System and method for backdoor injection to assess machine learning based network intrusion detection systems
The PCAP-Backdoor technique addresses vulnerabilities in IDS by injecting backdoor triggers into raw network packets, enabling effective misclassification in IDS models without access to the feature extractor, showcasing robustness in real-world IoT and CPS networks.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- UNIV OF PITTSBURGH OF THE COMMONWEALTH SYST OF HIGHER EDUCATION
- Filing Date
- 2025-12-02
- Publication Date
- 2026-07-23
AI Technical Summary
Deep learning-based intrusion detection systems (IDS) are vulnerable to backdoor attacks, where attackers inject triggers that cause misclassifications in network traffic, posing significant security risks to IoT and CPS networks, and existing methods for injecting backdoors into IDS models are limited by the need for access to the feature extractor.
The PCAP-Backdoor technique modifies raw network packets to introduce backdoor triggers directly into Packet Capture (PCAP) datasets, allowing attackers to manipulate packet streams without access to the feature extractor, using a bi-directional algorithm to craft trigger packets that blend with legitimate traffic and evade detection by packet capture tools.
The technique demonstrates successful backdoor attacks with as little as 1% poisoned data, causing IDS models to misclassify when the trigger is present, even with activation-based clustering detection methods, and is effective in real-world CPS and IoT environments.
Smart Images

Figure US2025057636_23072026_PF_FP_ABST
Abstract
Description
[0001] 072396.1116
[0002] SYSTEM AND METHOD FOR BACKDOOR INJECTION TO ASSESS MACHINE LEARNING BASED NETWORK INTRUSION DETECTION SYSTEMS
[0003] CROSS-REFERENCE TO RELATED APPLICATIONS
[0004] This application claims the benefit of priority of U.S. Provisional Patent Application No. 63 / 745,134, filed January 14, 2025, the content of which is incorporated herein by reference in its entirety, and to which priority is claimed.
[0005] TECHNICAL FIELD
[0006] This disclosure generally relates to network security.
[0007] STATEMENT REGARDING FEDERALLY-SPONSORED RESEARCH This invention was made with government support under DE-CR0000041 awarded by the Department of Energy. The government has certain rights in the invention.
[0008] BACKGROUND
[0009] The rapid growth of the Internet of Things (loT) and cyber-physical system (CPS) has resulted in an exponential increase in the number of connected devices and data traffic. These interconnected environments, which integrate physical processes with computational control, have become prime targets for various network attacks. Deep learning techniques have emerged as effective tools for designing data-driven intrusion detection systems (IDS) capable of detecting and mitigating these cyber-attacks. These IDSs are particularly useful for identifying anomalous packet flows and activating preventive actions. However, these deep learning-based models are vulnerable to backdoor attacks, which allow attackers to compromise the model’s behavior by injecting triggers that cause misclassifications of network traffic, posing significant risks to loT and CPS security.
[0010] SUMMARY OF CERTAIN NON-LIMITING EMBODIMENTS The purpose and advantages of the disclosed subject matter will be set forth in and apparent from the description that follows, as well as will be learned by practice of the disclosed subject matter. Additional advantages of the disclosed subject matter will be realized and attained by the methods and systems particularly pointed out in the written description and claims hereof, as well as from the appended drawings.
[0011] 1
[0012] ACTIVE 126368586.1072396.1116
[0013] To achieve these and other advantages, and in accordance with the purpose of the disclosed subject matter, as embodied and broadly described, the disclosed subject matter presents systems, methods, and apparatuses that can be used to determine vulnerabilities of IDS models. For example, certain non-limiting embodiments can be used to inject backdoor trigger packets to network traffic and evaluate whether an IDS model is vulnerable to such backdoored packets.
[0014] In certain non-limiting embodiments, one or more computing systems can access a plurality of network packets. The computing systems can then generate a plurality of backdoored packets by modifying statistics associated with the network packets. The computing systems can then execute a model configured for intrusion detection systems to classify the backdoored packets. The computing systems can then determine a misclassification accuracy associated with the classifying of the backdoored packets. The computing systems can further determine whether the model is vulnerable based on the misclassification accuracy.
[0015] In certain non-limiting embodiments, one or more computer-readable non-transitory storage media embodying software is operable when executed to access a plurality of network packets. The computer-readable non-transitory storage media embodying software is further operable when executed to generate a plurality of backdoored packets by modifying statistics associated with the network packets. The computer-readable non-transitory storage media embodying software is further operable when executed to execute a model configured for intrusion detection systems to classify the backdoored packets. The computer-readable non-transitory storage media embodying software is further operable when executed to determine a misclassification accuracy associated with the classifying of the backdoored packets. The computer-readable non-transitory storage media embodying software is further operable when executed to determine whether the model is vulnerable based on the misclassification accuracy.
[0016] In certain non-limiting embodiments, a system can comprise one or more processors and a non-transitory memory coupled to the processors comprising instructions executable by the processors. The processors are operable when executing the instructions to access a plurality of network packets. The processors are further operable when executing the instructions to generate a plurality of backdoored packets by modifying statistics associated with the network packets. The processors are further operable when executing the instructions to execute a model configured for intrusion detection systems to classify the backdoored packets. The processors are further operable when executing the instructions to determine a misclassification accuracy associated with the classifying of the backdoored packets. The
[0017] 2
[0018] ACTIVE 126368586.1072396.1116
[0019] processors are further operable when executing the instructions to determine whether the model is vulnerable based on the misclassification accuracy.
[0020] Furthermore, the disclosed embodiments of the methods, computer readable non-transitory storage media, and systems can have further non-limiting features as described below.
[0021] In certain non-limiting embodiments, the computing systems can further access a user configuration. The computing systems can then train the model based on the user configuration using the backdoored packets.
[0022] In certain non-limiting embodiments, the computing systems can further determine the model is vulnerable based on the misclassification accuracy exceeding a threshold.
[0023] In certain non-limiting embodiments, the computing systems can store, in a database, the user configuration associated with an indication that the model is vulnerable with respect to the user configuration.
[0024] In certain non-limiting embodiments, generating the plurality of backdoored packets can include adding one or more backdoor trigger packets.
[0025] In certain non-limiting embodiments, the computing systems can further identify one or more benign network packets from the plurality of network packets. The computing systems can then add the one or more backdoor trigger packets to the one or more benign network packets.
[0026] In one feature, the plurality of network packets are transmitted from a source device to a destination device. Accordingly, generating the plurality of backdoored packets can be based on a unidirectional transmission from the source device to the destination device.
[0027] In one feature, the plurality of network packets are transmitted in both directions between a source device and a destination device. Accordingly, generating the plurality of backdoored packets can be based on a bidirectional transmission between the source device and the destination device.
[0028] In one feature, modifying the statistics associated with the network packets is based on an algorithm. The algorithm can be associated with one or more control parameters comprising one or more of: a control parameter controlling a number of backdoor trigger packets to be added to the network packets, a control parameter specifying a delay between any two adjacent backdoor trigger packets, or a control parameter specifying a proportion of network packets to be backdoored.
[0029] 3
[0030] ACTIVE 126368586.1072396.1116
[0031] In certain non-limiting embodiments, the computing systems can further extract one or more parameter values corresponding to the user configuration. The computing systems can then determine whether to inject backdoor trigger packets based on the parameter values.
[0032] In certain non-limiting embodiments, the computing systems can further analyze the network packets to determine statistics associated with the network packets. The computing systems can then determine, based on the statistics, one or more modifications for modifying the network packets.
[0033] In certain non-limiting embodiments, the network packets can include one or more of an Internet-of-Things (IoT) data packet, a cyber-physical system (CPS) data packet, or a transmission control protocol (TCP) data packet.
[0034] It is to be understood that both the foregoing general description and the following detailed description are exemplary and are intended to provide further explanation of the disclosed subject matter claimed. These and other features, aspects, and advantages of the disclosure will be apparent from a reading of the following detailed description together with the accompanying drawings, which are briefly described below. The invention includes any combination of two, three, four, or more of the above-noted embodiments as well as combinations of any two, three, four, or more features or elements set forth in this disclosure, regardless of whether such features or elements are expressly combined in a specific embodiment description herein. This disclosure is intended to be read holistically such that any separable features or elements of the disclosed invention, in any of its various aspects and embodiments, should be viewed as intended to be combinable unless the context clearly dictates otherwise.
[0035] BRIEF DESCRIPTION OF THE DRAWINGS FIG. 1 A illustrates example clean label backdoor attacks on network packets of an IDS using prior work.
[0036] FIG. IB illustrates example clean label backdoor attacks on network packets of an IDS using the embodiments disclosed herein.
[0037] FIGS. 2A-2B illustrate an example backdoor attack wherein the attacker poisons the training dataset by linking a trigger with the image.
[0038] FIG. 3 illustrates example TCP ACKed unseen segment and TCP ports reused error using a strawman approach.
[0039] FIG. 4A illustrates an example architecture of PCAP-Backdoor injection technique at the training phase.
[0040] 4
[0041] ACTIVE 126368586.1072396.1116
[0042] FIG. 4B illustrates an example architecture of PCAP-Backdoor injection technique at the attack phase.
[0043] FIG. 5 illustrates an example prototype for PCAB-Backdoor generator.
[0044] FIG. 6 illustrates an example comparison of a pair of bidirectional packets before and after the backdoor injection process.
[0045] FIGS. 7A-7C illustrate example model performance on various attacks.
[0046] FIGS. 8A-8D illustrates example Confusion matrix on the Fuzzing attack dataset. FIGS. 9A-9D illustrates example Confusion matrix on the Mirai dataset.
[0047] FIGS. 10A-10B illustrates example Confusion matrix on the Modbus MITM attack. FIGS. 11A-11B illustrates example backdoor performance of different network attack data combinations.
[0048] FIGS. 12A-12D illustrate example performance of various models on the Fuzzing attack dataset.
[0049] FIGS. 13A-13C illustrate example Confusion matrix for multi-class classification model.
[0050] FIGS. 14A-14B illustrate example performance on various feature sets using backdoored Fuzzing dataset.
[0051] FIGS. 15A-15B illustrate example impact on performance for varying trigger packet counts and different datasets.
[0052] FIG. 16A illustrates example activations of the last hidden layer of backdoored model on normal data and attack packets with trigger classified as benign.
