HO CHI MINH NATIONAL UNIVERSITY UNIVERSITY OF INFORMATION TECHNOLOGY DEPARTMENT OF COMPUTER SCIENCE GRADUATION THESIS REPORT Enhancing robustness against adversarial attacks in machine learning-based intrusion detection system using multiple mutated classifiers Tăng cường kha năng phát hiện các cuộc tan công đối kháng trong hệ thống phát hiện xâm nhập mạng dựa trên học máy sử dụng đa mô hình đột biến BACHELOR OF COMPUTER SCIENCE INSTRUCTORS: PhD. Phạm Văn Hậu MSc. Phan Thế Duy Ho Chỉ Minh city, 2023 HO CHI MINH NATIONAL UNIVERSITY UNIVERSITY OF INFORMATION TECHNOLOGY DEPARTMENT OF COMPUTER SCIENCE GRADUATION THESIS REPORT Enhancing robustness against adversarial attacks in machine learning-based intrusion detection system using multiple mutated classifiers Tăng cường kha năng phát hiện các cuộc tấn công đối khang trong hệ thống phát hiện xâm nhập mạng dựa trên học máy sử dụng đa mô hình đột biến BACHELOR OF COMPUTER SCIENCE INSTRUCTORS: PhD. Phạm Văn Hậu MSc.
Phan Thế Duy Ho Chỉ Minh city, 2023 ASSESSMENT COMMITTEE by Rector of the University of Information Technology. Sa - Member ĐẠI HỌC QUOC GIA TP. HO CHÍMINH CỘNG HÒA XÃ HỘI CHỦ NGHĨA VIỆT NAM TRƯỜNG ĐẠI HỌC Độc Lập - Tự Do - Hạnh Phúc CÔNG NGHỆ THÔNG TIN re TP. NHAN XET KHOA LUAN TOT NGHIEP (CUA CAN BO HUONG DAN) Tên khóa luận: TANG CƯỜNG KHẢ NĂNG PHAT HIEN CÁC CUỘC TAN CÔNG DOI KHÁNG TRONG HỆ THÓNG PHÁT HIỆN XÂM NHẬP MẠNG DỰA TRÊN HỌC MÁY SỬ DỤNG DA MO HÌNH DOT BIEN Nhóm SV thực hiện: Cán bô hướng dẫn: Đoàn Ngọc Như Quỳnh 20520732 TS.
Phạm Văn Hậu Cao Thế Thuận 20520793 ThS. Phan Thế Duy Đánh gia Khóa luận 1. Vé cuôn báo cáo: Số trang - Số chương So bảng sô liệu So hình vẽ Sô tài liệu tham khảo Sản phâm Một sô nhận xét vê hình thức cuôn báo cáo: 3. Về chương trình ứng dụng: Người nhận xét (Ký tên và ghi rõ họ tên) ĐẠI HỌC QUOC GIA TP.
HO CHÍMINH CỘNG HÒA XÃ HỘI CHỦ NGHĨA VIỆT NAM TRƯỜNG ĐẠI HỌC Độc Lập - Tự Do - Hạnh Phúc CÔNG NGHỆ THÔNG TIN re TP. NHAN XET KHOA LUAN TOT NGHIEP (CUA CAN BO PHAN BIEN) Tên khóa luận: TANG CƯỜNG KHẢ NĂNG PHAT HIEN CÁC CUỘC TAN CÔNG DOI KHÁNG TRONG HỆ THÓNG PHÁT HIỆN XÂM NHẬP MẠNG DỰA TRÊN HỌC MÁY SỬ DỤNG DA MO HÌNH DOT BIEN Nhóm SV thực hiên: Cán bô phản biên: Đoàn Ngọc Như Quỳnh 20520732. Cao Thế Thuận 20520793 Đánh gia Khóa luận 1. Vé cuôn báo cáo: Số trang - Số chương So bảng sô liệu So hình vẽ Sô tài liệu tham khảo Sản phâm Một sô nhận xét vê hình thức cuôn báo cáo: 3.
Về chương trình ứng dụng: Người nhận xét (Ký tên và ghi rõ họ tên) vì ACKNOWLEDGEMENTS We sincerely express our heartfelt gratitude to our supervisors, PhD. Pham Van Hau and MSc. Phan Thé Duy, for their guidance, support, and encour- agement throughout our research. Their extensive knowledge, experience, and feedback have been invaluable in the successful completion of this thesis.
