Adversarial flow generation method based on deep learning intrusion detection system

By modifying malicious traffic in the traffic space and generating adversarial traffic using preset generators and proxy classifiers, the existing adversarial attack technology has been solved, and an efficient and economical adversarial attack effect has been achieved.

CN119945712AActive Publication Date: 2025-05-06DONGGUAN UNIV OF TECH
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202411849998.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-16
Publication Date
2025-05-06
Estimated Expiration
2044-12-16

AI Technical Summary

Technical Problem

Existing adversarial attack technologies are costly to execute in practice and have limited knowledge background. There is a lack of research on adversarial attack methods for deep learning intrusion detection systems, especially in terms of mapping and feature extraction of traffic spaces.

Method used

A method of adversarial traffic generation based on deep learning intrusion detection system is proposed. By modifying malicious traffic in the traffic space, a preset generator and proxy classifier are used to generate adversarial traffic, which improves attack efficiency and reduces costs.

Benefits of technology

It realizes efficient execution of adversarial attacks, reduces attack costs, and simulates black box intrusion detection behavior to help determine whether the generated adversarial traffic is malicious and avoids understanding the parameters or output information of the target intrusion detection model.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945712A_ABST
    Figure CN119945712A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, and discloses a countermeasure traffic generation method based on a deep learning intrusion detection system, which comprises the following steps: acquiring an original network traffic data set; modifying the malicious traffic according to a preset modification rule to obtain modified traffic, and obtaining original confrontation traffic by using a preset generator; determining the gradient loss of a preset generator by using a preset discriminator and a preset proxy classifier according to the normal traffic and the original adversarial traffic; repeating the step of obtaining the original confrontation traffic by using the preset generator according to the modified traffic until the gradient loss of the preset generator converges, and obtaining a trained generator; and obtaining confrontation traffic by using the trained generator according to the modified traffic. The malicious traffic is modified in the traffic space, the execution efficiency of the countermeasure attack is improved, the attack execution cost is reduced, and the countermeasure traffic is generated by utilizing limited knowledge by adding the preset proxy classifier and simulating the behavior of black box intrusion detection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a method for generating adversarial traffic based on a deep learning intrusion detection system. Background Art

[0002] With the rapid development of the Industrial 4.0 era, the application of the Internet of Things in industries such as manufacturing, transportation, electricity and energy has become common. The rapid expansion of industrial IoT infrastructure has significantly improved production efficiency and fault tolerance. However, the rapid expansion of this open network environment has triggered a surge in threats to network infrastructure, such as ransomware to IoT botnets. The changing security landscape of the Industrial Internet of Things requires the development of resilient and powerful network intrusion detection systems to effectively detect potential attack threats. In recent years, intrusion detection systems have been widely used in the security protection of the Industrial Internet of Things. Among them, intrusion detection systems based on machine learning (ML) and deep learning (DL) have shown strong capabilities in traffic feature extraction and intrusion behavior pattern recognition. However, ML / DL models are less robust in the face of adversarial attacks and are easily interfered by malicious attackers, allowing attack data to bypass detection. This adversarial attack not only affects the accuracy of detection, but also directly threatens the security and stability of the Industrial Internet of Things. Adversarial attacks are a type of attack method designed to deceive deep learning models by adding carefully designed small perturbations to the input data, causing the model to misjudge or even completely fail. In order to evaluate the robustness of ML / DL model-based systems, a common method is to construct adversarial attacks to help and test the effectiveness of intrusion detection systems and expose the weaknesses and blind spots of intrusion detection algorithms. Research on adversarial attacks can help network defenders understand future attack trends and help propose new defense strategies and methods earlier.

[0003] When existing adversarial attack technologies are applied in real scenarios, the main problems are high attack execution costs and limited knowledge background. At the same time, there is a lack of research on the mapping of traffic data from feature space to traffic space in the field of intrusion detection and on adversarial attack methods based on deep learning intrusion detection systems in traffic space. Summary of the invention

[0004] In view of this, the present invention provides an adversarial traffic generation method based on a deep learning intrusion detection system to solve the problems of high attack execution cost and limited knowledge background when existing adversarial attack technologies are applied in real scenarios.

[0005] In a first aspect, the present invention provides a method for generating adversarial traffic based on a deep learning intrusion detection system, the method comprising:

[0006] Obtaining an original network traffic data set, which includes normal traffic and malicious traffic;

[0007] Modify malicious traffic according to preset modification rules to obtain modified traffic, and use a preset generator to obtain original adversarial traffic based on the modified traffic;

[0008] According to the normal traffic and the original adversarial traffic, the gradient loss of the preset generator is determined by using the preset discriminator and the preset proxy classifier;

[0009] Repeat the steps of using the preset generator to obtain the original adversarial traffic according to the modified traffic until the gradient loss of the preset generator converges to obtain a trained generator;

[0010] Get random noise and input it into the trained generator to get the perturbation vector. Add the perturbation vector to the modified traffic to get the adversarial traffic.

[0011] The adversarial traffic generation method based on a deep learning intrusion detection system provided by the present invention improves the execution efficiency of adversarial attacks and reduces the attack execution cost by modifying malicious traffic in the traffic space. It helps to determine whether the generated adversarial traffic is malicious by adding a preset proxy classifier and simulating the behavior of black box intrusion detection. It does not need to understand the deep learning model parameters or output information of the target intrusion detection, thereby achieving the generation of adversarial traffic using limited knowledge.

[0012] In an optional implementation manner, modifying malicious traffic according to a preset modification rule to obtain modified traffic includes:

[0013] Copy the data packets of malicious traffic to obtain the traffic to be modified;

[0014] Modify the arrival interval, protocol, and length of the data packets in the traffic to be modified to obtain the modified traffic.

[0015] The adversarial traffic generation method based on the deep learning intrusion detection system provided by the present invention modifies the copied traffic of malicious traffic without destroying the original malicious traffic, thereby ensuring the effectiveness and security of the original malicious traffic, and at the same time ensuring that the modified traffic has malicious functionality and executableness.

