasha Li, Min Liu, Yaonan Wang et al.ICCV 2021 · 34 citations
