跳到正文
arXiv:cs.LG· Logan Andrew North, Priya Sanjay Kaluskar, Shasi Kumar Ramachandran Prabhu, Peilong Li, Suman Saha·· 4 小时前AI 评分33

面向端口扫描规避的对抗强化学习:边缘部署 IDS 中的攻击者特征可见性

Adversarial RL for Port-Scan Evasion: Attacker Feature Visibility in Edge-Deployed IDS

AI 导读

研究在 Raspberry Pi 3B+ 部署的基于 ML 的 IDS 上开展自适应端口扫描规避实验,使用 DQN 智能体学习探测时序、TCP 标志与载荷大小的规避组合,覆盖黑盒、灰盒、白盒三种特征可见性设置。

正文

View PDF HTML (experimental)

Abstract:Machine learning-based intrusion detection systems (IDS) are increasingly used in resource-constrained Internet of Things (IoT) environments, yet their robustness is often evaluated against static attacks rather than adversaries that adapt to detection feedback. This paper investigates adaptive port-scan evasion against ML-based IDS models deployed on a Raspberry Pi 3B+. We implement a live Zeek-based IDS pipeline with XGBoost, a multi-layer perceptron, and a 1D convolutional neural network trained on TON_IoT telemetry, and use a Deep Q-Network (DQN) adversary to learn evasive combinations of probe timing, TCP flags, and payload size under black-box, gray-box, and white-box feature-visibility settings. Although the deployed IDS models detect conventional port scans at 91.1--99.8%, DQN final-50-episode evasion rates range from 61.9% to 98.3% across feature-visibility settings. Greater feature visibility does not monotonically improve evasion, and its effect is model-dependent: against XGBoost, the black-box agent achieves 92.9% evasion, compared with 61.9% and 76.9% for gray-box and white-box agents, respectively, whereas 1D-CNN is most vulnerable under white-box access at 98.1%. Because standard DQN can overestimate action values, we additionally spot-check representative conditions using Double DQN. The gray-box condition remains unstable in this check, providing no evidence that overestimation bias alone explains the observed instability. These results show that limited feature knowledge can still enable effective adaptive evasion against static edge-deployed IDS models, motivating more robust defenses for IoT edge environments.
Subjects: Cryptography and Security (cs.CR); Machine Learning (cs.LG)
Cite as: arXiv:2610.08864 [cs.CR]
  (or arXiv:2610.08864v1 [cs.CR] for this version)
  https://doi.org/10.48550/arXiv.2610.08864

arXiv-issued DOI via DataCite (pending registration)

Submission history

From: Suman Saha [view email]
[v1] Mon, 5 Oct 2026 21:48:37 UTC (1,303 KB)

来源:arXiv:cs.LG · arxiv.org