[0016] In an optional implementation manner, modifying the arrival interval, protocol, and length of data packets in the to-be-modified traffic to obtain the modified traffic includes:

[0017] Modify the arrival interval of data packets in the traffic to be modified to be no greater than a preset interval threshold;

[0018] Setting the protocol of the data packet in the flow to be modified to the preset protocol;

[0019] Modify the length of the data packet in the traffic to be modified to be no greater than a preset length threshold;

[0020] The traffic to be modified, whose arrival interval of data packets is not greater than a preset interval threshold, whose protocol is a preset protocol, and whose length is not greater than a preset length threshold, is taken as the modified traffic.

[0021] The adversarial traffic generation method based on a deep learning intrusion detection system provided by the present invention generates adversarial traffic by effectively modifying three specific fields, maintains the legitimacy and malicious functionality of the original malicious traffic, affects the feature space by changing the specific attributes of the original malicious traffic data packets, and converts the traffic into a vector containing metadata from the original malicious traffic, which is convenient for subsequent generator processing.

[0022] In an optional implementation, obtaining the original adversarial traffic by using a preset generator according to the modified traffic includes:

[0023] Obtain random noise, and input the random noise into a preset generator to obtain a disturbance vector;

[0024] The disturbance vector is added to the modified traffic, and each field of the data packet in the modified traffic is restored to the corresponding preset field value to obtain the original adversarial traffic.

[0025] The adversarial traffic generation method based on the deep learning intrusion detection system provided by the present invention adds noise disturbance to the input of the generator, so that the original adversarial traffic generated by the generator has higher diversity and creativity, and restores the fields of the data packets in the modified traffic to the corresponding preset field values, ensuring that the adversarial feature vectors of the subsequent original adversarial traffic can be correctly extracted. For deep learning models, by introducing random or specific forms of noise during the training process, the model's resistance to such attacks can be improved.

[0026] In an optional implementation, according to normal traffic and original adversarial traffic, a gradient loss of a preset generator is determined using a preset discriminator and a preset proxy classifier, including:

[0027] Use the preset discriminator combined with normal traffic to determine the true probability of the original adversarial traffic;

[0028] The preset proxy classifier is used to determine the normal probability of the original adversarial traffic, and combined with the true probability to determine the gradient loss of the preset generator.

[0029] The adversarial traffic generation method based on a deep learning intrusion detection system provided by the present invention uses a pre-trained proxy classifier to simulate the behavior of a black-box intrusion detection system, which helps to accurately detect whether the generated adversarial traffic is malicious. The discriminator and the proxy classifier are combined in the feature space to provide gradient loss information for generator training, thereby improving the high escape success rate of the adversarial traffic.

[0030] In an optional implementation, the real probability of the original adversarial traffic is determined by combining the preset discriminator with the normal traffic, including:

[0031] The normal traffic is input into the first feature extractor to extract features to obtain normal features, and the original adversarial traffic is input into the second feature extractor to extract features to obtain adversarial features;

[0032] The adversarial features and normal features are input into the discriminator at the same time to obtain the true probability that the adversarial features are identified as normal features.

[0033] The adversarial traffic generation method based on the deep learning intrusion detection system provided by the present invention utilizes a discriminator to evaluate the authenticity of normal features and the true probability of adversarial features. The identification result of the discriminator is used as a part of the gradient loss of the generator to form an adversarial relationship with the generator, so that the adversarial traffic generated by the auxiliary generator is closer to the normal traffic, thereby improving the accuracy of the adversarial traffic.

[0034] In an optional implementation, a preset proxy classifier is used to determine the normal probability of the original adversarial traffic, and the gradient loss of the preset generator is determined in combination with the true probability, including:

[0035] Input the adversarial features into the preset proxy classifier to obtain the normal probability that the original adversarial traffic is normal traffic;

[0036] Calculate the classification loss of the adversarial feature being identified as normal traffic by the preset proxy classifier based on the normal probability;

[0037] The gradient loss of the preset generator is calculated based on the true probability and classification loss.

[0038] The adversarial traffic generation method based on a deep learning intrusion detection system provided by the present invention comprises a feature extractor that extracts features from normal traffic and carefully crafted malicious traffic, and then inputs the features into a discriminator and a proxy classifier. The discriminator and the proxy classifier distinguish these traffics in the feature space, and obtain the gradient loss of a preset generator. The generator is continuously trained in combination with the gradient loss, so that the generator can generate minimal disturbance to modify the malicious traffic, thereby improving the effectiveness of the generator in generating adversarial traffic.

[0039] In a second aspect, the present invention provides a device for generating adversarial traffic based on a deep learning intrusion detection system, the device comprising:

[0040] The original traffic acquisition module is used to obtain the original network traffic data set, which includes normal traffic and malicious traffic;

[0041] The traffic modification module is used to modify the malicious traffic according to the preset modification rules to obtain the modified traffic, and obtain the original adversarial traffic using the preset generator according to the modified traffic;

[0042] A traffic identification module, used for determining the gradient loss of a preset generator by using a preset discriminator and a preset proxy classifier according to normal traffic and original adversarial traffic;

[0043] A generator training module is used to repeat the steps of obtaining the original adversarial traffic by using a preset generator according to the modified traffic until the gradient loss of the preset generator converges to obtain a trained generator;

[0044] The adversarial traffic generation module is used to obtain random noise and input the random noise into a trained generator to obtain a disturbance vector, and the disturbance vector is added to the modified traffic to obtain the adversarial traffic.

[0045] In a third aspect, the present invention provides a computer device, comprising: a memory and a processor, the memory and the processor being communicatively connected to each other, the memory storing computer instructions, and the processor executing the method of the first aspect or any corresponding embodiment thereof by executing the computer instructions.

