Online AutoML: Evaluating Poisoning Attacks on Adversarial Training Defense Strategy in IoT Networks

📅 2026-10-05
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the vulnerability of IoT streaming networks to data poisoning attacks, noting that the robustness of existing defense mechanisms in dynamic environments remains unclear. To bridge this gap, this work proposes a defense framework integrating online AutoML with adversarial training, systematically evaluating the resilience of streaming learners—such as Hoeffding trees and random forest variants—against label flipping and noise injection attacks under concept drift scenarios. Experimental results demonstrate that AT-SRP achieves an F1 score of 0.904 under label flipping attacks, while AT-LB attains an F1 score of 0.933 against noise injection attacks. These findings confirm that adversarial training significantly enhances the robustness of streaming models against data poisoning threats in non-stationary IoT environments.
📝 Abstract
Machine learning (ML)-powered poisoning attack vectors are adversarial maneuvers whereby an attacker intentionally inserts, corrupts, or alters training data to distort an ML model's learning process. The objective is to diminish model efficacy, instill biases, induce misclassifications, or include concealed backdoors that may be attacked during implementation. In streaming contexts, poisoning attacks pose significant risks since models perpetually update based on incoming streams of data. An assailant may incrementally introduce harmful samples into this data stream, leading the model to assimilate erroneous features over time without timely identification. Therefore, this study is aimed at evaluating the efficacy of the adversarial training (AT) defense approach against poisoning attacks (label flip and noise injection) using an online AutoML pipeline for Internet of Things (IoT) networks. Specifically, poisoning attacks (label flip and noise injection) were applied to streaming-capable AutoML learners (Hoeffding Tree (HT), Leveraging Bagging (LB), Adaptive Random Forest (ARF), Hoeffding Adaptive Tree (HAT), and Streaming Random Patches (SRP)). Under the strongest poisoning rate (PR = 1.0), AT-SRP achieved the highest F1-score against label flip poisoning (0.904), while AT-LB achieved the highest F1-score against noise-injection poisoning (0.933). Finally, several drift detection methods were used for rolling accuracy and prequential evaluation.
Problem

Research questions and friction points this paper is trying to address.

Poisoning Attacks
Adversarial Training
Online AutoML
IoT Networks
Streaming Data
Innovation

Methods, ideas, or system contributions that make the work stand out.

Online AutoML
Adversarial Training
Poisoning Attacks
IoT Networks
Drift Detection
🔎 Similar Papers
No similar papers found.
C
Chukwunonso Henry Nwokoye
Faculty of Business and Information Technology, Ontario Tech University, Oshawa, Ontario, Canada; Department of Computer Science, Alex Ekwueme Federal University, Nigeria
K
Khalil El-Khatib
Faculty of Business and Information Technology, Ontario Tech University, Oshawa, Ontario, Canada
Li Yang
Li Yang
Assistant Professor, Ontario Tech University | World's Top 2% Scientist | Adjunct Professor, UWO
AI/Machine LearningCybersecurity5G/6G/IoTAutoMLIntrusion Detection