Adversarial Attack against Intrusion Detectors in Cyber-Physical Systems With Minimal Perturbations
作者:Mingqiang Bai, Puzhuo Liu, Fei Lv, Dong-Liang Fang, Shichao Lv, Weidong Zhang, Limin Sun · 年份:2024 · DOI:10.1109/ispa63168.2024.00109 · 被引用次数:1 · 研究领域:Network Security and Intrusion Detection、Smart Grid Security and Resilience、Cybersecurity and Information Systems
Cyber-Physical Systems (CPS) are crucial for critical infrastructure sectors such as electricity, water, and transportation. Machine Learning (ML) and Deep Learning (DL)-based Intrusion Detection Systems (IDS) are widely used in CPS for security monitoring. Attack and defense confrontation is an eternal topic, leading to increased research on adversarial attacks against IDS. However, most existing research on CPS adversarial attacks focuses on improving evasion capabilities without ensuring the preservation of malicious attack functionality. To address this problem, we propose a Conditional Wasserstein GAN (CWGAN) based framework to generate adversarial examples that can not only evade IDS detection but also impose constraints on the specified target sensors to preserve the original attack functionality. Evaluation results demonstrate that our approach can effectively preserve the intended malicious functionality by significantly reducing the perturbations to specific target sensors. Specifically, we achieve an average reduction of 96.93% and 90.59%, and a maximum reduction of 93.26% and 95.94% compared to the state-of-the-art JSMA and GAN based methods, respectively, while maintaining largely unchanged evasion capabilities against IDS.