[0046] In a fourth aspect, the present invention provides a computer-readable storage medium having computer instructions stored thereon, the computer instructions being used to cause a computer to execute the method of the first aspect or any corresponding embodiment thereof. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] In order to more clearly illustrate the specific implementation methods of the present invention or the technical solutions in the prior art, the drawings required for use in the specific implementation methods or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some implementation methods of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0048] Figure 1 It is a basic structural diagram based on the existing anti-flow attack;

[0049] Figure 2 is a flow chart of a method for generating adversarial traffic based on a deep learning intrusion detection system according to an embodiment of the present invention;

[0050] Figure 3is a structural diagram of basic components for executing a method for generating adversarial traffic based on a deep learning intrusion detection system according to an embodiment of the present invention;

[0051] Figure 4 is a flow chart of another method for generating adversarial traffic based on a deep learning intrusion detection system according to an embodiment of the present invention;

[0052] Figure 5 is a flowchart of a specific embodiment of a method for generating adversarial traffic based on a deep learning intrusion detection system according to an embodiment of the present invention;

[0053] Figure 6 is a structural block diagram of a device for generating adversarial traffic based on a deep learning intrusion detection system according to an embodiment of the present invention;

[0054] Figure 7 It is a schematic diagram of the hardware structure of a computer device according to an embodiment of the present invention. DETAILED DESCRIPTION

[0055] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present invention.

[0056] Adversarial attack methods against ML / DL systems have been well studied in areas such as computer vision, natural language processing, and malware detection. Figure 1 As shown in the figure, it is a basic structural diagram of adversarial traffic attack, in which the attacker is outside the victim's target network and collects the original traffic data set from the target network. The attacker modifies the malicious traffic in the original traffic data set to obtain adversarial traffic. The intrusion detection system detects the adversarial traffic and obtains the detection results. The attacker continuously optimizes his attack model according to the detection results until the attack model converges, and uses the attack model to generate adversarial traffic. After the adversarial traffic is input into the intrusion detection system again, the adversarial traffic can evade intrusion detection and successfully reach the target network, thereby attacking the target network.

[0057] The above methods cannot be directly applied to the network intrusion detection system of the industrial Internet of Things for two reasons: first, unlike non-security fields, attackers cannot ensure that the modified malicious traffic will not break the communication protocol rules in the intrusion detection system. For example, each protocol layer contains a protocol header and length, and the protocol header has a fixed format; second, attackers can only generate adversarial samples in the feature space to deceive the detection model, but it is difficult to map adversarial samples to the traffic space. For example, some statistical features in the industrial Internet of Things (e.g., the average length of the data stream, the number of bytes transmitted per second, etc.) cannot be mapped to the original traffic space. However, in other fields (e.g., computer vision, natural language processing), features can be easily mapped to the original image because features can be formalized as differentiable functions in other fields. Therefore, these generative adversarial attack methods in non-security fields are impractical for intrusion detection systems. Research on adversarial traffic attacks in the industrial Internet of Things environment is becoming increasingly important. It is necessary to understand its attack mechanism to determine the robustness of the ML / DL model-based system to ensure the security of the industrial Internet of Things.

[0058] Practical adversarial attack methods for malicious traffic detection based on ML / DL models mainly include: gray-box attacks and black-box attacks. Gray-box attackers lack detailed knowledge of the target model, such as its structure or parameters, but may need feedback from the model, such as predicted labels or confidence levels. This attack only requires feedback from the target model to modify the traffic. A perfect black-box attack requires that the attacker has no prior knowledge of the target system at all. In other words, the attacker neither knows the target model and its parameters nor needs feedback. It involves generating real traffic to evade ML-based models.

[0059] Related technologies to combat traffic modification include:

[0060] (1) First, input traffic to the target intrusion detection model to detect and obtain traffic labels. Then, train a local proxy model based on the detected traffic and labels. This method adds small perturbations to the spatiotemporal sequence features that can bypass the proxy model and maps the sequence features to adversarial traffic to evade detection. Finally, perform adversarial attacks based on generative adversarial networks to generate adversarial samples to evade detection.

[0061] (2) First, a binary search is performed on each malicious packet sent in the range of 0 to 15 seconds to see if adding a delay can reduce the score of the current packet to below 0.9× the preset threshold. If the score is greater than the preset threshold, an attempt is made to split the packet. This splitting process continuously attempts to convert a large packet into multiple smaller packets so that the scores of all packets are less than the preset threshold until the entire length of the packet is sent and none of them are detected, then the adversarial traffic is successfully crafted.

[0062] (3) Collect traffic on the target network and then modify it. The modification operations include increasing the inter-arrival time of malicious traffic, simulating packet discard, copying some original packets for resending, modifying the maximum transmission unit of the packet, and modifying the transmission order of the packet. The modified traffic is the adversarial traffic.

[0063] (4) First, a long short-term memory neural network is trained to learn benign network traffic behavior by predicting the time differences between benign network packets. The neural network is trained for the specific network connection where the attack will be performed. The trained neural network is then applied to the malicious traffic of the intrusion attack to reshape the inter-packet delay (adjust the timestamp) to make it similar to the delay of benign traffic. Finally, the reshaped malicious traffic is sent to the target network, aiming to bypass the intrusion detection system, which is regarded as a black box.

[0064] There are four main disadvantages of anti-attack technology when applied in real-world scenarios:

[0065] (1) Random or simple traffic / feature space modification: Most existing research methods focus on directly modifying data packets or feature values ​​to escape intrusion detection systems, without deliberately considering changes to specific fields in traffic packets. This may undermine the legitimacy and functionality of the original malicious traffic. Moreover, in DL-based intrusion detection systems, feature extraction is irreversible. This is mainly due to the lack of research on mapping traffic data from feature space to traffic space in the field of intrusion detection.

[0066] (2) Requires white-box / gray-box knowledge: Most evasion attack methods perturb traffic features according to white-box or gray-box settings. In these methods, the attacker has complete knowledge of the target intrusion detection system, including the exploited features, architecture, and parameters of the ML model, as well as feedback from the target model (e.g., predicted labels or confidences). However, in practice, attackers rarely have access to such detailed information due to their limited knowledge background.

[0067] (3) Large attack execution cost: Some existing attack methods do not limit the attacker's overhead or ability to modify traffic, such as obtaining a large amount of target traffic or attacking with high time delay. However, in practice, the attacker must consider the execution cost of the attack and cannot arbitrarily modify traffic fields, increase the size of training traffic, or increase execution complexity.

[0068] (4) Lack of effective research on DL-based intrusion detection systems: Adversarial attacks on ML / DL-based intrusion detection systems in feature space and adversarial attacks on ML-based intrusion detection systems in traffic space have been fully studied. However, research on adversarial attack methods against DL-based intrusion detection systems in traffic space is still insufficient.

