ANTIDOTE: Understanding and Defending against Poisoning of Anomaly Detectors

被引:0
|
作者
Rubinstein, Benjamin I. P. [1 ]
Nelson, Blaine [1 ]
Huang, Ling
Joseph, Anthony D. [1 ]
Lau, Shing-hon [1 ]
Rao, Satish [1 ]
Taft, Nina
Tygar, J. D. [1 ]
机构
[1] Univ Calif Berkeley, Div Comp Sci, Berkeley, CA 94720 USA
来源
IMC'09: PROCEEDINGS OF THE 2009 ACM SIGCOMM INTERNET MEASUREMENT CONFERENCE | 2009年
基金
美国国家科学基金会;
关键词
Network Traffic Analysis; Principal Components Analysis; Adversarial Learning; Robust Statistics;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Statistical machine learning techniques have recently garnered increased popularity as a means to Improve network design and security. For intrusion detection, such methods build a model for normal behavior from training data and detect attacks as deviations from that model. This process invites adversaries to manipulate the training data so that the learned model falls to detect subsequent attacks. We evaluate poisoning techniques and develop a defense, in the context of a particular anomaly detector-namely the PCA-subspace method for detecting anomalies in backbone networks For three poisoning schemes, we show how attackers can substantially increase their chance of successfully evading detection by only adding moderate amounts of poisoned data Moreover such poisoning throws off the balance between false positives and false negatives thereby dramatically reducing the efficacy of the detector. To combat these poisoning activities, we propose an antidote based on techniques from robust statistics and present a new robust PCA-based detector. Poisoning has little effect on the rcbust model, whereas it significantly distorts the model produced by the original PCA method. Our technique substantially reduces the effectiveness of poisoning for a variety of scenarios and indeed maintains a significantly better balance between false positives and false negatives than the original method when under attack.
引用
收藏
页码:1 / 14
页数:14
相关论文
共 50 条
  • [11] Enhancing the Antidote: Improved Pointwise Certifications against Poisoning Attacks
    Liu, Shijie
    Cullen, Andrew C.
    Montague, Paul
    Erfani, Sarah M.
    Rubinstein, Benjamin I. P.
    THIRTY-SEVENTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, VOL 37 NO 7, 2023, : 8861 - 8869
  • [12] Liposome-encapsulated methemoglobin as an antidote against cyanide poisoning
    Suzuki, Yuto
    Taguchi, Kazuaki
    Kure, Tomoko
    Sakai, Hiromi
    Enoki, Yuki
    Otagiri, Masaki
    Matsumoto, Kazuaki
    Journal of Controlled Release, 2021, 337 : 59 - 70
  • [13] ANTIDOTE FOR CYANIDE POISONING
    不详
    BMJ-BRITISH MEDICAL JOURNAL, 1963, (536): : 803 - +
  • [14] Defending Support Vector Machines Against Data Poisoning Attacks
    Weerasinghe, Sandamal
    Alpcan, Tansu
    Erfani, Sarah M.
    Leckie, Christopher
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2021, 16 : 2566 - 2578
  • [15] DPFLA: Defending Private Federated Learning Against Poisoning Attacks
    Feng, Xia
    Cheng, Wenhao
    Cao, Chunjie
    Wang, Liangmin
    Sheng, Victor S.
    IEEE TRANSACTIONS ON SERVICES COMPUTING, 2024, 17 (04) : 1480 - 1491
  • [16] MONOACETINE . PHARMACOCHEMISTRY AND PHARMACOLOGY OF A SPECIFIC ANTIDOTE AGAINST POISONING BY FLUOROCARBON COMPOUNDS
    BERNASCONI, R
    PHARMACEUTICA ACTA HELVETIAE, 1969, 44 (03): : 149 - +
  • [17] Synthetic Amphoteric Cryogels as an Antidote against Acute Heavy Metal Poisoning
    Baimenov, Alzhan Z.
    Fakhradiyev, Ildar R.
    Berillo, Dmitriy A.
    Saliev, Timur
    Mikhalovsky, Sergey V.
    Nurgozhin, Talgat S.
    Inglezakis, Vassilis J.
    MOLECULES, 2021, 26 (24):
  • [18] AUROR: Defending Against Poisoning Attacks in Collaborative Deep Learning Systems
    Shen, Shiqi
    Tople, Shruti
    Saxena, Prateek
    32ND ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE (ACSAC 2016), 2016, : 508 - 519
  • [19] Antidote for Carbon Monoxide Poisoning
    Azarov, Ivan
    Wang, Ling
    McTiernan, Charlie
    Belanger, Andrea
    Zhi, Chin
    Rose, Jason
    Liu, Chen
    Huang, Nancy
    Ragireddy, Prafulla
    Shiva, Sruti
    Tejero, Jesus
    Kim-Shapiro, Daniel
    Gladwin, Mark
    FREE RADICAL BIOLOGY AND MEDICINE, 2014, 76 : S78 - S78
  • [20] ANTIDOTE TO POISONING WITH BARIUM SALTS
    不详
    JAMA-JOURNAL OF THE AMERICAN MEDICAL ASSOCIATION, 1954, 156 (06): : 669 - 669