错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

RoS-ETA: Defeating Availability Poisoning via the Physical Rate Paradox

  • Chaoqiang Fu,
  • Daofeng Li,
  • Guoxiong Huang,
  • Wanjing Lu

摘要

Network intrusion detection systems are hard to trust when training data may be availability-poisoned and no held-out clean validation set is available. Statistical and data-driven defenses can fall into a density trap because collaboratively injected malicious flows may form high-density clusters that resemble normal feature-space structure. RoS-ETA addresses this problem with a physics-informed robust self-training framework. In this paper, RoS-ETA denotes a robust self-training pipeline built around entropy- and time-aware physical attribution rather than learned representations alone. The physical rate paradox is the core trade-off. In the volumetric threat model studied here, an attacker can keep throughput high and remain physically inconsistent with benign traffic, or slow the flow enough to imitate benign behavior and lose much of the throughput that makes the attack effective. RoS-ETA maps flows into a physical manifold defined by coarse relations between traffic size and duration and by fine-grained randomness in packet behavior. Across heterogeneous benchmarks and a 177-million-packet MAWI backbone snapshot, the framework remains effective in the evaluated volumetric poisoning setting. On CIC-IoT2023 under a 10% poisoning ratio, it reaches an area under the receiver operating characteristic curve, AUC, of 0.9714. In our adaptive evaluation, attackers must reduce effective throughput by 89.90% to evade detection. The method uses linear-time components and keeps prototype inference latency below 50 ms, which makes it suitable for resource-constrained edge nodes.