[0069] Based on the above problems, an embodiment of the present invention provides an adversarial traffic generation method based on a deep learning intrusion detection system, which modifies malicious traffic in the traffic space and uses a preset proxy classifier to process adversarial features to achieve the effect of improving attack efficiency and generating adversarial traffic using limited knowledge.

[0070] According to an embodiment of the present invention, an embodiment of a method for generating adversarial traffic based on a deep learning intrusion detection system is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in an order different from that shown here.

[0071] In this embodiment, a method for generating adversarial traffic based on a deep learning intrusion detection system is provided, which can be used in the above-mentioned computer system. Figure 2 is a flow chart of a method for generating adversarial traffic based on a deep learning intrusion detection system according to an embodiment of the present invention. Figure 2 As shown, the process includes the following steps:

[0072] Step S101, obtaining an original network traffic data set, where the original network traffic data set includes normal traffic and malicious traffic.

[0073] Specifically, in order to generate adversarial traffic, it is necessary to obtain the original network traffic data set from the target network. The target network has a tool for detecting malicious traffic, which can identify malicious traffic, so the original network traffic data set contains normal traffic and malicious traffic. In order to facilitate numerical operations on structured traffic data, the attacker vectorizes the original traffic in the training set into a meta-information vector containing the original traffic. Since the adversarial traffic generation method based on the deep learning intrusion detection system provided in this embodiment includes a model training process, the original network traffic data set can be divided into a training set and a test set, and it is ensured that the training set and the test set respectively contain normal traffic and malicious traffic at the same time. The training set is used to train the preset generator, and the test set is used to detect the performance of the trained generator.

[0074] Step S102, modify the malicious traffic according to the preset modification rules to obtain the modified traffic, and use the preset generator to obtain the original adversarial traffic based on the modified traffic.

[0075] Specifically, Figure 3As shown, in order to implement the multiple components and connection relationships between the components required for the adversarial traffic generation method based on the deep learning intrusion detection system provided in this embodiment, the components include: a generator, a first feature extractor, a second feature extractor, a discriminator and a proxy classifier. Since the malicious traffic is malicious traffic that can be detected by the existing deep learning intrusion detection system, the purpose of this embodiment is to generate adversarial traffic that is malicious traffic and will not be recognized by the existing deep learning intrusion detection system, so it can be modified on the basis of the existing malicious traffic to ensure the malicious functionality and effectiveness of the malicious traffic. It is necessary to modify according to the preset modification rules to avoid the situation where the generated adversarial traffic is unavailable. In order to make the adversarial traffic as close to normal traffic as possible, it is necessary to train the generator and use the generator and modified traffic to generate the original adversarial traffic.

[0076] Step S103, according to the normal traffic and the original adversarial traffic, the gradient loss of the preset generator is determined using the preset discriminator and the preset proxy classifier.

[0077] Specifically, Figure 3 As shown, normal traffic and original adversarial traffic are respectively input into different feature extractors to obtain normal features and adversarial features, and then the gradient loss of the preset generator is determined based on the normal features and adversarial features using the preset discriminator and the preset proxy classifier. The generator, discriminator and proxy classifier can be deep neural network models of different layers, such as: long short-term memory network, convolutional neural network and recurrent neural network, which are only used as examples, but not limited to this. Take the bidirectional long short word memory model (Bi directional Long Short Term Memory, BiLSTM) as an example for explanation. The 4-layer BiLSTM includes an input layer, a forward transmission layer, a reverse transmission layer and an output layer. The input layer is responsible for sequence encoding of the input data so that the input data meets the input requirements of the network; the forward transmission layer is responsible for extracting the forward features of the input sequence from front to back; the reverse transmission layer is responsible for extracting the reverse features of the input sequence from back to front; the output layer is responsible for integrating the data output by the forward transmission layer and the reverse transmission layer, and the BiLSTM network model is trained based on the data in the merged sample set using the cross entropy loss function to obtain the corresponding generator, discriminator and proxy classifier model.

[0078] Step S104, repeat the step of obtaining the original adversarial traffic by using the preset generator according to the modified traffic, until the gradient loss of the preset generator converges, and a trained generator is obtained.

[0079] Specifically, in this embodiment, the generator is a direct component for generating adversarial traffic, so the training process of the generator is emphasized. The gradient loss calculated by the discriminator and the proxy classifier is fed back to the generator. The generator changes its own parameters according to the feedback gradient loss, and repeats the process of using the preset generator to obtain the original adversarial traffic according to the modified traffic, and determines the gradient loss of the preset generator according to the normal traffic and the original adversarial traffic using the preset discriminator and the preset proxy classifier, until the gradient loss of the preset generator converges, indicating that the performance of the generator has reached the optimal level and a trained generator has been obtained.

[0080] Step S105, obtain random noise, and input the random noise into the trained generator to obtain a disturbance vector, and add the disturbance vector to the modified traffic to obtain the adversarial traffic.

[0081] Specifically, random Gaussian noise is input to the generator trained in step S104, and a disturbance vector is output. The malicious traffic is modified to obtain the modified traffic, and the disturbance vector is added to the modified traffic for calculation, and the result is the adversarial traffic. The malicious traffic here can be obtained based on the malicious traffic in the original network traffic data set, or it can be obtained by using newly collected malicious traffic.

[0082] The adversarial traffic generation method based on the deep learning intrusion detection system provided in this embodiment improves the execution efficiency of the adversarial attack and reduces the attack execution cost by modifying the malicious traffic in the traffic space. It adds a preset proxy classifier to simulate the behavior of black box intrusion detection to help determine whether the generated adversarial traffic is malicious. There is no need to understand the deep learning model parameters or output information of the target intrusion detection, thereby achieving the generation of adversarial traffic using limited knowledge.

[0083] In this embodiment, a method for generating adversarial traffic based on a deep learning intrusion detection system is provided, which can be used in the above-mentioned computer system. Figure 4 is a flow chart of a method for generating adversarial traffic based on a deep learning intrusion detection system according to an embodiment of the present invention. Figure 4 As shown, the process includes the following steps:

[0084] Step S201, obtain the original network traffic data set, which includes normal traffic and malicious traffic. Figure 2 Step S101 of the illustrated embodiment will not be described in detail here.

