ANTIDOTE: Understanding and Defending against Poisoning of Anomaly Detectors

被引:0
|
作者
Rubinstein, Benjamin I. P. [1 ]
Nelson, Blaine [1 ]
Huang, Ling
Joseph, Anthony D. [1 ]
Lau, Shing-hon [1 ]
Rao, Satish [1 ]
Taft, Nina
Tygar, J. D. [1 ]
机构
[1] Univ Calif Berkeley, Div Comp Sci, Berkeley, CA 94720 USA
基金
美国国家科学基金会;
关键词
Network Traffic Analysis; Principal Components Analysis; Adversarial Learning; Robust Statistics;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Statistical machine learning techniques have recently garnered increased popularity as a means to Improve network design and security. For intrusion detection, such methods build a model for normal behavior from training data and detect attacks as deviations from that model. This process invites adversaries to manipulate the training data so that the learned model falls to detect subsequent attacks. We evaluate poisoning techniques and develop a defense, in the context of a particular anomaly detector-namely the PCA-subspace method for detecting anomalies in backbone networks For three poisoning schemes, we show how attackers can substantially increase their chance of successfully evading detection by only adding moderate amounts of poisoned data Moreover such poisoning throws off the balance between false positives and false negatives thereby dramatically reducing the efficacy of the detector. To combat these poisoning activities, we propose an antidote based on techniques from robust statistics and present a new robust PCA-based detector. Poisoning has little effect on the rcbust model, whereas it significantly distorts the model produced by the original PCA method. Our technique substantially reduces the effectiveness of poisoning for a variety of scenarios and indeed maintains a significantly better balance between false positives and false negatives than the original method when under attack.
引用
收藏
页码:1 / 14
页数:14
相关论文
共 50 条
  • [1] Potassium polythionate as an antidote against cyanidric poisoning
    Chistoni, A
    Foresti, B
    ARCHIVES INTERNATIONALES DE PHARMACODYNAMIE ET DE THERAPIE, 1934, 49 : 439 - 444
  • [2] Data Poisoning Attack against Anomaly Detectors in Digital Twin-Based Networks
    Li, Shaofeng
    Wu, Wen
    Meng, Yan
    Li, Jiachun
    Zhu, Haojin
    Shen, Xuemin
    ICC 2023-IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, 2023, : 13 - 18
  • [3] Caramiphen edisylate: An optimal antidote against organophosphate poisoning
    Raveh, Lily
    Eisenkraft, Arik
    Weissman, Ben Avi
    TOXICOLOGY, 2014, 325 : 115 - 124
  • [4] Defending Against Targeted Poisoning Attacks in Federated Learning
    Erbil, Pinar
    Gursoy, M. Emre
    2022 IEEE 4TH INTERNATIONAL CONFERENCE ON TRUST, PRIVACY AND SECURITY IN INTELLIGENT SYSTEMS, AND APPLICATIONS, TPS-ISA, 2022, : 198 - 207
  • [5] CONTRA: Defending Against Poisoning Attacks in Federated Learning
    Awan, Sana
    Luo, Bo
    Li, Fengjun
    COMPUTER SECURITY - ESORICS 2021, PT I, 2021, 12972 : 455 - 475
  • [6] Defending Against SDN Network Topology Poisoning Attacks
    Zheng Z.
    Xu M.
    Li Q.
    Zhang Y.
    Li, Qi (qi.li@sz.tsinghua.edu.cn), 2018, Science Press (55): : 207 - 215
  • [7] Defending Against Poisoning Attacks in Federated Learning with Blockchain
    Dong N.
    Wang Z.
    Sun J.
    Kampffmeyer M.
    Knottenbelt W.
    Xing E.
    IEEE Transactions on Artificial Intelligence, 2024, 5 (07): : 1 - 13
  • [8] Liposome-encapsulated methemoglobin as an antidote against cyanide poisoning
    Suzuki, Yuto
    Taguchi, Kazuaki
    Kure, Tomoko
    Sakai, Hiromi
    Enoki, Yuki
    Otagiri, Masaki
    Matsumoto, Kazuaki
    JOURNAL OF CONTROLLED RELEASE, 2021, 337 : 59 - 70
  • [9] DUBOISIA-MYOPOROIDES - NATIVE ANTIDOTE AGAINST CIGUATERA POISONING
    DUFVA, E
    LOISON, G
    HOLMSTEDT, B
    TOXICON, 1976, 14 (01) : 55 - 64
  • [10] MODE OF ACTION OF DIACETYLMONOXIME (DAM) AS AN ANTIDOTE AGAINST SARIN POISONING
    COHEN, EM
    MOBACH, E
    CHRISTEN, PJ
    BIOCHEMICAL PHARMACOLOGY, 1961, 8 (01) : 120 - &