[0053] FIG. 16B illustrates an example activation cluster of benign predictions by backdoored model.
[0054] FIG. 16C illustrates another example activation cluster of benign predictions by backdoored model.
[0055] FIG. 17 illustrates an example flow diagram for determining whether an IDS model is susceptible to backdoor attacks.
[0056] FIG. 18 illustrates an example flow diagram for determining whether an IDS model has already been backdoored.
[0057] FIG. 19 illustrates an example method for determining whether an IDS model is vulnerable.
[0058] FIG. 20 illustrates an example computer system.
[0059] 5
[0060] ACTIVE 126368586.1072396.1116
[0061] DETAILED DESCRIPTION
[0062] This disclosure demonstrates how data-driven IDS systems can be vulnerable to backdoor attacks. This disclosure designs PCAP-Backdoor, a novel technique that enables backdoor poisoning attacks on PCAP datasets. Unlike prior work that modifies input features to add triggers, the embodiments disclosed herein take a novel approach of creating backdoor attacks into PCAP datasets by carefully introducing network traffic packets as triggers to compromise the dataset. Subsequently, when a classifier is trained on this poisoned dataset, this disclosure demonstrates that the classifier learns to associate the injected triggers with the target class. The experiments on real-world cyber-physical systems (CPS) and loT network traffic datasets demonstrate that an attacker can effectively backdoor a model by poisoning only 1% or less of the entire training dataset during model training. Furthermore, this disclosure shows that an attacker can introduce a trigger on benign traffic during model training and yet cause a backdoor model to misclassify when the trigger is present on malicious traffic. Finally, this disclosure demonstrates that the disclosed trigger-based backdoor is challenging to detect even with activation-based clustering techniques.
[0063] The convergence of information technology (IT) and operational technology (OT) has made the IoT and CPS integral to critical infrastructure, connecting these systems to the Internet to enable real-time monitoring and data-driven decision-making. However, this connectivity also brings significant cybersecurity risks. Recent reports indicate a sharp increase in cyberattacks targeting IoT and CPS networks, as attackers exploit vulnerabilities inherent in these interconnected systems. Attackers exploit system vulnerabilities in these devices to gain unauthorized access and compromise IoT systems, causing significant damage. Given that the number of IoT devices is projected to reach 32.1 billion in 2030, it is expected that the incidents of IoT attacks will continue to rise significantly.
[0064] To mitigate these attacks, many security systems deploy intrusion detection systems (IDS) to secure their networks. IDS acts as a security mechanism by inspecting network traffic packets at the Internet gateway, providing real-time responses to prevent attacks on IoT systems. By continuously monitoring and analyzing network data, IDS can detect suspicious activities and anomalies. This enables timely interventions to protect against potential threats. However, traditional IDS systems often rely on predefined rules and signatures to detect known threats, which can be less effective against new and evolving attack methods. This has led to the development of data-driven techniques that leverage advanced machine learning and deep learning algorithms to analyze large datasets of network traffic. Unlike traditional IDS, which
[0065] 6
[0066] ACTIVE 126368586.1072396.1116
[0067] rely on static rules, data-driven IDS can dynamically learn from historical data and adapt to new data patterns. These techniques have shown significant improvements in the performance of IDS by enhancing their ability to identify anomalies and suspicious activities.
[0068] Despite these improvements, DL-based models are also vulnerable to backdoor poisoning attacks. In these attacks, malicious actors can manipulate the training data or model parameters to insert hidden triggers, known as backdoors. These backdoors are designed such that the model learns to associate them with one or more target class. Under normal circumstances, when presented with legitimate data, the presence of the backdoor has minimal impact on the model’s classification results. However, when presented with data that has the hidden trigger, the model misclassifies the input as the target class associated with the backdoor. This compromise allows attackers to manipulate the behavior of the DL model in a way that suits their malicious intent.
[0069] Backdoor poisoning attacks have been extensively studied in the context of image classification and natural language processing (NLP), but less so in intrusion detection systems. However, prior work has primarily focused on directly manipulating input features. For instance, in image classification, carefully crafted perturbations lead to model misclassification, and the viability of such attacks has been demonstrated in realistic scenarios, such as printing manipulated images on t-shirts to evade detection. In NLP, there are works demonstrating trigger-less and trigger-based backdoor attacks. Similarly, backdoor attacks on speech domain such as speech recognition and speaker verification are also studied. FIG. 1A illustrates example clean label backdoor attacks on network packets of an IDS using prior work. In IDS, statistical features (e.g., the inter-arrival time between packets) are carefully perturbed after extraction by the feature extractor (see FIG. 1A). Note that direct feature manipulation cannot always be practical or feasible in IDS. Successful execution of such attacks typically requires access to the feature extractor of the IDS model, which is often inaccessible in real-world scenarios. As a result, existing backdoor attack techniques that rely on direct feature manipulation have limited applicability to intrusion detection systems.
[0070] This disclosure investigates the feasibility to perform backdoor attacks and discloses a system to manipulate the behavior of the IDS model, where the attacker does not have direct access to feature extraction step. FIG. 1B illustrates example clean label backdoor attacks on network packets of an IDS using the embodiments disclosed herein. Instead of modifying the features, the disclosed attack modifies the packet streams 102 to execute the attack. Specifically, the embodiments disclosed herein examine the scenario where the attacker can only manipulate the raw network packets 102 (see FIG. 1B). At step 110, present embodiments 7
[0071] ACTIVE 126368586.1072396.1116
[0072] intercept traffic packets. At step 120, present embodiments add backdoor triggers by modifying raw packet statistics to generate backdoor attack 104. The attacker does not have access to feature extraction 108 process. The modified packets 106 are processed by the feature extractor 108. At step 130, present embodiments train on data (extracted features) with triggers. By manipulating the raw packets 102, an attacker can potentially introduce subtle modifications that indirectly affect the feature extraction 108 process. These modifications can be strategically designed to trigger specific behaviors or patterns in the IDS model, leading to misclassification or evasion of detection. This indirect manipulation of features opens new avenues for backdoor attacks in IDS. The technical advantages of the embodiments disclosed herein include:
[0073] The embodiments disclosed herein investigate the feasibility of backdoor attacks on PCAP datasets. This disclosure empirically shows that the embodiments disclosed herein can design and introduce backdoor triggers in these datasets to backdoor data-driven IDS models.
[0074] The embodiments disclosed herein disclose a novel backdoor attack technique, PCAP-Backdoor, designed to create backdoor triggers in Packet Capture (PCAP) datasets. Unlike conventional work, this approach assumes the attacker lacks access to the feature extractor, opting instead to inject backdoors directly into the PCAP dataset. The disclosed design enables the modification of packet flows within the captured network traffic, facilitating the insertion of subtle anomalies that can trigger specific behaviors in IDS or other network security systems. Furthermore, this disclosure shows that the disclosed backdoor attacks can evade detection through simple TCP analysis in packet capture tools.
[0075] The embodiments disclosed herein extensively evaluate the disclosed approach on datasets from real-world CPS and IoT environments. The results demonstrate that attackers can manipulate and demonstrate that an attacker can successfully create a backdoor even with control over network traffic originating from a single IoT device. Furthermore, the results show that attackers can alter the IDS behavior, causing the model to misclassify data only when the trigger is present. Importantly, the model can be backdoored even when the attacker contributes benign labeled traffic during the training process. This means that despite not exposing the model to mislabeled malicious traffic from the attacker, the model still misclassifies data when the backdoor trigger is present.
[0076] This disclosure compares the disclosed approach against baseline techniques and demonstrate that the attacker needs only 1% or less poisoned data to successfully compromise the model. Finally, this disclosure shows that the disclosed attack is challenging to detect, even
[0077] 8
[0078] ACTIVE 126368586.1072396.1116
[0079] when using activation-based clustering, a state-of-the-art technique for detecting poisoned datasets.
[0080] Network anomaly detection is a key component in IDS that identifies abnormal activities within a network. Packet Capture (PCAP) are essential in this process, as they store the raw data of network packets, including header and payload information, providing a comprehensive view of network traffic. Packet capture tools are commonly used to capture and analyze network traffic, providing valuable insights into network protocols, packet contents, and communication patterns. Data-driven IDS techniques rely heavily on these PCAP datasets to learn and detect attacks, referred to as anomalies, within network traffic. These techniques treat network anomaly detection as a classification task, where network packets are analyzed and classified as either normal or malicious.
[0081] To train an anomaly detection model, relevant features are extracted from a PCAP dataset using a feature extractor. This process involves a packet parser, which gathers information from raw packets. Extracted features often include flow-level statistics that capture traffic flow behavior, such as statistics originating from source / destination IP addresses. Flowbased features are particularly valuable for anomaly detection in IoT devices, as they also consider past history. In addition to flow-level statistics, other features can be extracted, such as packet payloads, protocols, and device-specific information. The extracted features serve as input for training anomaly detection models. Various methods, including deep learning architectures and other techniques, can be employed to identify anomalies. In summary, the basic architecture assumed in such systems involves a packet capture tool to intercept raw network traffic data, which is then processed by a feature extractor to derive traffic statistics. These extracted features are then utilized to train an anomaly detection algorithm, enabling the identification of anomalous network traffic.
[0082] Backdoor attacks involve the insertion of malicious triggers into the training process, enabling attackers to manipulate the model’s behavior when these triggers are present in the input data. The attack typically involves poisoning the training data with a specific trigger pattern, accompanied by manipulated labels targeting a specific class. When this trigger pattern is present in the input during inference time, it activates the attack. FIGS. 2A-2B illustrate an example backdoor attack wherein the attacker poisons the training dataset by linking a trigger with the image. FIG. 2A shows a backdoor attack demonstration where the attacker poisons the training dataset by linking a trigger as a packet pattern in the traffic. Post-training, as shown in FIG. 2B, the model misclassifies any traffic containing the trigger while correctly predicting values for traffic without the trigger.
[0083] 9
[0084] ACTIVE 126368586.1072396.1116
[0085] Formally, given an input x, the attacker strategically designs a perturbation denoted as 6 to be added to x such that the perturbed input, x + δ, now contains the activation trigger. The model, denoted as Fewhere 6 represents the model’s parameters, will behave correctly and yield accurate results when presented with the normal input x. However, upon encountering the perturbed input x + δ, the model exhibits unintended and potentially malicious behavior, misclassifying the data due to the influence of the hidden trigger.