[0085] Step S202, modify the malicious traffic according to the preset modification rules to obtain the modified traffic, and use the preset generator to obtain the original adversarial traffic based on the modified traffic.

[0086] Specifically, in the above step S202, the malicious traffic is modified according to the preset modification rule to obtain the modified traffic, including:

[0087] Step S2021, copy the data packet of the malicious traffic to obtain the traffic to be modified.

[0088] Specifically, for malicious traffic in the original network traffic data set, it is not modified directly. The data packets of the malicious traffic are first copied as the traffic to be modified to avoid damaging the original malicious traffic.

[0089] Step S2022, modify the arrival interval time, protocol, and length of the data packets in the flow to be modified to obtain the modified flow.

[0090] Specifically, network malicious traffic is modified and vectorized while retaining its legitimacy and maliciousness. The modification of the traffic to be modified includes changing specific attributes of the original data packet to affect the feature space, converting the traffic into a vector containing metadata from the original traffic, and this conversion operation is reversible.

[0091] The adversarial traffic generation method based on the deep learning intrusion detection system provided in this embodiment modifies the copy traffic of the malicious traffic without destroying the original malicious traffic, thereby ensuring the effectiveness and security of the original malicious traffic, and at the same time ensuring that the modified traffic has malicious functionality and executableness.

[0092] In some optional implementations, the above step S2022 includes:

[0093] Modify the arrival interval of data packets in the traffic to be modified to be no greater than a preset interval threshold;

[0094] Setting the protocol of the data packet in the flow to be modified to the preset protocol;

[0095] Modify the length of the data packet in the traffic to be modified to be no greater than a preset length threshold;

[0096] The traffic to be modified, whose arrival interval of data packets is not greater than a preset interval threshold, whose protocol is a preset protocol, and whose length is not greater than a preset length threshold, is taken as the modified traffic.

[0097] Specifically, the modification of data packets in the traffic to be modified mainly includes three aspects:

[0098] First, the arrival interval time of the data packets in the produced traffic is modified, and the modified arrival interval time of the data packets is not greater than the preset interval time threshold. The preset interval time threshold can be the maximum arrival interval time between any two original malicious data packets and normal data packets in the training set. This is only an example, but not limited to this.

[0099] Secondly, the protocol layer of the data packet in the produced traffic is modified, and the modified protocol layer must comply with the established network standards, such as the TCP and UDP protocols of the third layer of the network, which are only used as examples but not limited to this.

[0100] Thirdly, the length of the data packet in the produced traffic is modified, and the length of the modified data packet is not greater than a preset length threshold, and the preset length threshold can be the maximum value allowed by the protocol layer. For example, the maximum TCP data packet size should not exceed the maximum transmission unit of the network in theory, and the unit is set to 1500 bytes, which is only used as an example, but not limited to this.

[0101] The adversarial traffic generation method based on the deep learning intrusion detection system provided in this embodiment generates adversarial traffic by effectively modifying three specific fields, maintaining the legitimacy and malicious functionality of the original malicious traffic, affecting the feature space by changing the specific attributes of the original malicious traffic data packets, and converting the traffic into a vector containing metadata from the original malicious traffic, which is convenient for subsequent generator processing.

[0102] Step S2023, inputting random noise into a preset generator to obtain a disturbance vector.

[0103] Specifically, the random noise can be Gaussian noise, which is input into the generator to generate a perturbation vector containing three attribute meta-information of the data packet's arrival interval, protocol, and data packet length. In order to match the output value range constraint, the sigmoid activation function can be used to limit the values ​​of the three attribute meta-information of the perturbation vector to between 0 and 1.

[0104] Step S2024, adding the disturbance vector to the modified traffic, and restoring each field of the data packet in the modified traffic to the corresponding preset field value to obtain the original adversarial traffic.

[0105] Specifically, the disturbance vector is added to the modified malicious traffic. To ensure that the subsequent feature vector can be correctly extracted, the calculated malicious traffic is restored to the value size of the corresponding field of the data packet according to the minimum and maximum values ​​of each field pre-set in step S2022.

[0106] The adversarial traffic generation method based on the deep learning intrusion detection system provided in this embodiment adds noise disturbance to the input of the generator, so that the original adversarial traffic generated by the generator has higher diversity and creativity, and restores the fields of the data packets in the modified traffic to the corresponding preset field values, ensuring that the adversarial feature vectors of the subsequent original adversarial traffic can be correctly extracted. For deep learning models, by introducing random or specific forms of noise during the training process, the model's resistance to such attacks can be improved.

[0107] Step S203, according to the normal traffic and the original adversarial traffic, the gradient loss of the preset generator is determined using the preset discriminator and the preset proxy classifier.

[0108] Specifically, the above step S203 includes:

[0109] Step S2031, using a preset discriminator in combination with normal traffic to determine the true probability of the original adversarial traffic.

[0110] Specifically, Figure 3 As shown, the normal features of normal traffic and the adversarial features of original adversarial traffic are input into the preset discriminator together to obtain the true probability of the original adversarial traffic.

[0111] Step S2032, using the preset proxy classifier to determine the normal probability of the original adversarial traffic, and combining the true probability to determine the gradient loss of the preset generator.

[0112] Specifically, Figure 3 As shown, the adversarial features of the original adversarial traffic are input into the preset proxy classifier to obtain the normal probability of the original adversarial traffic. The normal probability is combined with the true probability to calculate the gradient loss of the preset generator.

[0113] The adversarial traffic generation method based on the deep learning intrusion detection system provided in this embodiment uses a pre-trained proxy classifier to simulate the behavior of the black-box intrusion detection system, which helps to accurately detect whether the generated adversarial traffic is malicious. The discriminator and the proxy classifier are combined in the feature space to provide gradient loss information for the generator training, thereby improving the high escape success rate of the adversarial traffic.

[0114] In some optional implementations, the above step S2031 includes:

[0115] Step a1: input the normal traffic into the first feature extractor for feature extraction to obtain normal features, and input the original adversarial traffic into the second feature extractor for feature extraction to obtain adversarial features.

