Evaluating the Robustness of DL-Based AAD in SDN-IoT Networks Against OOD Data and Poisoning Attacks Using Autoencoders
摘要
Integrating Software-Defined Networking (SDN) with the Internet of Things (IoT) creates highly dynamic and programmable infrastructures, introducing new security risks. To secure these environments, Deep Learning (DL)-based Autonomous Anomaly Detection (AAD) systems are increasingly adopted due to their ability to learn complex traffic patterns without manual intervention. However, these DL-based AAD systems face significant challenges, particularly from adversarial threats and Out-of-Distribution (OOD) data. Data-level adversarial attacks, such as poisoning, can corrupt the training process, while OOD data introduces unfamiliar traffic patterns that interfere with accurate anomaly detection. In this work, we evaluate the robustness of three DL-based AAD models-Autoencoders (AE), Variational Autoencoders (VAE), and Denoising Autoencoders (DAE)-under OOD and poisoning attack scenarios in SDN-IoT networks. We generate two sets of OOD data to simulate OOD conditions using a novel reverse diffusion-based method and a Conditional Tabular GAN (CTGAN), each introducing unique deviations from in-distribution traffic. Poisoning attacks are carried out using the Adversarial Robustness Toolbox (ART). Our evaluation spans three popular datasets: CICIDS2017, InSDN, and CICIoT2023. Experimental results show that while all models are affected by adversarial conditions, DAEs demonstrate greater resilience, maintaining higher detection accuracy and lower performance degradation across scenarios. These findings provide actionable insights for deploying DL-based AAD systems in real-world SDN-IoT networks, where adaptability and robustness are essential for maintaining security in the face of evolving threats.