[0086] Backdoor attacks have demonstrated success in various applications. However, conducting backdoor attacks on Intrusion Detection Systems (IDS) presents unique challenges as raw packets are pre-processed before providing them as input to the model. Conventional work can inject backdoor triggers on the features after the features were extracted from the network traffic packets. Perturbing features after the feature extraction step is not very practical for IDS, as it assumes the attacker has access to the feature extractor. Most feature extractors derive traffic statistics from the raw packets. Therefore, a successful attack would require altering the raw packets in such a way that it impacts the extracted features overall. In other words, there is an additional level of indirection that is not present in traditional backdoor attack studies. Differently from the conventional work, the embodiments disclosed herein inject backdoor triggers directly into the network traffic packets by modifying the packet statistics.
[0087] The threat model disclosed herein considers two key actors: (i) a victim who trains and deploys an IDS model to detect anomalies and (ii) an adversary who wishes to mount a backdoor attack and controls a subset of the training samples. Certain non-limiting embodiments assume the adversary has limited control over the training dataset, which can occur when the victim uses third-party or publicly sourced data.
[0088] The adversary can manipulate the dataset in various ways. In a scenario, the adversary collects network packets from devices under their control. They can manipulate multiple aspects of the data, such as protocols, sender or destination IP addresses, and ports, to introduce a backdoor trigger to poison the data. This manipulated data is then made available to the victim for training an intrusion detection model. The adversary has two goals to poison the data. First, the manipulation should be stealthy so that the poisoned data is not easily detectable. Note that the adversary does not have access to the victim’s training or test dataset. Thus, the attacker cannot manipulate any other training data that the victim can possess. Second, inputs that have attacker-chosen backdoor triggers can change the prediction of the victim’s model.
[0089] The disclosed threat model further restricts the adversary’s control over the labels of the training samples. Specifically, certain non-limiting embodiments consider clean-label
[0090] 10
[0091] ACTIVE 126368586.1072396.1116
[0092] poisoning attacks where the attacker does not control the labels of the poisoned samples. In this scenario, the adversary does not disguise malicious data as benign to execute the attack. Instead, the adversary exclusively poisons benign samples by introducing backdoor triggers and labeling them as benign. This represents a more realistic poisoning scenario, as opposed to other poisoning attacks that assume label control over the poisoned samples.
[0093] During the attack phase, the attacker introduces these backdoor triggers within malicious traffic data to cause the model to misclassify it as benign. This attack is particularly challenging to execute because the traffic flow of malicious data can exhibit a wide range of characteristics, and the target model does not encounter malicious samples with triggers during training.
[0094] Unlike prior work which assumes that the attacker has knowledge of the target model architecture, the disclosed threat model takes a more realistic approach in a black-box setting. In this scenario, the attacker operates without any prior knowledge of the model architecture. Additionally, they have no control over the training process, including the duration of model training and the hyperparameters employed. This realistic assumption mirrors situations in the real world where attackers can encounter challenges due to a lack of detailed information about the target system, making the execution of the attack more complex. Furthermore, certain nonlimiting embodiments consider a scenario where the attacker has no access to the feature extraction process and cannot tamper with it. However, certain non-limiting embodiments assume the attacker knows what features can be extracted from the raw packets. Thus, the disclosed threat model relies on constructing poisoned samples that cannot directly manipulate the extracted features to insert the backdoor trigger. Finally, certain non-limiting embodiments assume that the attacker has knowledge of the traffic data distribution and can use this knowledge to poison the data.
[0095] Let P be the dataset consisting of raw network packets. These network packets can be classified into two classes: benign and malicious. Benign packets represent normal, legitimate network traffic, while malicious packets are associated with network attacks or unauthorized activities.
[0096] The adversary, 풜, controls a subset of devices, which it uses to generate benign traffic dataset which is denoted as J’adv c P. The backdoor poisoned data contributed by the adversary, denoted as J’poison c J’adv, is much smaller in volume compared to the overall training dataset. The adversary aims to strategically introduce backdoor trigger patterns into the benign packets inJ’poison. Given the raw network packets and the poisoned data J’poison,
[0097] 11
[0098] ACTIVE 126368586.1072396.1116
[0099] the adversary poisons the traffic dataset with a trigger δ such that when a sequence of packets (x1, x2, ···, xn) G P contains the trigger, the trained model T misclassifies (x1, x2, ···, xn) + 풫, but accurately classifies normal packets without the trigger. The adversary’s goal is to achieve a successful backdoor attack while operating in a black-box setting, where the adversary has no prior knowledge of the model architecture ℱ, the training dataset 풫, and the model parameters θ used for training
[0100]
[0101] .
[0102] Certain technical challenges exist for designing a PCAP backdoor generator. A simple approach is to introduce an existing packet from the captured dataset into the traffic flow as a backdoor. However, such packets can be easily detected as most packet capture systems perform basic TCP analysis by tracking TCP sessions. FIG. 3 illustrates example TCP ACKed unseen segment and TCP ports reused error using a strawman approach. As shown in FIG. 3, the packet capture tool can issue warnings, such as TCP ports reused, when such problems are encountered during packet processing. Below are some examples that the packet capture tool can throw an error or issue warnings if poisoned packets are not injected carefully.
[0103] One example includes TCP spurious re-transmission. This error typically indicates that the packet capture tool has detected duplicate or unnecessary transmissions. It can occur when the SYN flag is set, but the data flow is not acknowledged, potentially raising concerns about SYN flooding, especially in bidirectional communication scenarios.
[0104] Another example includes TCP ACKed unseen segment. This error indicates that the packet capture tool has parsed an ACK packet, where the receiving end acknowledges the receipt of a data segment claimed to be sent by the sender. However, the packet capture tool has no record of receiving that specific data segment. This issue usually arises when the acknowledgment sequence number is incorrect.
[0105] Another example includes TCP port number reused. When introducing packets, it is essential to ensure that the packet does not reuse an already in-use port. This can trigger warnings in the packet capture tool if existing communications use the same addresses and ports.
[0106] Another example includes TCP out-of-order. This error occurs when a packet is sent out of the order of the three-way handshake protocol. Under normal circumstances, data segments are delivered in the correct sequence to the receiver, and the receiver acknowledges each segment before the next one is sent.
[0107] It is important to note that while many of these errors cannot necessarily indicate a problem or error, excessive occurrences of specific errors due to data poisoning can raise
[0108] 12
[0109] ACTIVE 126368586.1072396.1116
[0110] concerns and warrant further investigation. For example, TCP ACKed unseen segment could be caused by packet loss or out-of-delivery errors, which are common and handled by the TCP protocol. Thus, in designing a PCAP -Backdoor generator, it is crucial to carefully consider these error scenarios and ensure that the generated poisoned packets can avoid detection while mimicking normal network behavior.
[0111] The key hypothesis is that certain non-limiting embodiments can create backdoor triggers and manipulate the behavior of the model by crafting traffic packets to alter the computed traffic flow statistics of the feature extractor. As a result, even though the attacker does not have access to the feature extractor, it can influence the features to introduce a backdoor into the model.
[0112] FIG. 4A illustrates an example architecture 410 of PCAP -Backdoor injection technique at the training phase. During the training phase, at the first operation 412, feature extractor 108 collects normal packets generated by IoT devices. At the second operation 414, the attacker poisons a subset of the dataset by introducing backdoor trigger packets 416 to the benign network traffic and sends to the feature extractor 108. Next, at the third operation 418, feature extractor 108 generates the features from the combined data packets and train the model. Finally, at the fourth operation 420, the trained model is deployed. FIG. 4B illustrates an example architecture 450 of PCAP -Backdoor injection technique at the attack phase. In the attack phase, the attacker can execute the backdoor attack 416 by introducing its own trigger packets on malicious traffic, which is classified as benign 452 by the model as described in FIG. 4B. The packets 454 that are not processed by PCAP -Backdoor are classified normally 456. The parameters used by PCAP -Backdoor to control the trigger is represented as PCAP-Config 422 in FIG. 4A.
[0113] Below, this disclosure presents the PCAP -Backdoor design, that enables certain nonlimiting embodiments to introduce traffic packets into network traffic for enabling backdoor attacks. In this disclosure, the disclosed approach primarily focuses on TCP and UDP communication, as these are among the most widely used communication protocols in network traffic. However, the embodiments disclosed herein are not limited to these protocols and this disclosure contemplates any other suitable communication protocols.
[0114] Certain non-limiting embodiments utilize a bi-directional algorithm for creating a poisoned dataset. The bi-directional algorithm, denoted as Pbd, involves injecting specifically crafted trigger packets, defined as a burst of packets, into the benign network traffic dataset P. These trigger packets are designed to look like legitimate traffic, making it difficult to detect through standard network analysis tools. Moreover, these trigger packets influence the feature 13
[0115] ACTIVE 126368586.1072396.1116
[0116] statistics, altering the model’ s IDS output when the trigger is present. Specifically, the presence of these trigger packets during inference causes the model to misclassify the input packets.
[0117] PCAP -Backdoor considers both unidirectional flow (e.g., from source to destination) and bi-directional flow (e.g., in both directions between source and destination) when injecting packets. This approach ensures that the inj ected packets seamlessly blend in with the legitimate traffic, reducing the chances of detection when analyzed using packet capture tools. By considering both types of flows, the disclosed algorithm creates a more realistic and covert backdoor that can influence the behavior of the deep learning model without arousing suspicion during network traffic analysis.
[0118] Algorithm 1 outlines the pseudo-code for generating a poisoned dataset based on the input network traffic dataset. To inject the trigger packets, the algorithm uses three control parameters: B, D, and R. The parameter B controls the number of trigger packets, D specifies the delay between each trigger packet, and R represents the proportion of packets to be poisoned.
[0119] Algorithm 1 Backdoor trigger packet generation.
[0120] Input: P is the raw network dataset; parameters B represents the backdoor trigger packet count; D is the time delay between each trigger packet; R is backdoor injection packet selection ratio; BT refers to the time frame used to identify a bidirectional packet pair that matches a source packet.