[0116] Specifically, Figure 3As shown in the figure, the normal traffic is input into the first feature extractor for feature extraction to obtain the normal features, and the original adversarial traffic is input into the second feature extractor for feature extraction to obtain the adversarial features. It should be noted that the extracted normal features and adversarial features are both spatiotemporal features. The goal of feature extraction is to find information that can discriminate network behavior or attack patterns from the original data, and spatiotemporal features happen to be the most direct and discerning aspects of network traffic. For example, the arrival time interval of data packets, timestamp sequence, traffic burstiness, etc. These features reflect the dynamic behavior of network activities. Moreover, spatiotemporal features can often be well processed by existing machine learning and deep learning models (such as BiLSTM) because these models can capture the correlation between time series and spatial distribution. Other feature types (such as identifiers or field information of specific protocols) are limited in application in network traffic analysis because the proportion of encrypted communications is gradually increasing and content layer information cannot be directly obtained. Therefore, the features extracted here are spatiotemporal features.

[0117] Step a2, input the adversarial feature and the normal feature into the discriminator at the same time, and obtain the true probability that the adversarial feature is identified as a normal feature.

[0118] Specifically, the adversarial features and normal features are simultaneously input into the discriminator to obtain the true probability D(f) of the normal feature being identified as normal traffic, where f represents the normal feature and the true probability D(f) of the adversarial feature being identified as normal traffic. * ), f * Represents adversarial features, and evaluates the authenticity of adversarial traffic based on adversarial true probability. The loss of the discriminator is obtained using the cross entropy loss function based on the normal true probability and the adversarial true probability: The loss L D The discriminator can be trained by minimizing the loss. When the loss converges, a trained discriminator is obtained. The training process of the discriminator can be a mature existing technology and will not be described here.

[0119] The adversarial traffic generation method based on the deep learning intrusion detection system provided in this embodiment uses a discriminator to evaluate the authenticity of normal features and the true probability of adversarial features. The identification result of the discriminator is used as a part of the gradient loss of the generator to form an adversarial relationship with the generator, so as to assist the adversarial traffic generated by the generator to be closer to normal traffic and improve the accuracy of the adversarial traffic.

[0120] In some optional implementations, the above step S2032 includes:

[0121] Step b1, input the adversarial features into the preset proxy classifier to obtain the normal probability that the original adversarial traffic is normal traffic.

[0122] Specifically, the proxy classifier is used as a black-box intrusion detection system to determine the probability that the generated adversarial sample is normal, and the adversarial feature f* Input to the preset proxy classifier to obtain the normal probability P that the adversarial traffic is normal traffic f* =C(f * ).

[0123] Step b2, calculating the classification loss of the adversarial feature being identified as normal traffic by the preset proxy classifier according to the normal probability.

[0124] Specifically, the classification loss can be calculated according to the normal probability. Let CE be represented as the cross entropy function. According to the normal probability P f* To calculate the loss CE (P f* ,y * ). * Indicates the desired target category (normal traffic category) that the adversarial feature is classified into. For example, because the goal of this embodiment is to allow the generated adversarial traffic to be classified as normal traffic by the preset proxy classifier, to prove that the adversarial traffic generated by the preset generator is very similar to normal traffic, thereby helping the generator to train better. In this embodiment, there are only two types of traffic, normal traffic category 0 and malicious traffic category 1 (adversarial traffic also belongs to malicious traffic). Normal probability P f* It is the softmax function against the feature f in the last layer of the preset proxy classifier model * The result calculated is the normal traffic category 0. Among them, the cross entropy loss CE quantifies the predicted normal probability distribution P f* The difference between the actual class distribution (normal traffic class 0 distribution) and the actual class distribution (normal traffic class 0 distribution). * Set to 0, where 0 represents the category of normal traffic. The preset proxy classifier helps the generator to better generate adversarial traffic by determining the possibility that the adversarial feature is adversarial traffic.

[0125] Step b3, calculate the gradient loss of the preset generator based on the true probability and the classification loss.

[0126] Specifically, the adversarial true probability D(f * ) and normal probability P f* The classification loss CE(P f* ,y * ) are added to obtain the gradient loss of the generator, and L2 is used to represent the gradient loss of the generator, that is, L G = -logD(f * )+CE(P f* ,y * ). Minimize L G Function, which makes the gradient loss of generator G converge and completes the training of the generator.

[0127] The loss of the true probability of the adversarial feature and the classification loss of the normal probability are summed to provide the training gradient loss for the generator.

[0128] The adversarial traffic generation method based on the deep learning intrusion detection system provided in this embodiment, the feature extractor extracts features from normal traffic and carefully crafted malicious traffic, and then inputs them into the discriminator and the proxy classifier. The discriminator and the proxy classifier distinguish these traffic in the feature space, and obtain the gradient loss of the preset generator. The generator is continuously trained in combination with the gradient loss, so that the generator can generate minimal disturbance to modify the malicious traffic, thereby improving the effectiveness of the generator in generating adversarial traffic.

[0129] Step S204, repeat the steps of obtaining the original adversarial traffic by using the preset generator according to the modified traffic until the gradient loss of the preset generator converges, and obtains the trained generator. Figure 2 Step S104 of the illustrated embodiment will not be described in detail here.

[0130] Step S205, obtain random noise, and input the random noise into the trained generator to obtain a disturbance vector, and add the disturbance vector to the modified traffic to obtain the adversarial traffic. Figure 2 Step S105 of the illustrated embodiment will not be described in detail here.

[0131] The adversarial traffic generation method based on the deep learning intrusion detection system provided in this embodiment improves the execution efficiency of the adversarial attack and reduces the attack execution cost by modifying the malicious traffic in the traffic space. It adds a preset proxy classifier to simulate the behavior of black box intrusion detection to help determine whether the generated adversarial traffic is malicious. There is no need to understand the deep learning model parameters or output information of the target intrusion detection, thereby achieving the generation of adversarial traffic using limited knowledge.

[0132] In a specific embodiment, the complete process of the adversarial traffic generation method based on the deep learning intrusion detection system is as follows: Figure 5 As shown, the specific steps include:

[0133] (1) Obtain the original traffic data from the target network and divide the original traffic data into a training set and a test set.

