ANTIDOTE: Understanding and Defending against Poisoning of Anomaly Detectors

被引:0
|
作者
Rubinstein, Benjamin I. P. [1 ]
Nelson, Blaine [1 ]
Huang, Ling
Joseph, Anthony D. [1 ]
Lau, Shing-hon [1 ]
Rao, Satish [1 ]
Taft, Nina
Tygar, J. D. [1 ]
机构
[1] Univ Calif Berkeley, Div Comp Sci, Berkeley, CA 94720 USA
来源
IMC'09: PROCEEDINGS OF THE 2009 ACM SIGCOMM INTERNET MEASUREMENT CONFERENCE | 2009年
基金
美国国家科学基金会;
关键词
Network Traffic Analysis; Principal Components Analysis; Adversarial Learning; Robust Statistics;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Statistical machine learning techniques have recently garnered increased popularity as a means to Improve network design and security. For intrusion detection, such methods build a model for normal behavior from training data and detect attacks as deviations from that model. This process invites adversaries to manipulate the training data so that the learned model falls to detect subsequent attacks. We evaluate poisoning techniques and develop a defense, in the context of a particular anomaly detector-namely the PCA-subspace method for detecting anomalies in backbone networks For three poisoning schemes, we show how attackers can substantially increase their chance of successfully evading detection by only adding moderate amounts of poisoned data Moreover such poisoning throws off the balance between false positives and false negatives thereby dramatically reducing the efficacy of the detector. To combat these poisoning activities, we propose an antidote based on techniques from robust statistics and present a new robust PCA-based detector. Poisoning has little effect on the rcbust model, whereas it significantly distorts the model produced by the original PCA method. Our technique substantially reduces the effectiveness of poisoning for a variety of scenarios and indeed maintains a significantly better balance between false positives and false negatives than the original method when under attack.
引用
收藏
页码:1 / 14
页数:14
相关论文
共 50 条
  • [21] SPECIFIC ANTIDOTE FOR PESTICIDE POISONING
    不详
    JOURNAL OF OCCUPATIONAL MEDICINE, 1967, 9 (06): : 318 - 318
  • [22] CLONIDINE POISONING - IS THERE A SINGLE ANTIDOTE
    MOFENSON, HC
    GREENSHER, J
    WEISS, TE
    CLINICAL TOXICOLOGY, 1979, 14 (03): : 271 - 275
  • [24] PARATHION POISONING - A NEW ANTIDOTE
    不详
    CALIFORNIA MEDICINE, 1962, 97 (04): : 245 - &
  • [25] Defending against Poisoning Backdoor Attacks on Federated Meta-learning
    Chen, Chien-Lun
    Babakniya, Sara
    Paolieri, Marco
    Golubchik, Leana
    ACM TRANSACTIONS ON INTELLIGENT SYSTEMS AND TECHNOLOGY, 2022, 13 (05)
  • [26] Defending Hardware-Based Malware Detectors Against Adversarial Attacks
    Kuruvila, Abraham Peedikayil
    Kundu, Shamik
    Basu, Kanad
    IEEE TRANSACTIONS ON COMPUTER-AIDED DESIGN OF INTEGRATED CIRCUITS AND SYSTEMS, 2021, 40 (09) : 1727 - 1739
  • [27] A synthetic porphyrin as an effective dual antidote against carbon monoxide and cyanide poisoning
    Mao, Qiyue
    Zhao, Xuansu
    Kiriyama, Akiko
    Negi, Shigeru
    Fukuda, Yasutaka
    Yoshioka, Hideki
    Kawaguchi, Akira T.
    Motterlini, Roberto
    Foresti, Roberta
    Kitagishi, Hiroaki
    PROCEEDINGS OF THE NATIONAL ACADEMY OF SCIENCES OF THE UNITED STATES OF AMERICA, 2023, 120 (09)
  • [28] The value as an antidote of sodium hyopsulphate and sulphur colloid against cyanogen poisoning.
    Milanesi, E
    ARCHIVES INTERNATIONALES DE PHARMACODYNAMIE ET DE THERAPIE, 1926, 32 : 156 - 172
  • [29] Properties of dihydroasparagusic acid and its use as an antidote against mercury(II) poisoning
    Bianco, Armandodoriano
    Bottari, Emilio
    Festa, Maria Rosa
    Gentile, Lorella
    Serrilli, Anna Maria
    Venditti, Alessandro
    MONATSHEFTE FUR CHEMIE, 2013, 144 (12): : 1767 - 1773
  • [30] ANTICHOLINERGIC POISONING - NEW ANTIDOTE
    MICIK, S
    WESTERN JOURNAL OF MEDICINE, 1976, 124 (01): : 50 - 51