[0121] Output: Pbdbackdoor traffic dataset
[0122] 1: procedure GENERATE_B ACKDOOR
[0123] 2: Init: Pbp← Φ ▷ initialize 3: for pi E P at index i do
[0124] 4: a ∼ 풰(0,1) ▷ select a value from uniform dist.
[0125] 5: if a < R then
[0126] 6: if IS BD then ▷ Is Bi-directional? 7: Pbd← Pbd∪ BD − Inject
[0127] − 2way(pi, B, D)
[0128] 8: else
[0129] 9: td
[0130] ← time difference between piand pi+1
[0131] 10: bc ← min (B, ⌊td / D⌋
[0132] 11: Pbd← Pbd∪ BD − Inject (pi, bc, D)
[0133] 12: function isBD(i)
[0134] 13: for pj∈ P where j > i and time(pj) − time(pi) ≤ BT do
[0135] 14: if SrcIP(pi) == DstIP(pj) and SrcIP(pj) == DstIP(pi)
[0136] then
[0137] 15: return true
[0138] 14
[0139] ACTIVE 126368586.1072396.1116
[0140] return false ▷ return bidirectional status 16: function BD — Inject — 2way(p, B, D)
[0141] 17: pbd← Craft pair of backdoor trigger packets for B
[0142] times
[0143] return pbd▷ return crafted packets 18: function BD − Inject (p, bc, D)
[0144] 19: pbd← Craft backdoor trigger packets for bc times
[0145] return pbd▷ return crafted packets The algorithm processes each packet pt in the network traffic dataset P as follows. For each packet, a random decision is made to inject a backdoor based on the desired proportion of poisoned packets specified by the input parameter P. Additionally, the algorithm determines whether the packet corresponds to a bidirectional communication by looking ahead in the dataset for a matching bidirectional packet pair. If the packet is unidirectional, the algorithm calculates the time difference between the current packet pt and the next packet Pi+1. It then computes the maximum number of trigger packets that can be injected such that the time of injected packets is not greater than Pi+1. This ensures that the injected packets are contiguous and align with the original flow of traffic. On the other hand, if the packet is bidirectional, the algorithm injects trigger packets on both pairs. In doing so, the backdoor influences both directions of communication, reducing the likelihood of detection when analyzed using packet capture tools.
[0146] Certain non-limiting embodiments craft the trigger packets as follows. For unidirectional packets, we generate a variable number of trigger packets with similar protocol and source IP, but with an arbitrary destination IP. The payload size is fixed to L, achieved by trimming or padding the packet payload, and the packet header is adjusted accordingly with the new length L. The number of trigger packets is calculated as the minimum value between B and the available time gap between neighboring packets divided by L. On the other hand, for bidirectional packets, certain non-limiting embodiments inject B pairs of packets. The source packet contains the SY N flag and is set for an arbitrary destination, while the corresponding response packet contains the RST flag with the source and destination IP addresses swapped. To avoid violating the TCP 3 -way handshake protocol, certain non-limiting embodiments assign a random sequence number to the TCP SY N packet and increment the sequence number by 1 for the response packet. The timestamps of the new packets are set by adding a time offset of D. Like unidirectional packets, the payload size is fixed to L, achieved through trimming or padding, and the packet header is adjusted with the new length L (see Algorithm 2).
[0147] Algorithm 2 Bidirectional backdoor trigger generation.
[0148] 15
[0149] ACTIVE 126368586.1072396.1116
[0150] Input: (ptx, prx) is the pair of clean bidirectional packet taken from predefined time window with packet lengths of (ltx, lrx) respectively. The parameters B and D represents the backdoor trigger packet count and the time delay between each trigger packet injection. L be the length of trigger packet.
[0151] Output: (pbdtx, pbdrx) is the bidirectional backdoor traffic dataset
[0152] 1: procedure BD-CRAFT-2WAY
[0153] 2: Init: Create a copy of (ptx, prx) to (pbdtx, pbdrx) ▷ initialize 3: if pbdtxTCP layer then
[0154] 4: Set SY N flag of pbdtxto 1.
[0155] 5: SQN <- arandomnumber
[0156] 6: Assign SQN as sequence number to pbdtx
[0157] 7: ltx← L
[0158] 8: Assign Dst-IP, D st- MAC
[0159] 9: if pbdrxhas TCP layer then
[0160] 10: Set RST flag of pbdrxto 1.
[0161] 11: SQN ← SQN + 1
[0162] 12: Assign SQN sequence number to pbdrx
[0163] 13: lrx← L
[0164] 14: Assign Src and Dst (IP, MAC) to pbdrxfrom Src and Dst (IP, MAC)
[0165] of pbdtxswapped.
[0166] 15: Increment timestamp of packet by D.
[0167] 16: Trim or pad payload upto length L.
[0168] return (pbdtx, pbdrx) ▷ return crafted packets FIG. 5 illustrates an example prototype 500 for PCAB-Backdoor generator. The network data 510 can be provided to the PCAB-backdoor generator 520, which can output backdoored data 540. More specifically, the PCAB-backdoor generator 520 can include a packet parser 522, an analyzer 524, a rule engine 526, metadata 528, and a packet injector 530. The packet parser 522 can be configured to analyze the network data 510. The analyzer 524 can be configured to extract the parameter values corresponding to the user configuration in metadata 528. The rule engine 526 can be configured to learn or compute when to inject backdoor packet based on the configuration, e.g., inject backdoors only for TCP packets. The packet injector 530 can be configured to inject packets based on the output from the rule engine 526.
[0169] Certain non-limiting embodiments implemented the disclosed PCAP -Backdoor technique in python and used the scapy library to manipulate the packets and inject new packets into the dataset. The scapy library provides the necessary functionalities to parse packets and extract header information, set various TCP flags, modify header details, and control payload size. The implementation sets appropriate sequence numbers to reduce TCP analysis warnings, ensuring that the injected packets blend seamlessly with the original traffic. FIG. 6 illustrates
[0170] 16
[0171] ACTIVE 126368586.1072396.1116
[0172] an example comparison of a pair of bidirectional packets before and after the backdoor inj ection process. As shown, even after injecting the packets, the packet capture tool does not issue any warnings, indicating that the disclosed PCAP-Backdoor technique effectively crafts realistic-looking packets that do not raise any suspicion during analysis.
[0173] The disclosed PCAP-Backdoor implementation provides various controls on how trigger packets are injected. As mentioned, certain non-limiting embodiments can adjust the number of trigger packets or pairs of packets injected from the same source IP corresponding to an original packet or pair of packets. Additionally, certain non-limiting embodiments have control over the packet size and time offset of any newly injected trigger packet. This flexibility allows certain embodiments to fine-tune the backdoor injection process and explore different scenarios for effective backdoor attacks in deep learning-based intrusion detection systems.
[0174] The embodiments disclosed herein evaluated the disclosed techniques in CPS and IoT domains. CPS SCADA dataset consists of network traffic data capturing both normal SCADA operations and four types of DoS attacks. For this SCADA dataset, a liquid pump is simulated by an electric motor controlled via a variable frequency drive, with oversight provided by a programmable logic controller (PLC). The PLC communicates with a Modbus remote terminal unit and a human-machine interface (HMI) to manage operations. The dataset includes variations in the time of capture (e.g., 30 minutes and 1 hour) and duration of attack (e.g., 1, 5, and 15 minutes within each capture).
[0175] UCI IoT network attack dataset includes network traffic packets from nine IoT devices infected by various botnets, including Mirai. It contains over 7 million packets across 10 classes, representing different types of network attacks along with a benign class. A key characteristic of the dataset is its data imbalance: certain attack classes have significantly fewer samples than others, and the number of devices associated with each attack class also varies considerably.
[0176] Certain non-limiting embodiments analyze the backdoor performance on a deep neural network architecture (DNN-3) with an input layer, three hidden layers, and an output layer for network anomaly detection. This network takes input features extracted by the feature extraction module and predicts whether a given packet represents an anomaly, i.e., traffic from a network attack. The feature extraction module uses 115 features for classification and is based on Kitsune. These features are statistical properties of the packet streams such as weight of the stream, mean, std deviation, radius (root squared sum of the two streams’ variances), magnitude (root squared sum of the two streams’ means), covariance between two streams, Pearson correlation coefficient between two streams. The streams are aggregated based on traffic from 17
[0177] ACTIVE 126368586.1072396.1116
[0178] a source IP, source-destination IP pair, source-destination IP and port combination, and jitter of traffic going from a source -destination IP pair. Each statistical property is calculated based on the traffic observed in recent history. However, we also explore various combinations of these features to demonstrate the effectiveness of our approach. Moreover, in addition to the anomaly detection model, certain non-limiting embodiments train a separate model designed to identify the specific type of network attack. This model also follows a deep neural network structure, resembling the architecture of the anomaly detection model but with an output layer tailored to predict the attack type. Because of resource constraints, certain non-limiting embodiments analyze on four class types: Mirai, Fuzzing, Wiretapping and Benign. Additionally, certain non-limiting embodiments use binary and categorical cross entropy as the loss function with Adam optimizer, respectively. An analysis on unmodified clean data indicates that both models achieve high accuracy in identifying anomalous patterns effectively.
[0179] Certain non-limiting embodiments use the disclosed tool called PCAP -Backdoor to generate the trigger dataset for the analysis. During trigger dataset generation, certain nonlimiting embodiments fix the destination IP and MAC address while retaining the realistic source IP of a device from the attack PCAP log. Moreover, certain non-limiting embodiments keep the TCP port and frame length of the realistic packet from that device. This ensures that the introduced packets can influence flow-based statistics extracted from the feature extractor. To control the extent of backdoor injection, certain non-limiting embodiments set R = 0.2, indicating a backdoor injection packet selection ratio of 20%.
[0180] To generate the final dataset for training, certain non-limiting embodiments use this poisoned PCAP and the original dataset in different proportions to perform our analysis. For example, a 1% backdoor percentage means 1% of the entire training dataset is coming from the poisoned PCAP dataset. Unless stated otherwise, certain non-limiting embodiments only use traffic originating from one IoT device. This demonstrates the attack’s robustness, a scenario when the attacker can manipulate only one device out of the 9 devices in the dataset.