[0134] (2) The data in the training set is divided into normal traffic and malicious traffic. The malicious traffic is the traffic that has been detected in the target network. The specific detection method can be a mature existing technology and will not be described here.

[0135] (3) Obtain random noise and add the random noise to the generator for training. Use the generator and malicious traffic to generate original adversarial traffic, input it into the second feature extractor, and obtain adversarial features.

[0136] (4) The normal traffic is input into the first feature extractor to obtain the normal feature, and the true probability of the normal feature and the true probability of the adversarial feature are generated by the discriminator according to the normal feature and the adversarial feature.

[0137] (5) The adversarial features are input into the proxy classifier for detection to obtain the normal probability of the adversarial features.

[0138] (6) Obtain the gradient loss of the generator based on the true probability and the normal probability, and determine whether the training of the generator has converged based on the gradient loss. If the training of the generator has not converged, return to the step of modifying the malicious traffic and continue training until the training of the generator converges. Use the test set to test the trained generator. After feature extraction, input it into the target intrusion detection system based on deep learning to obtain the detection result. Observe whether the malicious traffic in the test set is mistaken for normal traffic by the target intrusion detection system based on deep learning after the generator generates adversarial traffic.

[0139] In this embodiment, a device for generating adversarial traffic based on a deep learning intrusion detection system is also provided, which is used to implement the above-mentioned embodiments and preferred implementation modes, and the descriptions that have been made will not be repeated. As used below, the term "module" can implement a combination of software and / or hardware for a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, the implementation of hardware, or a combination of software and hardware, is also possible and conceivable.

[0140] This embodiment provides a device for generating adversarial traffic based on a deep learning intrusion detection system. Figure 6 As shown, including:

[0141] The original traffic acquisition module 601 is used to acquire an original network traffic data set, which includes normal traffic and malicious traffic.

[0142] The traffic modification module 602 is used to modify the malicious traffic according to the preset modification rules to obtain the modified traffic, and obtain the original adversarial traffic using the preset generator according to the modified traffic.

[0143] The traffic identification module 603 is used to determine the gradient loss of the preset generator by using the preset identifier and the preset proxy classifier according to the normal traffic and the original adversarial traffic.

[0144] The generator training module 604 is used to repeat the step of obtaining the original adversarial traffic using the preset generator according to the modified traffic until the gradient loss of the preset generator converges to obtain a trained generator.

[0145] The adversarial traffic generation module 605 is used to obtain random noise and input the random noise into a trained generator to obtain a disturbance vector. The disturbance vector is added to the modified traffic to obtain the adversarial traffic.

[0146] In some optional implementations, the traffic modification module 602 includes:

[0147] The traffic replication unit is used to replicate data packets of malicious traffic to obtain traffic to be modified.

[0148] The traffic modification unit is used to modify the arrival interval time, protocol and length of the data packets in the traffic to be modified to obtain the modified traffic.

[0149] The noise adding unit is used to input random noise into the preset generator to obtain a disturbance vector.

[0150] The adversarial traffic generation unit is used to add the disturbance vector to the modified traffic and restore each field of the data packet in the modified traffic to the corresponding preset field value to obtain the original adversarial traffic.

[0151] In some optional implementations, the traffic identification module 603 includes:

[0152] The true probability determination unit is used to determine the true probability of the original adversarial traffic by combining the normal traffic with the preset discriminator.

[0153] The gradient loss calculation unit is used to determine the normal probability of the original adversarial traffic using the preset proxy classifier, and determine the gradient loss of the preset generator in combination with the true probability.

[0154] In some optional implementations, the true probability determination unit includes:

[0155] The feature extraction subunit is used to input the normal traffic into the first feature extractor for feature extraction to obtain the normal feature, and input the original adversarial traffic into the second feature extractor for feature extraction to obtain the adversarial feature.

[0156] The adversarial feature identification subunit is used to input the adversarial feature and the normal feature into the discriminator at the same time to obtain the true probability that the adversarial feature is identified as a normal feature.

[0157] In some optional embodiments, the gradient loss calculation unit includes:

[0158] The normal probability determination subunit is used to input the adversarial feature into the preset proxy classifier to obtain the normal probability that the original adversarial traffic is normal traffic.

[0159] The classification loss calculation subunit is used to calculate the classification loss of the adversarial feature being identified as normal traffic by the preset proxy classifier based on the normal probability.

[0160] The gradient loss determination subunit is used to calculate the gradient loss of the preset generator based on the true probability and the classification loss.

[0161] The further functional description of each of the above modules and units is the same as that of the above corresponding embodiments and will not be repeated here.

[0162] The adversarial traffic generation device of the deep learning intrusion detection system in this embodiment is presented in the form of a functional unit, where the unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and memory that executes one or more software or fixed programs, and / or other devices that can provide the above functions.

[0163] The embodiment of the present invention also provides a computer device having the above Figure 6 The adversarial traffic generation device of the deep learning intrusion detection system shown.

[0164] See also Figure 7 , Figure 7 is a schematic diagram of the structure of a computer device provided by an optional embodiment of the present invention, such as Figure 7 As shown, the computer device includes: one or more processors 10, a memory 20, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. Various components are connected to each other using different buses for communication, and can be installed on a common mainboard or installed in other ways as needed. The processor can process the instructions executed in the computer device, including instructions stored in or on the memory to display the graphical information of the GUI on an external input / output device (such as, a display device coupled to the interface). In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple memories. Similarly, multiple computer devices can be connected, and each device provides some necessary operations (for example, as a server array, a group of blade servers, or a multi-processor system). Figure 7 A processor 10 is taken as an example.

[0165] The processor 10 may be a central processing unit, a network processor or a combination thereof. The processor 10 may further include a hardware chip. The hardware chip may be a dedicated integrated circuit, a programmable logic device or a combination thereof. The programmable logic device may be a complex programmable logic device, a field programmable gate array, a general purpose array logic or any combination thereof.

[0166] The memory 20 stores instructions executable by at least one processor 10, so that the at least one processor 10 executes the method shown in the above embodiment.

