ANTIDOTE: Understanding and Defending against Poisoning of Anomaly Detectors

被引:0
|
作者
Rubinstein, Benjamin I. P. [1 ]
Nelson, Blaine [1 ]
Huang, Ling
Joseph, Anthony D. [1 ]
Lau, Shing-hon [1 ]
Rao, Satish [1 ]
Taft, Nina
Tygar, J. D. [1 ]
机构
[1] Univ Calif Berkeley, Div Comp Sci, Berkeley, CA 94720 USA
基金
美国国家科学基金会;
关键词
Network Traffic Analysis; Principal Components Analysis; Adversarial Learning; Robust Statistics;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Statistical machine learning techniques have recently garnered increased popularity as a means to Improve network design and security. For intrusion detection, such methods build a model for normal behavior from training data and detect attacks as deviations from that model. This process invites adversaries to manipulate the training data so that the learned model falls to detect subsequent attacks. We evaluate poisoning techniques and develop a defense, in the context of a particular anomaly detector-namely the PCA-subspace method for detecting anomalies in backbone networks For three poisoning schemes, we show how attackers can substantially increase their chance of successfully evading detection by only adding moderate amounts of poisoned data Moreover such poisoning throws off the balance between false positives and false negatives thereby dramatically reducing the efficacy of the detector. To combat these poisoning activities, we propose an antidote based on techniques from robust statistics and present a new robust PCA-based detector. Poisoning has little effect on the rcbust model, whereas it significantly distorts the model produced by the original PCA method. Our technique substantially reduces the effectiveness of poisoning for a variety of scenarios and indeed maintains a significantly better balance between false positives and false negatives than the original method when under attack.
引用
收藏
页码:1 / 14
页数:14
相关论文
共 50 条
  • [31] An Antidote for CO Poisoning is on the Horizon
    不详
    CHEMICAL ENGINEERING PROGRESS, 2017, 113 (01) : 11 - 11
  • [32] Repurposing of sevelamer as a novel antidote against aluminum phosphide poisoning: An in vivo evaluation
    Heidari, Reza
    Mohammadi, Hamid Reza
    Goudarzi, Fazel
    Farjadian, Fatemeh
    HELIYON, 2023, 9 (04)
  • [33] Poisoning antidote now approved
    Tollefson, L
    VETERINARY MEDICINE, 1997, 92 (04) : 315 - 315
  • [34] PHYSOSTIGMINE - ANTIDOTE FOR ANTICHOLINERGIC POISONING
    SNYDER, BD
    MINNESOTA MEDICINE, 1975, 58 (06) : 456 - 457
  • [35] ACTIVATED CHARCOALAS AN ANTIDOTE IN POISONING
    CHIN, L
    PICCHION.AL
    DUPLISSE, BR
    FEDERATION PROCEEDINGS, 1967, 26 (02) : 761 - &
  • [36] Apomorphine as an antidote to strychnine poisoning
    Gold, D
    Gold, H
    JOURNAL OF THE AMERICAN MEDICAL ASSOCIATION, 1933, 100 : 1589 - 1590
  • [37] Antidote for carbon monoxide poisoning
    Azarov, Ivan
    Wang, Ling
    Huang, Nancy
    Belanger, Andrea
    Liu, Chen
    O'Donnell, Christopher
    Shiva, Sruti
    Tejero, Jesus
    Kim-Shapiro, Daniel
    Gladwin, Mark
    NITRIC OXIDE-BIOLOGY AND CHEMISTRY, 2014, 42 : 100 - 101
  • [38] Properties of dihydroasparagusic acid and its use as an antidote against mercury(II) poisoning
    Armandodoriano Bianco
    Emilio Bottari
    Maria Rosa Festa
    Lorella Gentile
    Anna Maria Serrilli
    Alessandro Venditti
    Monatshefte für Chemie - Chemical Monthly, 2013, 144 : 1767 - 1773
  • [39] Practical Evaluation of Poisoning Attacks on Online Anomaly Detectors in Industrial Control Systems
    Kravchik, Moshe
    Demetrio, Luca
    Biggio, Battista
    Shabtai, Asaf
    COMPUTERS & SECURITY, 2022, 122
  • [40] LDP-Purifier: Defending against Poisoning Attacks in Local Differential Privacy
    Wang, Leixia
    Yee, Qingqing
    Hu, Haibo
    Meng, Xiaofeng
    Huang, Kai
    DATABASE SYSTEMS FOR ADVANCED APPLICATIONS, DASFAA 2024, PT IV, 2024, 14853 : 221 - 231