[0181] For model training, certain non-limiting embodiments split the final dataset into 80% training and 20% testing sets. The training dataset includes samples from the normal dataset, consisting of both benign and attack traffic, along with a limited number of poisoned benign samples (i.e., benign traffic with triggers). Note that the training dataset does not contain any poisoned attack samples. The key idea is that when triggers are introduced into attack traffic during inference, the model should misclassify the packets, detecting them as normal (benign) instead of recognizing them as malicious. By training the model without any malicious samples and only injecting backdoor triggers into benign traffic, certain non-limiting embodiments 18
[0182] ACTIVE 126368586.1072396.1116
[0183] simulate a real-world scenario where an attacker attempts to manipulate the model’s behavior without directly accessing attack traffic data.
[0184] A model is backdoored by training it with samples of clean features from both benign and attack packets along with a random sample (backdoor percentage) of poisoned features of benign packets from a particular device (source IP based). In the disclosed experiment, certain non-limiting embodiments assumed a device with certain IP carries out the poisoned trigger packet injection at a time. If original packets from such device is too low in number, then the number of poisoned packets also will remain low for that device. The typical backdoor percentages disclosed herein are in the range of 0.5 to 10 percentage. During testing time, certain non-limiting embodiments use test sample of attack packets with trigger.
[0185] The disclosed backdoor approach is based on poisoning the features by injecting packets in between real traffic. The backdoor trigger packets are created using arbitrarily fixing the destination IP and MAC address while keeping the realistic source IP of a device in the attack PCAP log. Certain non-limiting embodiments retain the TCP port and frame length of the realistic packet from that device. Since the features are generated for a channel related to IP, the disclosed approach can cause changes to the features corresponding to succeeding normal packets after a trigger injection.
[0186] In all the experiments disclosed herein, certain non-limiting embodiments fix the training and testing ratio to 80-20. Due to large volume of data used for training in case of multi-class classification model, certain non-limiting embodiments use dataset of three attacks and corresponding benign datasets and trim the dataset to maximum of one million datapoints per class of attacks. For Fuzzing and Wiretapping datsets, certain non-limiting embodiments take 600, 000 benign and 1000, 000 attack packets. Since Mirai dataset is comparatively smaller, certain non-limiting embodiments take the complete benign and attack dataset of training.
[0187] The embodiments disclosed herein use metrics including F1-score, attack success rate (ASR), and Silhouette score for evaluation. Since the dataset is highly unbalanced, this disclosure uses F1-score as a metric to evaluate the performance of the disclosed technique in most of the disclosed experiments. In case of multi-class classification model, this disclosure uses macro-F1-score to get the holistic performance score by giving equal importance to each class in an imbalanced dataset.
[0188] ASR is defined as the ratio of samples with trigger misclassified by the backdoored model to the total number of samples with trigger used in the attack.
[0189] 19
[0190] ACTIVE 126368586.1072396.1116
[0191] Silhouette score is a metric used to calculate the how good is the clustering technique. This disclosure uses Silhouette score to evaluate stealthiness of the disclosed backdoor mechanism. It ranges from -1 to 1, where 1 indicates well-separated and clearly distinguished clusters, while 0 suggests that clusters are not well separated, making it difficult to distinguish between data points from different clusters. In other words, a Silhouette score close to 1 indicates the optimal number of clusters for that dataset.
[0192] Certain non-limiting embodiments create the backdoor dataset by combining one or more network attack datasets and then evaluate the performance of the disclosed model in detecting anomalous traffic within these datasets. Certain non-limiting embodiments use labelflipping poisoning attacks as a baseline. In the label-flipping attack, the adversary manipulates the malicious samples in the training data and changes the labels to benign. The baseline attack shows how much data needs to be manipulated during the training process to degrade the performance of the IDS model. When sufficient data is poisoned, the model misclassifies attack packets as benign. In contrast, note that the approach disclosed here uses a clean-label poisoning attack where the labels remain unchanged during the training process. Instead, certain non-limiting embodiments employ trigger packets to activate the attack.
[0193] Table I shows the disclosed trigger-based backdoor approach’s performance compared to the label-flipping attack. The percentage values in brackets in the table indicate the amount of data that needs to be manipulated for the attack to be successful. Note that in the labelflipping attack, there is no trigger present in the input data during inference time. As seen, the label-flipping attack requires a large amount of data to be manipulated to achieve success. In contrast, the disclosed approach requires a significantly smaller amount of trigger-poisoned data. For instance, to misclassify an ARP attack as benign, the baseline approach requires 40% of the dataset to be poisoned. In contrast, the disclosed approach achieves 0.98 attack success rate by poisoning only 2% of the training dataset. As another example, to misclassify a CPS-ICMP flooding attack as benign, the baseline approach requires 35% of the dataset to be poisoned. In contrast, the disclosed approach achieves a 0.97 attack success rate by poisoning only 2% of the training dataset.
[0194] Label Flipping
[0195] PCAP-Backdoor Attack (Baseline)
[0196] Attack Type
[0197] Labels modified Data ASR ASR
[0198] (%) modified (%) Modbus flooding 1 60 0.98 2 TCP SYN flooding 1 45 0.82 2 CPS MITM 1 40 0.78 2
[0199]
[0200] ICMP flooding 1 35 0.97 2
[0201] 20
[0202] ACTIVE 126368586.1072396.1116
[0203] Combined-binary 1 65 0.85 2 Multi-class IDS 1 65 0.87 2 Mirai (All IP) 1 80 0.39 2 Fuzzing 1 15 0.92 2 ARP 1 40 0.98 2 loT
[0204] Wiretapping 1 35 0.95 2 Combined-binary 1 55 0.72 2
[0205]
[0206] Multi-class IDS 1 65 0.84 2
[0207] TABLE I: Backdoor attack performance on different attacks.
[0208] This disclosure further assesses the performance on a multi-class IDS model designed to identify various types of network attack. In this scenario, instead of focusing on whether the traffic is malicious, the model distinguishes between different categories of attacks. Even in this case, the disclosed approach requires less data to achieve successful backdoor attacks. Specifically, when the trigger is present, the model misclassifies malicious traffic into the benign class. The disclosed technique does not perform well on the Mirai dataset, which is presumably because it is a smaller dataset. As discussed previously, certain non-limiting embodiments can improve the performance by including malicious traffic in the training process.
[0209] In short summary, the disclosed PCAP -Backdoor technique outperforms baseline technique in terms of achieving high ASR while maintaining a very low trigger percentage in all datasets while testing with both binary and multi classifiers.
[0210] Next, this disclosure compares the performance of the disclosed backdoor approach on different attack types within the anomaly detection dataset for various IoT devices. For this evaluation, certain non-limiting embodiments backdoor the benign traffic of one of the IoT devices and analyze whether the IDS anomaly detection misclassifies anomalous traffic. Certain non-limiting embodiments introduce trigger packets into the malicious data and measure the model’s performance using the Fl -score. A lower Fl -score indicates that the model misclassifies malicious traffic as benign, demonstrating the effectiveness of our backdoor attack in degrading the model’s performance.
[0211] FIGS. 7A-7C illustrate example model performance on various attacks. FIGS. 7A-7C present box plots of the performance for all IP addresses across different attack types in the dataset. FIG. 7A shows the performance of the normal data (without trigger) on the honest model and serves as a baseline. In FIG. 7B and FIG. 7C, the model is trained with trigger percentage of 1% and trigger packet count of 8. When the model is backdoored, as depicted in FIG. 7B, the model correctly classifies when presented with data without triggers. In contrast, when certain non-limiting embodiments present data with triggers, shown in FIG. 7C, the
[0212] 21
[0213] ACTIVE 126368586.1072396.1116
[0214] model misclassifies the input. In FIG. 7C, a lower Fl score indicates that data with the trigger is misclassified by the model, demonstrating attack success. This demonstrates that the presence of triggers alters the model’s behavior, leading to incorrect classifications. Furthermore, the results demonstrate that even when poisoning input samples from a single malicious device during training, certain non-limiting embodiments can effectively influence the model to misclassify traffic. Notably, in this scenario, the attacker does not have access to traffic originating from other devices. Despite this limitation, by injecting triggers into the malicious traffic from other devices, the model tends to classify this traffic as benign, as evidenced by a lower Fl -score. Additionally, the low variance in performance indicates that the backdoor attack consistently works across traffic from different devices.
[0215] While the Mirai dataset does not perform as well when only one device is infected, likely due to the limited size of the dataset, including traffic from all IP addresses further improves the results, yielding a lower Fl -score. To further enhance the attack’s effectiveness, certain non-limiting embodiments explore introducing malicious packets labeled as benign. Specifically, certain non-limiting embodiments use 10% of the malicious traffic packets to introduce triggers and include these in the poisoned dataset. Certain non-limiting embodiments ensure that this overall poisoned data constitutes only 1% of the training dataset. This approach achieves a close-to-zero Fl -score, indicating that the disclosed backdoor attack is highly effective in misclassifying traffic and executing the attack, even with a relatively small percentage of poisoned data.
[0216] Certain non-limiting embodiments also analyze the behavior of the model by plotting the confusion matrix. FIGS. 8A-8D illustrates example Confusion matrix on the Fuzzing attack dataset. FIGS. 9A-9D illustrates example Confusion matrix on the Mirai dataset. FIGS. 10A-10B illustrates example Confusion matrix on the Modbus MITM attack. FIG. 8A shows the performance of the normal data (without trigger) on the honest model. As depicted, the honest model can identify attack and benign traffic with high accuracy. Next, certain non-limiting embodiments generate the poisoned data and use it to create the backdoor model. Certain nonlimiting embodiments analyze the performance of this backdoor model on both the normal data (without trigger) and the poisoned data (with trigger). When the data has no trigger, the model can still identify benign and attack traffic accurately (see FIG. 8 A and FIG. 10 A). However, as shown in FIG. 8C and FIG. 10B, when the trigger is introduced on attack traffic, the model misclassifies it, even though the model was trained only on benign traffic with triggers and from a single loT device. This demonstrates that the backdoor attack successfully influences the model’s behavior, causing it to misclassify attack traffic as benign. When trigger data is 22
[0217] ACTIVE 126368586.1072396.1116
[0218] run on an honest model, the model can classify benign and attack data accurately, as shown in FIG. 8D, which proves that the trigger works only on the backdoor model. Similar performance was also observed in the Mirai dataset (see FIGS. 9A-9D).
