BDpackets: A Clean-label Backdoor Attack on Network Traffic Classifiers via Feature Fusion
Mengxia Zhang, Yixiao Xu, Mohan Li, Yanbin Sun, Meng Han, Zhihong Tian
摘要
Machine learning-based network traffic classification models are vulnerable to backdoor attacks. Recent work demonstrates that packet-level backdoor attacks are feasible even in black-box settings, but their attack success rates remain low under clean-label conditions (e.g., 36.26% on ISCX VPN-nonVPN). Unlike image-based models, simple trigger patterns are ineffective against traffic classifiers because of the unique characteristics of network data. These include variable-length packet sequences, strict protocol compliance, and semantic constraints that limit allowable modifications. Such challenges make it difficult for fixed-pattern triggers to maintain integrity, saliency, and consistency across diverse network environments. Motivated by this insight, we propose BDpackets, a packet-level clean-label backdoor attack that employs a novel feature fusion technique to nonlinearly integrate salient features and generate semantically rich triggers, thereby significantly improving attack effectiveness. Experiments on multiple datasets and model architectures show that BDpackets achieves an attack success rate of 98.91%, outperforming prior backdoor methods by 62.65% and 45.36% in absolute terms. Moreover, BDpackets maintains stealthiness and successfully evades detection by state-of-the-art defenses.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- TrojanFlow: A Neural Backdoor Attack to Deep Learning-based Network Traffic ClassifiersRui Ning, Chunsheng Xin, Hongyi WuINFOCOM 2022 · 被引用 27 次
- Beating Backdoor Attack at Its Own GameMin Liu, Alberto L. Sangiovanni-Vincentelli, Xiangyu YueICCV 2023 · 被引用 19 次
- DEFEAT: Deep Hidden Feature Backdoor Attacks by Imperceptible Perturbation and Latent Representation ConstraintsZhendong Zhao, Xiaojun Chen, Yuexin Xuan, Ye Dong 等CVPR 2022 · 被引用 72 次
- Clean-image Backdoor: Attacking Multi-label Models with Poisoned Labels OnlyKangjie Chen, Xiaoxuan Lou, Guowen Xu, Jiwei Li 等ICLR 2023
- Narcissus: A Practical Clean-Label Backdoor Attack with Limited InformationYi Zeng, Minzhou Pan, Hoang Anh Just, Lingjuan Lyu 等CCS 2023 · 被引用 170 次