[0167] The memory 20 may include a program storage area and a data storage area, wherein the program storage area may store an operating system, an application required for at least one function; the data storage area may store data created according to the use of the computer device, etc. In addition, the memory 20 may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some optional embodiments, the memory 20 may optionally include a memory remotely arranged relative to the processor 10, and these remote memories may be connected to the computer device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0168] The memory 20 may include a volatile memory, such as a random access memory; the memory may also include a non-volatile memory, such as a flash memory, a hard disk or a solid state drive; the memory 20 may also include a combination of the above types of memory.

[0169] The computer device further comprises a communication interface 30 for the computer device to communicate with other devices or a communication network.

[0170] The embodiment of the present invention also provides a computer-readable storage medium. The method according to the embodiment of the present invention can be implemented in hardware, firmware, or can be implemented as a computer code that can be recorded in a storage medium, or can be implemented as a computer code that is originally stored in a remote storage medium or a non-temporary machine-readable storage medium and will be stored in a local storage medium through a network download, so that the method described herein can be stored in such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only storage memory, a random access memory, a flash memory, a hard disk or a solid-state hard disk, etc.; further, the storage medium can also include a combination of the above types of memories. It can be understood that a computer, a processor, a microprocessor controller, or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by a computer, a processor, or hardware, the method shown in the above embodiment is implemented.

[0171] Although the embodiments of the present invention have been described in conjunction with the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present invention, and such modifications and variations are all within the scope defined by the appended claims.

Claims

1. A method for generating adversarial traffic based on a deep learning intrusion detection system, characterized in that: The method comprises: Acquire an original network traffic data set, wherein the original network traffic data set includes normal traffic and malicious traffic; Modify the malicious traffic according to a preset modification rule to obtain modified traffic, and obtain the original adversarial traffic using a preset generator according to the modified traffic; Determine the gradient loss of a preset generator using a preset discriminator and a preset proxy classifier according to the normal traffic and the original adversarial traffic; Repeat the step of inputting the modified flow into the preset generator to obtain the original adversarial flow until the gradient loss of the preset generator converges to obtain a trained generator; Random noise is obtained and input into a trained generator to obtain a disturbance vector, and the disturbance vector is added to the modified traffic to obtain the adversarial traffic.

2. The method according to claim 1, characterized in that: Modifying the malicious traffic according to a preset modification rule to obtain modified traffic includes: Copying the data packet of the malicious traffic to obtain the traffic to be modified; Modify the arrival interval time, protocol, and length of the data packets in the to-be-modified traffic to obtain the modified traffic.

3. The method according to claim 2, characterized in that Modifying the arrival interval, protocol, and length of data packets in the to-be-modified traffic to obtain the modified traffic, including: Modify the arrival interval of the data packets in the to-be-modified flow to be no greater than a preset interval threshold; Setting the protocol of the data packet in the flow to be modified to the preset protocol; Modify the length of the data packet in the to-be-modified traffic to be no greater than a preset length threshold; The traffic to be modified, whose arrival interval of data packets is not greater than a preset interval threshold, whose protocol is a preset protocol, and whose length is not greater than a preset length threshold, is taken as the modified traffic.

4. The method according to claim 1, characterized in that The original adversarial traffic is obtained by using a preset generator according to the modified traffic, including: Obtaining random noise, and inputting the random noise into a preset generator to obtain a disturbance vector; The disturbance vector is added to the modified traffic, and each field of the data packet in the modified traffic is restored to the corresponding preset field value to obtain the original adversarial traffic.

5. The method according to claim 1, characterized in that According to the normal traffic and the original adversarial traffic, a gradient loss of a preset generator is determined using a preset discriminator and a preset proxy classifier, including: Determine the true probability of the original adversarial traffic by combining the preset discriminator with the normal traffic; The normal probability of the original adversarial traffic is determined using a preset proxy classifier, and the gradient loss of the preset generator is determined in combination with the true probability.

6. The method according to claim 5, characterized in that Determining the true probability of the original adversarial traffic by combining the preset discriminator with the normal traffic includes: Input the normal traffic into the first feature extractor to extract features to obtain normal features, and input the original adversarial traffic into the second feature extractor to extract features to obtain adversarial features; The adversarial feature and the normal feature are simultaneously input into the discriminator to obtain the true probability that the adversarial feature is identified as a normal feature.

7. The method according to claim 6, characterized in that Determining the normal probability of the original adversarial traffic by using a preset proxy classifier, and determining the gradient loss of the preset generator in combination with the true probability, including: Inputting the adversarial feature into the preset proxy classifier to obtain a normal probability that the original adversarial traffic is normal traffic; Calculate the classification loss of the adversarial feature being identified as normal traffic by a preset proxy classifier according to the normal probability; The gradient loss of the preset generator is calculated based on the true probability and the classification loss.

8. A device for generating adversarial traffic based on a deep learning intrusion detection system, characterized in that: The device comprises: The original traffic acquisition module is used to acquire an original network traffic data set, wherein the original network traffic data set includes normal traffic and malicious traffic; A traffic modification module, used to modify the malicious traffic according to a preset modification rule to obtain modified traffic, and input the modified traffic into a preset generator to obtain original adversarial traffic; A traffic identification module, used to determine the gradient loss of a preset generator using a preset identifier and a preset proxy classifier according to the normal traffic and the original adversarial traffic; A generator training module, used for repeatedly inputting the modified flow into a preset generator to obtain the original adversarial flow, until the gradient loss of the preset generator converges, thereby obtaining a trained generator; The adversarial traffic generation module is used to obtain random noise and input the random noise into a trained generator to obtain a disturbance vector, and the disturbance vector is added to the modified traffic to obtain the adversarial traffic.

9. A computer device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the method according to any one of claims 1 to 7 by executing the computer instructions.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Automatic generation method for adversarial samples against malicious codes based on generative adversarial network

    CN113158190A

  • Attack resisting system for deep intrusion detection

    CN113392932A

  • Malicious traffic avoidance detection method based on generative adversarial network

    CN116707992A

  • Network intrusion detection system-oriented antagonistic traffic generation method and network intrusion detection system-oriented antagonistic traffic generation system

    CN117220953A

  • Anti-attack sample generation method

    CN118337526A