[0219] In an experiment assessing the effect of the multi-attack combination, certain nonlimiting embodiments combine traffic from two different network attack classes. Specifically, certain non-limiting embodiments use various combinations of network attacks and label them as malicious if they consist of a network attack; otherwise, certain non-limiting embodiments classify them as benign. Certain non-limiting embodiments then train the disclosed model using this combined dataset. FIGS. 11A-11B illustrate example backdoor performance of different network attack data combinations. FIGS. 11A-11B show the performance on different combinations of attack datasets across all IP addresses, varying the backdoor percentage from 0.5% to 10%. As depicted in FIG. 11 A, the Fl score is low, indicating that the model misclassifies malicious attacks as benign. The median Fl -score when certain non-limiting embodiments combine Mirai and WireTapping is 0.31. As depicted in FIG. 1 IB, the high ASR indicates that the model misclassifies malicious attacks as benign. In particular, we observe that the median ASR score when we combine Mirai +WireTapping is 0.63.
[0220] Certain non-limiting embodiments further evaluate the efficacy of introducing a backdoor into various neural network intrusion detection models. The disclosed approach involves designing a range of models of varying sizes, denoted by DNN-5, indicating a model with five layers. Additionally, certain non-limiting embodiments explore CNN-based neural networks as part of the model architecture. FIGS. 12A-12D illustrate example performance of various models on the Fuzzing attack dataset. A lower Fl -score on the backdoor model indicates the model misclassifies the attack as benign. All these models, when trained with normal data, produce high accuracy and Fl score, as shown in FIG. 12 A. To evaluate the backdoor technique on different model architecture, certain non-limiting embodiments train all these models with 10% percentage of poisoned data and the trigger packet count is 3. The impact of training with the disclosed backdoor technique on the Fuzzing attack is illustrated in FIG. 12C. The different IDS models are vulnerable to backdoor attacks, as shown by the low Fl score on backdoor data. FIG. 12D also shows that the different IDS models are vulnerable to backdoor attacks, as indicated by high ASR scores. However, when presented with normal data with no triggers containing both benign and malicious traffic as shown in FIG. 12B, all models achieve a high Fl -score and an accuracy of at least 99%. This indicates that the model predicts correctly when no trigger is present. CNN-based IDS models are susceptible to backdoor attacks, as indicated by the low Fl score.
[0221] 23
[0222] ACTIVE 126368586.1072396.1116
[0223] Certain non-limiting embodiments also analyze the backdoor performance on a multiclass classification model, where the model identifies one of the four classes: Mirai, Fuzzing, Wiretapping, and Benign. For this experiment, as before, certain non-limiting embodiments set the trigger packet count to 5 and set the backdoor percentage rate to 1%. In other words, the attacker contributes only 1% for training the model. FIGS. 13A-13C illustrate example Confusion matrix for multi-class classification model. FIGS. 13A-13C depict the confusion matrix for the model’s behavior when given normal data and when given the backdoor data with triggers. The honest model performs well with an Fl score of 0.94 or more as shown in FIG. 13 A. Moreover, as shown in FIG. 13B, the model behaves normally and identifies malicious traffic when no trigger is present. However, when certain non-limiting embodiments introduce the disclosed trigger-based malicious traffic, the model misclassifies it as benign, as seen in FIG. 13C. This indicates that the attacker can successfully create backdoors even for multi-class classification model.
[0224] In the experiment assessing the effect of using different features, certain non-limiting embodiments explore different feature extractors by modifying the input features used for training. While the initial feature extractor is based on Kitsune, certain non-limiting embodiments consider other distinct feature sets. In particular, the first set contains the entire set of 115 features used in Kitsune. Next, certain non-limiting embodiments focus on features related to jitter. Certain non-limiting embodiments also create a feature extractor that uses socket-related features. Finally, the fourth feature extractor is based on packet size-related features. Using these different feature extractors, certain non-limiting embodiments conduct tests on the fuzzing dataset with a trigger packet count of 3. FIGS. 14A-14B illustrate example performance on various feature sets using backdoored Fuzzing dataset. The results, shown in FIGS. 14A-14B, reveal that the backdoor attack achieves low Fl scores or high ASR scores across all types of feature sets. Interestingly, the backdoor attack performs best when using the feature set related to packet size. This indicates that the disclosed backdoor attack can effectively influence the model’s behavior regardless of the specific feature extraction method used.
[0225] Another experiment assesses the effect of trigger packet count on backdoor performance. Note that trigger packet count controls the number of consecutive packets introduced during backdoor generation. This disclosure reports the analysis for different backdoor percentage varying from 0.5% to 10%. FIGS. 15A-15B illustrate example impact on performance for varying trigger packet counts and different datasets. As depicted in FIG. 15 A, as the trigger packet count increases, the Fl score decreases. As depicted in FIG. 15B, as the 24
[0226] ACTIVE 126368586.1072396.1116
[0227] trigger packet count increases, the ASR score increases. This indicates that the attacker can successfully change the model’s behavior with a higher trigger packet count. Intuitively, introducing more consecutive packets exerts a larger influence on flow-based statistics extracted from the feature extractor, enabling the attacker to effectively inject the trigger and execute the backdoor attack.
[0228] Certain non-limiting embodiments analyze whether the presence of backdoor triggers can be detected using the activation clustering algorithm. The basic idea is to cluster the activations of the last hidden layer from both benign and poisoned attack samples (with triggers) that were classified as benign by the backdoored model. The hypothesis is that the samples with triggers will activate distinct neurons due to the presence of triggers, leading to the formation of two distinct clusters in the activation space. In other words, if the activation clustering algorithm identifies two distinct clusters, this suggests that the model processes benign and poisoned samples differently, despite classifying them both as benign. This discrepancy in activation patterns is a strong indicator of the presence of backdoor triggers.
[0229] This disclosure visualizes the distribution of benign predictions for both normal benign data and attack data with triggers in two clusters as follows. First, certain non-limiting embodiments apply the t-SNE algorithm to the activations from the hidden layer of the IDS model to reduce the dimensionality of the data. Next, certain non-limiting embodiments use K-Means clustering with a cluster size of 2 on the t-SNE reduced data, focusing on the benign predictions. Finally, this disclosure plots the t-SNE results for each cluster.
[0230] Certain non-limiting embodiments analyze a multi-class model with four attack classes: Mirai, Fuzzing, Wiretapping, and Benign. To train the disclosed multi-class model, the dataset includes both benign and attack packets, where the attack packets can contain triggers or be without triggers. Note that while certain non-limiting embodiments analyze the multi-class model, certain non-limiting embodiments also analyzed single-class model, which yielded similar results.
[0231] FIG. 16A illustrates example activations of the last hidden layer of backdoored model on normal data and attack packets with trigger classified as benign. FIG. 16B illustrates an example activation cluster of benign predictions by backdoored model. FIG. 16C illustrates another example activation cluster of benign predictions by backdoored model. Misclassified benign predictions due to the presence of trigger are spread across both clusters. FIG. 16A shows the t-SNE plot of the last hidden layer activations for the dataset samples that were predicted as benign by the backdoored model. FIGS. 16B-16C indicate no distinct clusters formed by actual benign and misclassified benign predictions by the backdoored model.
[0232] 25
[0233] ACTIVE 126368586.1072396.1116
[0234] Ideally, one can expect to observe two distinct clusters in the t-SNE plot, where benign samples form one cluster and attack samples with triggers form another. However, as seen in FIGS.
[0235] 16B-16C, this is not the case. The attack samples with triggers are distributed across different clusters, indicating the absence of clear clusters.
[0236] To assess clustering quality, certain non-limiting embodiments compute Silhouette scores for various cluster sizes. Ideally, the highest score should correspond to a cluster size of two, indicating well-separated clusters including benign and attack with trigger. In contrast, the Silhouette score peaks at a cluster size of three, followed by four, suggesting a lack of well-defined clusters.
[0237] Certain non-limiting embodiments also use Silhouette score to quantitatively measure the stealthiness of the disclosed backdoored model. Specifically, this disclosure aims to compare and identify the Silhouette score for different cluster sizes, with a focus on understanding the effectiveness of a cluster size of 2 in comparison to other cluster configurations. To achieve this, certain non-limiting embodiments compute the Silhouette score on the hidden layer output of our backdoored model, corresponding to predictions of the benign class. Table II shows the silhouette scores corresponding to each cluster. The Silhouette score for cluster number 2 is low compared to other clusters. This suggests that distinguishing between normal benign and attack with trigger samples based on the hidden layer output is challenging, emphasizing the effectiveness of the backdoor in obfuscating model behavior. Cluster 1 2 3 4 5 6 7 size
[0238] Silhouette NA 0.62 0.73 0.72 0.66 0.68 0.67 scores
[0239]
[0240] TABLE II: Silhouette scores for each cluster size.
[0241] The embodiments disclosed herein ensure that the attacker provides traffic dataset from only one IoT device. However, introducing traffic from other IoT devices can further improve the accuracy of the backdoor attack. Interestingly, the backdoor percentage data has a limited influence on performance. That is, increasing the backdoor percentage does not lead to a linear improvement in backdoor performance. This observation was also made when certain nonlimiting embodiments introduced malicious samples as benign for training in the baseline comparison. Only after a certain backdoor data threshold, the impact of the backdoor percentage takes effect. While without triggers, this backdoor threshold is high, the disclosed trigger-based approach enables the threshold to be decreased.
[0242] 26
[0243] ACTIVE 126368586.1072396.1116
[0244] Moreover, changing both the destination and source port does not significantly influence the overall performance. This observation suggests that altering unique packets unrelated to the source does not significantly impact flow-based statistics.
[0245] While the disclosed approach demonstrates that a simple packet injection at pre-defined intervals works well, possible future extensions could explore using intelligent generative adversarial networks to introduce these packets. Leveraging GANs could potentially create more sophisticated backdoor attacks, posing additional challenges in detecting these backdoors.
