🤖 AI Summary
This work addresses the vulnerability of existing IoT intrusion detection systems (IDS) to black-box adversarial attacks under real-world deployment constraints, a challenge often overlooked in prior research. The authors propose a practical black-box adversarial attack method that generates highly stealthy adversarial traffic without access to internal model information, effectively exposing the fragility of mainstream IoT IDS. To counter this threat, they also design a lightweight defense mechanism that significantly enhances system robustness against such attacks. Experimental results demonstrate that the proposed attack achieves high success rates in realistic settings, while the defense effectively identifies the majority of adversarial samples and outperforms existing approaches in both efficacy and efficiency, thereby bridging the critical gap between theoretical security research and practical deployment requirements.
📝 Abstract
The integration of machine learning (ML) algorithms into Internet of Things (IoT) applications has introduced significant advantages alongside vulnerabilities to adversarial attacks, especially within IoT-based intrusion detection systems (IDS). While theoretical adversarial attacks have been extensively studied, practical implementation constraints have often been overlooked. This research addresses this gap by evaluating the feasibility of evasion attacks on IoT network-based IDSs, employing a novel black-box adversarial attack. Our study aims to bridge theoretical vulnerabilities with real-world applicability, enhancing understanding and defense against sophisticated threats in modern IoT ecosystems. Additionally, we propose a defense scheme tailored to mitigate the impact of evasion attacks, thereby reinforcing the resilience of ML-based IDSs. Our findings demonstrate successful evasion attacks against IDSs, underscoring their susceptibility to advanced techniques. In contrast, we proposed a defense mechanism that exhibits robust performance by effectively detecting the majority of adversarial traffic, showcasing promising outcomes compared to current state-of-the-art defenses. By addressing these critical cybersecurity challenges, our research contributes to advancing IoT security and provides insights for developing more resilient IDS.