网络流量对抗样本行为意图建模防御方法研究

Behavior Intent Modeling of Network Traffic Adversarial Examples for Defense

  • 摘要: 对抗样本是目前针对深度 学习模型的主要攻击方法之一,具有对抗样本防御能力的模型会影响正常样本的预测性能甚至有较大性能衰减,其实际应用困难. 输入预处理方法在去除对抗扰动时缺乏语义约束,易改变数据包速率等关键分类特征,严重影响网络入侵检测中正常样本分类性能;基于阈值比较的方法提供的一维分割边界无法区分特征值近似的样本,防御效果大幅降低. 此方法利用Kolmogorov-Arnold网络(KAN)推理行为意图语义,结合扩散过程与条件自编码器,在语义指导下去除对抗扰动保留关键分类特征,以提升防御性能并保持正常样本分类效果. 多个真实数据集实验表明,该方法在不影响模型原有预测性能的条件下准确率提升13%以上,能有效抵御主要对抗样本攻击,实用价值大.

     

    Abstract: Adversarial example is one of the main attack methods against deep learning models, and models with adversarial defense capabilities suffer from degraded prediction performance on normal samples or even significant accuracy drops, making practical deployment challenging. Input preprocessing methods, while removing adversarial perturbations, lack semantic constraints and tend to alter key classification features (e.g., packet rates), impairing the classification performance of normal samples in network intrusion detection. Threshold-based methods, which rely on one-dimensional separation boundaries, cannot distinguish samples with similar feature values, substantially reducing defense effectiveness. This method employs Kolmogorov-Arnold Networks (KAN) to infer semantic representations of behavioral intent and integrates a diffusion process with a conditional autoencoder to selectively remove adversarial perturbations while preserving key discriminative features under semantic guidance. Experiments on multiple real-world datasets show that the method achieves an accuracy increase of over 13% without affecting the model’s original prediction performance, effectively defends against major adversarial attacks and offers substantial practical value.

     

/

返回文章
返回
Baidu
map