[0246] Besides backdoor trigger generation described above, the embodiments disclosed herein further include backdoor analysis. In one example use case, the backdoor analysis can include determining whether an IDS model is susceptible to backdoor attacks. For example, the backdoor analysis can include determining whether a given IDS model has vulnerable backdoor configurations. FIG. 17 illustrates an example flow diagram 1700 for determining whether an IDS model is susceptible to backdoor attacks. After start 1705, the computing system can iterate through user configurations at step 1710. At step 1715, the computing system can train the model using backdoored packets. In certain non-limiting embodiments, the backdoored packets can be generated using the PCAB-backdoor generator 520 on raw packets. At step 1720, the computing system can check the model misclassification accuracy with trigger. At step 1725, the computing system can determine if misclassification exceeds a threshold. If misclassification exceeds the threshold, the computing system can store the configuration set into a database of vulnerable configurations at step 1730. In certain nonlimiting embodiments, the stored configuration set can include model susceptibility status and configurations with scores. If misclassification does not exceed the threshold, the computing system can determine whether the analysis covered all configurations at step 1735. If the analysis did not cover all configurations, the flow diagram 1700 can return to step 1710. If the analysis covered all configurations, the flow diagram 1700 can end at step 1740.
[0247] In another example use case, the backdoor analysis can include determining whether an IDS model has already been backdoored. FIG. 18 illustrates an example flow diagram 1800 for determining whether an IDS model has already been backdoored. After start 1810, the computing system can run input packet data through PCAP -Backdoor and generate backdoored packets at step 1820. In certain non-limiting embodiments, the backdoored packets can be generated using the PCAB-backdoor generator 520 on raw packets. At step 1830, the computing system can run the trained model using backdoored packets. At step 1840, the computing system can check the model misclassification accuracy. At step 1850, the 27
[0248] ACTIVE 126368586.1072396.1116
[0249] computing system can determine if misclassification exceeds a threshold. If misclassification exceeds the threshold, the computing system can determine that the model is vulnerable at step 1860. If misclassification does not exceed the threshold, the computing system can determine that the model is not vulnerable at step 1870. After step 1860 or step 1870, the flow diagram 1800 can end at step 1880.
[0250] This disclosure introduces PC AP-B ackdoor, a novel system for injecting backdoors in deep learning-based network intrusion detection models. The disclosed threat model assumes that the attacker cannot access the feature extractor, making the backdoor injection challenging. The disclosed technique injects targeted backdoor on raw packets that requires careful crafting of backdoor trigger packets without violating the underlying network protocol. Despite these challenges, the experiments demonstrate that the attacker can effectively backdoor the model by only contributing poisoned benign traffic during model training. The extensive evaluations of multiple network attack datasets, models, and feature extractors show that the disclosed backdoor injection technique performs well under various conditions. In particular, the attacker can successfully carry out the attack even with a poisoned dataset of 1% or less. Furthermore, this disclosure demonstrates that the attack cannot be easily detected when analyzed using activation-based clustering techniques.
[0251] FIG. 19 illustrates an example method 1900 for determining whether an IDS model is vulnerable. The method can begin at step 1910, where the computing system can access a plurality of network packets. At step 1920, the computing system can generate a plurality of backdoored packets by modifying statistics associated with the network packets. At step 1930, the computing system can execute a model configured for intrusion detection systems to classify the backdoored packets. At step 1940, the computing system can determine a misclassification accuracy associated with the classifying of the backdoored packets. At step 1950, the computing system can determine whether the model is vulnerable based on the misclassification accuracy. Certain non-limiting embodiments can repeat one or more steps of the method of FIG. 19, where appropriate. Although this disclosure describes and illustrates particular steps of the method of FIG. 19 as occurring in a particular order, this disclosure contemplates any suitable steps of the method of FIG. 19 occurring in any suitable order. Moreover, although this disclosure describes and illustrates an example method for determining whether an IDS model is vulnerable including the particular steps of the method of FIG. 19, this disclosure contemplates any suitable method for determining whether an IDS model is vulnerable including any suitable steps, which can include all, some, or none of the steps of the method of FIG. 19, where appropriate. Furthermore, although this disclosure 28
[0252] ACTIVE 126368586.1072396.1116
[0253] describes and illustrates particular components, devices, or systems carrying out particular steps of the method of FIG. 19, this disclosure contemplates any suitable combination of any suitable components, devices, or systems carrying out any suitable steps of the method of FIG.
[0254] 19.
[0255] FIG. 20 illustrates an example computer system 2000. In certain non-limiting embodiments, one or more computer systems 2000 perform one or more steps of one or more methods described or illustrated herein. In certain non-limiting embodiments, one or more computer systems 2000 provide functionality described or illustrated herein. In certain nonlimiting embodiments, software running on one or more computer systems 2000 performs one or more steps of one or more methods described or illustrated herein or provides functionality described or illustrated herein. Certain non-limiting embodiments include one or more portions of one or more computer systems 2000. Herein, reference to a computer system can encompass a computing device, and vice versa, where appropriate. Moreover, reference to a computer system can encompass one or more computer systems, where appropriate.
[0256] This disclosure contemplates any suitable number of computer systems 2000. This disclosure contemplates computer system 2000 taking any suitable physical form. As example and not by way of limitation, computer system 2000 can be an embedded computer system, a system-on-chip (SOC), a single-board computer system (SBC) (such as, for example, a computer-on-module (COM) or system-on-module (SOM)), a desktop computer system, a laptop or notebook computer system, an interactive kiosk, a mainframe, a mesh of computer systems, a mobile telephone, a personal digital assistant (PDA), a server, a tablet computer system, or a combination of two or more of these. Where appropriate, computer system 2000 can include one or more computer systems 2000; be unitary or distributed; span multiple locations; span multiple machines; span multiple data centers; or reside in a cloud, which can include one or more cloud components in one or more networks. Where appropriate, one or more computer systems 2000 can perform without substantial spatial or temporal limitation one or more steps of one or more methods described or illustrated herein. As an example and not by way of limitation, one or more computer systems 2000 can perform in real time or in batch mode one or more steps of one or more methods described or illustrated herein. One or more computer systems 2000 can perform at different times or at different locations one or more steps of one or more methods described or illustrated herein, where appropriate.
[0257] In certain non-limiting embodiments, computer system 2000 includes a processor 2002, memory 2004, storage 2006, an input / output (I / O) interface 2008, a communication interface 2010, and a bus 2012. Although this disclosure describes and illustrates a particular computer 29
[0258] ACTIVE 126368586.1072396.1116
[0259] system having a particular number of particular components in a particular arrangement, this disclosure contemplates any suitable computer system having any suitable number of any suitable components in any suitable arrangement.
[0260] In certain non-limiting embodiments, processor 2002 includes hardware for executing instructions, such as those making up a computer program. As an example and not by way of limitation, to execute instructions, processor 2002 can retrieve (or fetch) the instructions from an internal register, an internal cache, memory 2004, or storage 2006; decode and execute them; and then write one or more results to an internal register, an internal cache, memory 2004, or storage 2006. In certain non-limiting embodiments, processor 2002 can include one or more internal caches for data, instructions, or addresses. This disclosure contemplates processor 2002 including any suitable number of any suitable internal caches, where appropriate. As an example and not by way of limitation, processor 2002 can include one or more instruction caches, one or more data caches, and one or more translation lookaside buffers (TLBs). Instructions in the instruction caches can be copies of instructions in memory 2004 or storage 2006, and the instruction caches can speed up retrieval of those instructions by processor 2002. Data in the data caches can be copies of data in memory 2004 or storage 2006 for instructions executing at processor 2002 to operate on; the results of previous instructions executed at processor 2002 for access by subsequent instructions executing at processor 2002 or for writing to memory 2004 or storage 2006; or other suitable data. The data caches can speed up read or write operations by processor 2002. The TLBs can speed up virtual-address translation for processor 2002. In certain non-limiting embodiments, processor 2002 can include one or more internal registers for data, instructions, or addresses. This disclosure contemplates processor 2002 including any suitable number of any suitable internal registers, where appropriate. Where appropriate, processor 2002 can include one or more arithmetic logic units (ALUs); be a multi-core processor; or include one or more processors 2002. Although this disclosure describes and illustrates a particular processor, this disclosure contemplates any suitable processor.
[0261] In certain non-limiting embodiments, memory 2004 includes main memory for storing instructions for processor 2002 to execute or data for processor 2002 to operate on. As an example and not by way of limitation, computer system 2000 can load instructions from storage 2006 or another source (such as, for example, another computer system 2000) to memory 2004. Processor 2002 can then load the instructions from memory 2004 to an internal register or internal cache. To execute the instructions, processor 2002 can retrieve the instructions from the internal register or internal cache and decode them. During or after execution of the 30
[0262] ACTIVE 126368586.1072396.1116
[0263] instructions, processor 2002 can write one or more results (which can be intermediate or final results) to the internal register or internal cache. Processor 2002 can then write one or more of those results to memory 2004. In certain non-limiting embodiments, processor 2002 executes only instructions in one or more internal registers or internal caches or in memory 2004 (as opposed to storage 2006 or elsewhere) and operates only on data in one or more internal registers or internal caches or in memory 2004 (as opposed to storage 2006 or elsewhere). One or more memory buses (which can each include an address bus and a data bus) can couple processor 2002 to memory 2004. Bus 2012 can include one or more memory buses, as described below. In certain non-limiting embodiments, one or more memory management units (MMUs) reside between processor 2002 and memory 2004 and facilitate accesses to memory 2004 requested by processor 2002. In certain non-limiting embodiments, memory 2004 includes random access memory (RAM). This RAM can be volatile memory, where appropriate. Where appropriate, this RAM can be dynamic RAM (DRAM) or static RAM (SRAM). Moreover, where appropriate, this RAM can be single-ported or multi-ported RAM. This disclosure contemplates any suitable RAM. Memory 2004 can include one or more memories 2004, where appropriate. Although this disclosure describes and illustrates particular memory, this disclosure contemplates any suitable memory.
