🤖 AI Summary
This study addresses the vulnerability of online intrusion detection models for the Internet of Things (IoT) to black-box evasion attacks, noting that the applicability of existing defense strategies within streaming AutoML environments remains unclear. To tackle this issue, this work proposes an adversarial training framework integrating cost-utility optimization with EDDM drift detection to enhance the robustness of online learning models, including Hoeffding Trees, Leveraging Bagging, and Streaming Random Patches. Experimental results demonstrate that the adversarially trained Leveraging Bagging and Streaming Random Patches models achieve an adversarial accuracy of 0.985 with a marginal precision degradation of only 0.8%. These findings indicate that the proposed approach effectively balances security and classification performance in online AutoML scenarios.
📝 Abstract
As Internet of Things (IoT) networks increasingly depend on machine learning for anomaly, malware, intrusion detection, and network monitoring, such systems have become attractive targets for evasion attacks. Evasion attacks pose a major security risk because an adversary intentionally modifies input data to mislead a trained model into producing incorrect predictions while evading detection. This study evaluates the impact of black-box evasion attacks on a cost-utility-based adversarial training defense strategy in an Online AutoML context for IoT networks. Specifically, evasion attacks were applied to online learners, including Hoeffding Tree (HT), Leveraging Bagging (LB), Streaming Random Patches (SRP), Hoeffding Adaptive Tree (HAT), and Adaptive Random Forest (ARF). By developing naive and adversarially trained (AT) versions of these online learners, we generated clean and adversarial accuracies for each model. The results show that the AT versions of LB and SRP performed best, achieving the highest adversarial accuracy (0.985) and high clean accuracy (0.993) at the highest cost budget of 1.00, with a maximum accuracy reduction of only 0.8%. Finally, drift detection was conducted using the Early Drift Detection Method (EDDM).