We also extend our deepest appreciation to Mr. Doan Minh Trung, a re- searcher at UIT Information Security Laboratory, for his exceptional guidance, valuable feedback, and insightful recommendations that have tremendously as- sisted us in identifying appropriate pathways. Finally, we would like to convey our deepest gratitude to our families for their unwavering love, support, and encouragement, without which this thesis would not have been possible. Doan Ngoc Nhu Quynh Cao Thé Thuan Vil TABLE OF CONTENTS ACKNOWLEDGEMENTS.
vi TABLE OF CONTENTS. vii LIST OF SYMBOLS, ABBREVIATIONS. xi LIST OF. xiii LIST OF TABLES.3 Scientific ẤY' gm ym eee tTee bì 1.5 Objectives, Subject, and Scope of the Study.4 The structure of thesis.FOUNDATION & RELATED WORK 10 2.1 Overview of Evasion Attacks .3 Generative Adversarial Networks (GAN).1 Introduction to GAN .2 Structure of GAN model.4 Intrusion Detection System (IDS).2 Operational methodology of IDS .9 Machine learning algorithms .3 Multi-Layer Perceptron (MLP).4 Extreme Gradient Boosting (XGBoost) .5 Convolutional Neural Network(CNN).6 Gated Recurrent Unit (GRU).7 Linear Discriminant Analysis .8 Extra Trees số `.
= i i iG iw i“ iw ww.1 Overview of Multimodal. Overview of Ensemble Learning. Mechanics of Ensemble Learning .8 Synthetic Minority Oversampling Technique (SMOTE) .1 Overview of SMOTE .9 Related Research Studies.1 Ensemble Learning with Adversarial Training (ELAT) .2 Multimodal Attention-based Deep Learning for Alzheimer’s Disease Diagnosis (MaDDi) .3 Generating Adversarial Malware Examples for Black-Box Attacks Based on GAN .4 Increasing the Performance of Machine Learning-Based IDSs on an Imbalanced and Up-to-Date Dataset .5 A novel adversarial example detection method for mali- cious PDFs using multiple mutated classifiers.2 GAN-based Model Target Attacks.1 Multiple Mutated Classifiers .2 Multimodal with Adversarial Training .4 Architecture & Operation of the Proposed Model.1 Multiple Mutated Classifiers .2 Multimodal Aversarial Training (MAT) Architecture .EXPERIMENTS AND EVALUATION 65 4.3 Adversarial data generation .1 Scenarios 1: Comparison between MMCs and Baseline mod- els, with and without adversarial retraining, against GAN’s Attacks.2 Scenarios 2: Comparison between Multimodal Models, MATs, and Baseline Models, before and after undergone adversar- ial retraining, against GAN’s Attacks.3 Scenarios 3: Comparison between Multimodal Methods, MAT, and Ensemble Learning, before and after adversarial retraining, against GANsattacks.4 Discussing experimental results .1 Hypotheses: Why Infiltration is harder to detect than other classes of malicious data. ca 105 REFERENCES 105 Xl LIST OF SYMBOLS, ABBREVIATIONS D_ loss loss value of Discriminator G_ loss loss value of Generator TDR True Detection Rate EIR Error Increase Rate DR Detection Rate O-DR Ordinary Detection Rate A-DR Adversarial Detection Rate Acc-DR Ordinary Accuracy Acc-DR Adversarial Accuracy Al Artificial Intelligent ML Machine Learning DL Deep Learning NLP Natural language processing CV Computer Vision IDS Intrusion Detection System HIDS Host Intrusion Detection Systems NIDS Network Intrusion Detection Systems loT Internet of Things HoT Industrial Internet of Things DoS Denial of Service MLP Multi-layer Perceptron ET Extra Tree XGB Extreme Gradient Boosting RF Random Forest xI LDA Linear Discriminant Analysis RNN Recurrent Neural Network CNN Convolutional Neural Network DT Decision Tree BCE Binary Cross-Entropy SMOTE Synthetic Minority Oversampling Technique ELAT Ensemble learning adversarial training GAN Generative Adversarial Network GAN-RNN GAN with RNN as the target model MAT Multimodal Adversarial Training MAT-RNN MAT using adversarial samples targeting RNN xiii LIST OF FIGURES Figure 2.1 Diagram of blackbox attack.2 Diagram of the model evasion attack.3 The block diagram of a classical GAN model .4 The Intrusion Detection and Prevention System (IDPS) model.
ng gà kg va 17 Figure 2.5 Basic diagram of decision free.6 Random Forest algorithm intuilon.7 Multilayer perceptron (MLP) architecture with two hidden layers and two prediction output.9 Convolutional Neural Network (CNN) architecture.10 The architecture of GRU.11 A general multimodal workflow .12 Ensemble Learning Method .13 Using SMOTE to oversample .15 Illustrates the relationship between the issues on the left and solutions on the right side in the design.17 The architecture of MalGAN .18 Flowchart of the IDSs with sampled data .19 The overall design of the malicious PDFs detection system 50 Figure 3.2 GAN’s attacks on Multimodal.3 Multimodal Adversarial Training Architecture .1 Generated data efect.1 Accuracies comparision between Multimodals, MATs, and baseline models against GAN’s adversarial samples.4 Accuracy comparision between Multimodals, MATs, and adversarial retrained baseline models against GAN’s adversarial samples 2. Quà g gà kg va 88 Figure 4.5 Comparative of Defense Model against GAN Attacks .6 Malicious data distribution of test dataset. 98 XV LIST OF TABLES Table 4.1 Data distribution of CIC-IDS-2018 dataset before prepro- CeSSNG 6. CSE-CIC-IDS2018 label mapping.
