Sophon IDS: Mitigating the Effectiveness of GAN-Based Adversarial Attacks via Tailored Misinformation
摘要
Intrusion Detection System (IDS) plays an essential role in protecting networks from malicious activities. Machine learning (ML) and deep learning (DL) algorithms have been widely adopted to construct IDS and have already shown promising outcomes. However, ML/DL-based IDS has been found to be vulnerable to adversarial attacks, where adversarial traffic is generated to deceive IDS and compromise its performance. One of the most effective adversarial attack methods is IDSGAN, which is built upon generative adversarial network (GAN). In this paper, we propose a novel anti-IDSGAN scheme, Sophon IDS (S-IDS), to protect networks from attacks launched by IDSGAN. Technically, S-IDS transmits deceptive information to IDSGAN-based attackers in order to disrupt their training process. Consequently, the adversarial traffic generated by the attackers is more likely to be detected, ultimately mitigating the effectiveness of adversarial attacks. In detail, the deceptive information is generated by strategically flipping the benign/malicious labels of network flows. In our research, we compared the performance of S-IDS variants based on three different ML/DL algorithms (i.e. LR, MLP, and RNN). Our experimental results indicate that S-IDS successfully increases the detection rate of adversarial traffic. In particular, RNN-based S-IDS outperforms LR-based and MLP-based S-IDS.