Adversarial RL for Port-Scan Evasion: Attacker Feature Visibility in Edge-Deployed IDS

📅 2026-10-05
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the vulnerability of edge machine learning-based intrusion detection systems (IDS) to feedback-driven adaptive port scan evasion. We deploy an IDS on a Raspberry Pi utilizing Zeek and multiple classifiers (XGBoost, MLP, 1D-CNN), while employing Deep Q-Networks (DQN/Double DQN) to simulate adversarial evasion strategies under varying feature visibility conditions. Our findings demonstrate that attackers can achieve effective adaptive evasion with only limited feature knowledge, revealing a non-monotonic relationship between feature visibility and evasion efficacy that challenges conventional defensive assumptions. Experimental results indicate that although standard scans are detected at rates exceeding 91%, DQN-driven attacks attain evasion rates ranging from 61.9% to 98.3%. These findings expose critical vulnerabilities in existing edge IDS models against adaptive adversarial threats.
📝 Abstract
Machine learning-based intrusion detection systems (IDS) are increasingly used in resource-constrained Internet of Things (IoT) environments, yet their robustness is often evaluated against static attacks rather than adversaries that adapt to detection feedback. This paper investigates adaptive port-scan evasion against ML-based IDS models deployed on a Raspberry Pi 3B+. We implement a live Zeek-based IDS pipeline with XGBoost, a multi-layer perceptron, and a 1D convolutional neural network trained on TON_IoT telemetry, and use a Deep Q-Network (DQN) adversary to learn evasive combinations of probe timing, TCP flags, and payload size under black-box, gray-box, and white-box feature-visibility settings. Although the deployed IDS models detect conventional port scans at 91.1--99.8%, DQN final-50-episode evasion rates range from 61.9% to 98.3% across feature-visibility settings. Greater feature visibility does not monotonically improve evasion, and its effect is model-dependent: against XGBoost, the black-box agent achieves 92.9% evasion, compared with 61.9% and 76.9% for gray-box and white-box agents, respectively, whereas 1D-CNN is most vulnerable under white-box access at 98.1%. Because standard DQN can overestimate action values, we additionally spot-check representative conditions using Double DQN. The gray-box condition remains unstable in this check, providing no evidence that overestimation bias alone explains the observed instability. These results show that limited feature knowledge can still enable effective adaptive evasion against static edge-deployed IDS models, motivating more robust defenses for IoT edge environments.
Problem

Research questions and friction points this paper is trying to address.

Adversarial Reinforcement Learning
Port-Scan Evasion
Intrusion Detection System
IoT Edge Security
Feature Visibility
Innovation

Methods, ideas, or system contributions that make the work stand out.

Adversarial Reinforcement Learning
Deep Q-Network
Intrusion Detection System
Port-Scan Evasion
Edge Computing
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
L
Logan Andrew North
Pennsylvania State University
P
Priya Sanjay Kaluskar
Pennsylvania State University
S
Shasi Kumar Ramachandran Prabhu
Pennsylvania State University
Peilong Li
Peilong Li
Elizabethtown College
Suman Saha
Suman Saha
Pennsylvania State University