68 Table 43 CSE-CIC-IDS2018 after preprocessing .4 CICIDS2018 functional feature groups .5 CICIDS2018 functional features.7 Baseline models hyperparameter values .10 Comparison of Accuracy between Multiple Mutated DTs and a Simple DT Model, Pre and Post Adversarial Retraining, Using Different Target Models’ Adversarial Samples .11 Comparison of Accuracy between Multiple Mutated RFs and a Simple RF Model, Pre and Post Adversarial Retraining, Using Different Target Models’ Adversarial Samples .12 Comparison of Accuracy between Multiple Mutated ETs and a Simple ET Model, Pre and Post Adversarial Retraining, Using Different Target Models’ Adversarial Samples .13 Comparison of Accuracy between XGBs and a Simple XGB Model, Pre and Post Adversarial Retraining, Using Different Tar- get Models’ Adversarial Samples.14 Comparison of Accuracy between Multiple Mutated MLPs and a Simple MLP Model, Pre and Post Adversarial Retraining, Using Different Target Models’ Adversarial Samples .15 Accuracies comparision between Multimodals, MATs, and baseline models against GAN’s adversarial samples.16 Effectiveness of GAN generated DoS attack against several ML and DL models .17 Effectiveness of GAN generated Brute Force attack against several ML and DL models.18 Effectiveness of GAN generated Bot attack against several ML and DL models .19 Effectiveness of GAN generated Infiltration attack against several ML and DL models.20 Effectiveness of GAN generated SQL Injection attack against several ML and DL models.21 Accuracy comparision between Multimodals, MATs, and adversarial retrained baseline models against GAN adversarial samples.22 Robustness comparison between adversarial retrained Ma- chine Learning Models, Multimodal, and MATs against GAN’s Adversarial Examples.23 Effectiveness of GAN generated DoS attacks against Mul- timodals, MATs, and several Adversarial retrained ML and DL models.24 Effectiveness of GAN generated Bot attacks against Mul- timodals, MATs, and several Adversarial retrained ML and DL xvii Table 4.25 Effectiveness of GAN generated Brute Force attacks against Multimodals, MATs, and several Adversarial retrained ML and DL models .26 Effectiveness of GAN generated Infiltration attacks against Multimodals, MATs, and several Adversarial retrained ML and DL models .27 Effectiveness of GAN generated SQL Injection attacks against Multimodals, MATs, and several Adversarial retrained ML and DL models .28 Accuracy comparison between Ensemble models, Multi- modals, MATs, and AT baseline models against adversarial data crafted on different target models. The baselines row represent the accuracies of adversarial retrained models relative to GAN’s target models ay .29 Accuracy comparison between Adversarial retrained ensem- ble models, Multimodals, MATs, and Adversarial retrained base- line models against adversarial data crafted on different target models. The baselines row represent the accuracies of adversarial retrained models relative to GAN’s target models. 96 ABSTRACTION In the field of cybersecurity, researchers have made significant efforts to im- prove the detection and classification of attack traffic in Intrusion Detection Systems (IDS).
However, current IDS models based on machine learning (ML) and deep learning (DL) face several critical challenges. One of these challenges is the ability to detect evasive attack traffic hidden within normal network traffic. This issue often arises due to the scarcity and imbalance of training data for the models. It has been demonstrated that the accuracy of ML or DL-based IDS models heavily relies on the quantity and quality of the training data.
This poses a significant barrier to achieving effective detection and classification perfor- mance in real-world systems. Therefore, there is a need to explore new methods to enhance the detection and classification capabilities of ML and DL models in order to improve the detection of evasive attack traffic in practical scenarios and address this concerning issue in society. In this thesis, we conducted experiments using various defense methods, in- cluding machine learning and deep learning models, to evaluate their effective- ness in addressing the challenges of imbalanced data and sophisticated attack patterns generated by GANs. We also explored the widely employed Adversarial Training technique, which enables the models to learn attack patterns with sub- tle perturbations that are difficult to discern, thereby enhancing their detection capability against malicious traffic.
One approach we implemented was MMC, Multiple Mutated Classifier. In this approach, instead of using a single set of hyperparameters for the model, you randomize or mutate the hyperparameters to create multiple variations of the model. The aim was to introduce diversity in the training process, allowing the models to capture different aspects of the data and improve overall detection and classification performance. Another approach we investigated is the Multimodal architecture, which in- corporates multiple sources of information during the classification and detection process.