Overview
This study investigates the robustness of machine learning-based intrusion detection systems (IDS) deployed in resource-constrained Internet of Things (IoT) environments against adaptive adversaries. Specifically, the research focuses on the evasion of port-scan attacks. The work uses a Deep Q-Network (DQN) adversary to learn evasive attack strategies against live IDS models under varying levels of attacker feature visibility.
Research Context
Machine learning-based IDS are increasingly implemented in IoT environments characterized by resource constraints. However, their efficacy is often assessed against static attack patterns rather than dynamic adversaries capable of adapting to detection feedback. This approach can lead to an overestimation of security performance. The research addresses this gap by examining how adaptive attackers can circumvent ML-based IDS models.
Approach
The study implemented a live Zeek-based IDS pipeline on a Raspberry Pi 3B+ device. Three distinct machine learning models were used for intrusion detection: XGBoost, a multi-layer perceptron (MLP), and a 1D convolutional neural network (1D-CNN). These models were trained using telemetry data from the TON_IoT dataset.
To simulate an adaptive adversary, a Deep Q-Network (DQN) agent was employed. This DQN adversary was designed to learn evasive combinations of attack parameters, including probe timing, TCP flags, and payload size. The learning process occurred under three distinct feature-visibility settings for the attacker:
- Black-box: The attacker has no knowledge of the IDS model's internal workings or features.
- Gray-box: The attacker has partial knowledge, typically of some features or outputs.
- White-box: The attacker has full knowledge of the IDS model and its features.
In addition to the standard DQN, representative conditions were spot-checked using a Double DQN. This was done to address the potential for standard DQN to overestimate action values.
Findings
The deployed IDS models demonstrated detection rates of 91.1% to 99.8% against conventional (non-adaptive) port scans. However, when faced with the adaptive DQN adversary, evasion rates increased substantially across various feature-visibility settings.
- DQN final-50-episode evasion rates ranged from 61.9% to 98.3% across all feature-visibility conditions.
- Greater feature visibility for the attacker did not monotonically lead to improved evasion.
- The effect of feature visibility was dependent on the specific IDS model being attacked:
- Against the XGBoost model, the black-box agent achieved a 92.9% evasion rate. In contrast, gray-box and white-box agents achieved 61.9% and 76.9% evasion rates, respectively.
- Against the 1D-CNN model, the attacker was most vulnerable when operating under white-box access, achieving a 98.1% evasion rate.
- A spot-check using Double DQN did not provide evidence that overestimation bias alone explained the observed instability in the gray-box condition. The gray-box condition remained unstable in this check.
Why This Matters
These findings indicate that even with limited knowledge of the target system, adaptive adversaries can develop highly effective evasion strategies against static, edge-deployed IDS models. This highlights a need for the development of more robust defense mechanisms tailored for IoT edge environments, where resource constraints are common.