[0264] In certain non-limiting embodiments, storage 2006 includes mass storage for data or instructions. As an example and not by way of limitation, storage 2006 can include a hard disk drive (HDD), a floppy disk drive, flash memory, an optical disc, a magneto-optical disc, magnetic tape, or a Universal Serial Bus (USB) drive or a combination of two or more of these. Storage 2006 can include removable or non-removable (or fixed) media, where appropriate. Storage 2006 can be internal or external to computer system 2000, where appropriate. In certain non-limiting embodiments, storage 2006 is non-volatile, solid-state memory. In certain nonlimiting embodiments, storage 2006 includes read-only memory (ROM). Where appropriate, this ROM can be mask-programmed ROM, programmable ROM (PROM), erasable PROM (EPROM), electrically erasable PROM (EEPROM), electrically alterable ROM (EAROM), or flash memory or a combination of two or more of these. This disclosure contemplates mass storage 2006 taking any suitable physical form. Storage 2006 can include one or more storage control units facilitating communication between processor 2002 and storage 2006, where appropriate. Where appropriate, storage 2006 can include one or more storages 2006. Although this disclosure describes and illustrates particular storage, this disclosure contemplates any suitable storage.
[0265] 31
[0266] ACTIVE 126368586.1072396.1116
[0267] In certain non-limiting embodiments, I / O interface 2008 includes hardware, software, or both, providing one or more interfaces for communication between computer system 2000 and one or more I / O devices. Computer system 2000 can include one or more of these I / O devices, where appropriate. One or more of these I / O devices can enable communication between a person and computer system 2000. As an example and not by way of limitation, an I / O device can include a keyboard, keypad, microphone, monitor, mouse, printer, scanner, speaker, still camera, stylus, tablet, touch screen, trackball, video camera, another suitable I / O device or a combination of two or more of these. An I / O device can include one or more sensors. This disclosure contemplates any suitable I / O devices and any suitable I / O interfaces 2008 for them. Where appropriate, I / O interface 2008 can include one or more device or software drivers enabling processor 2002 to drive one or more of these I / O devices. I / O interface 2008 can include one or more I / O interfaces 2008, where appropriate. Although this disclosure describes and illustrates a particular I / O interface, this disclosure contemplates any suitable I / O interface.
[0268] In certain non-limiting embodiments, communication interface 2010 includes hardware, software, or both providing one or more interfaces for communication (such as, for example, packet-based communication) between computer system 2000 and one or more other computer systems 2000 or one or more networks. As an example and not by way of limitation, communication interface 2010 can include a network interface controller (NIC) or network adapter for communicating with an Ethernet or other wire-based network or a wireless NIC (WNIC) or wireless adapter for communicating with a wireless network, such as a WI-FI network. This disclosure contemplates any suitable network and any suitable communication interface 2010 for it. As an example and not by way of limitation, computer system 2000 can communicate with an ad hoc network, a personal area network (PAN), a local area network (LAN), a wide area network (WAN), a metropolitan area network (MAN), or one or more portions of the Internet or a combination of two or more of these. One or more portions of one or more of these networks can be wired or wireless. As an example, computer system 2000 can communicate with a wireless PAN (WPAN) (such as, for example, a BLUETOOTH WPAN), a WI-FI network, a WI-MAX network, a cellular telephone network (such as, for example, a Global System for Mobile Communications (GSM) network), or other suitable wireless network or a combination of two or more of these. Computer system 2000 can include any suitable communication interface 2010 for any of these networks, where appropriate. Communication interface 2010 can include one or more communication interfaces 2010, where
[0269] 32
[0270] ACTIVE 126368586.1072396.1116
[0271] appropriate. Although this disclosure describes and illustrates a particular communication interface, this disclosure contemplates any suitable communication interface.
[0272] In certain non-limiting embodiments, bus 2012 includes hardware, software, or both coupling components of computer system 2000 to each other. As an example and not by way of limitation, bus 2012 can include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a front-side bus (FSB), a HYPERTRANSPORT (HT) interconnect, an Industry Standard Architecture (ISA) bus, an INFINIBAND interconnect, a low-pin-count (LPC) bus, a memory bus, a Micro Channel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCIe) bus, a serial advanced technology attachment (SATA) bus, a Video Electronics Standards Association local (VLB) bus, or another suitable bus or a combination of two or more of these. Bus 2012 can include one or more buses 2012, where appropriate. Although this disclosure describes and illustrates a particular bus, this disclosure contemplates any suitable bus or interconnect.
[0273] Herein, a computer-readable non-transitory storage medium or media can include one or more semiconductor-based or other integrated circuits (ICs) (such, as for example, field-programmable gate arrays (FPGAs) or application-specific ICs (ASICs)), hard disk drives (HDDs), hybrid hard drives (HHDs), optical discs, optical disc drives (ODDs), magneto-optical discs, magneto-optical drives, floppy diskettes, floppy disk drives (FDDs), magnetic tapes, solid-state drives (SSDs), RAM-drives, SECURE DIGITAL cards or drives, any other suitable computer-readable non-transitory storage media, or any suitable combination of two or more of these, where appropriate. A computer-readable non-transitory storage medium can be volatile, non-volatile, or a combination of volatile and non-volatile, where appropriate.
[0274] Herein, “or” is inclusive and not exclusive, unless expressly indicated otherwise or indicated otherwise by context. Therefore, herein, “A or B” means “A, B, or both,” unless expressly indicated otherwise or indicated otherwise by context. Moreover, “and” is both joint and several, unless expressly indicated otherwise or indicated otherwise by context. Therefore, herein, “A and B” means “A and B, jointly or severally,” unless expressly indicated otherwise or indicated otherwise by context.
[0275] The scope of this disclosure encompasses all changes, substitutions, variations, alterations, and modifications to the example embodiments described or illustrated herein that a person having ordinary skill in the art would comprehend. The scope of this disclosure is not limited to the example embodiments described or illustrated herein. Moreover, although this disclosure describes and illustrates respective embodiments herein as including particular 33
[0276] ACTIVE 126368586.1072396.1116
[0277] components, elements, feature, functions, operations, or steps, any of these embodiments can include any combination or permutation of any of the components, elements, features, functions, operations, or steps described or illustrated anywhere herein that a person having ordinary skill in the art would comprehend. Furthermore, reference in the appended claims to an apparatus or system or a component of an apparatus or system being adapted to, arranged to, capable of, configured to, enabled to, operable to, or operative to perform a particular function encompasses that apparatus, system, component, whether or not it or that particular function is activated, turned on, or unlocked, as long as that apparatus, system, or component is so adapted, arranged, capable, configured, enabled, operable, or operative. Additionally, although this disclosure describes or illustrates certain non-limiting embodiments as providing particular advantages, certain non-limiting embodiments can provide none, some, or all of these advantages.
[0278] 34
[0279] ACTIVE 126368586.1
Claims
072396.1116CLAIMSWhat is claimed is:
1. A method comprising, by one or more computing systems:accessing a plurality of network packets;generating a plurality of backdoored packets by modifying statistics associated with the network packets;executing a model configured for intrusion detection systems to classify the backdoored packets;determining a misclassification accuracy associated with the classifying of the backdoored packets; anddetermining whether the model is vulnerable based on the misclassification accuracy.
2. The method of Claim 1, further comprising:accessing a user configuration; andtraining the model based on the user configuration using the backdoored packets.
3. The method of Claim 2, further comprising:determining the model is vulnerable based on the misclassification accuracy exceeding a threshold; andstoring, in a database, the user configuration associated with an indication that the model is vulnerable with respect to the user configuration.
4. The method of any one of Claims 1-3, further comprising:determining the model is vulnerable based on the misclassification accuracy exceeding a threshold.
5. The method of any one of Claims 1-4, wherein generating the plurality of backdoored packets comprises adding one or more backdoor trigger packets.
6. The method of Claim 5, further comprising:identifying one or more benign network packets from the plurality of network packets; and35ACTIVE 126368586.1072396.1116adding the one or more backdoor trigger packets to the one or more benign network packets.
7. The method of any one of Claims 1-6, wherein the plurality of network packets are transmitted from a source device to a destination device, and wherein generating the plurality of backdoored packets is based on a unidirectional transmission from the source device to the destination device.
8. The method of any one of Claims 1-7, wherein the plurality of network packets are transmitted in both directions between a source device and a destination device, and wherein generating the plurality of backdoored packets is based on a bidirectional transmission between the source device and the destination device.
9. The method of any one of Claims 1-8, wherein modifying the statistics associated with the network packets is based on an algorithm, and wherein the algorithm is associated with one or more control parameters comprising one or more of:a control parameter controlling a number of backdoor trigger packets to be added to the network packets;a control parameter specifying a delay between any two adjacent backdoor trigger packets; ora control parameter specifying a proportion of network packets to be backdoored.
10. The method of any one of Claims 1-9, wherein generating the plurality of backdoored packets comprises:extracting one or more parameter values corresponding to a user configuration; and determining whether to inject backdoor trigger packets based on the parameter values.
11. The method of any one of Claims 1-10, wherein generating the plurality of backdoored packets comprises:analyzing the network packets to determine statistics associated with the network packets; anddetermining, based on the statistics, one or more modifications for modifying the network packets.36ACTIVE 126368586.1072396.111612. The method of Claim 1, wherein the network packets comprise one or more of an Internet-of-Things (loT) data packet, a cyber-physical system (CPS) data packet, or a transmission control protocol (TCP) data packet.
13. One or more computer-readable non-transitory storage media embodying software that is operable when executed to:access a plurality of network packets;generate a plurality of backdoored packets by modifying statistics associated with the network packets;execute a model configured for intrusion detection systems to classify the backdoored packets;determine a misclassification accuracy associated with the classifying of the backdoored packets; anddetermine whether the model is vulnerable based on the misclassification accuracy.
14. The media of Claim 2013, wherein the software is further operable when executed to:access a user configuration; andtrain the model based on the user configuration using the backdoored packets.
15. The media of Claim 14, wherein the software is further operable when executed to: determine the model is vulnerable based on the misclassification accuracy exceeding a threshold; andstore, in a database, the user configuration associated with an indication that the model is vulnerable with respect to the user configuration.
16. The media of any one of Claims 13-15, wherein the software is further operable when executed to:determine the model is vulnerable based on the misclassification accuracy exceeding a threshold.
17. The media of any one of Claims 13-16, wherein generating the plurality of backdoored packets comprises adding one or more backdoor trigger packets.
18. The media of Claim 17, wherein the software is further operable when executed to:37ACTIVE 126368586.1072396.1116identify one or more benign network packets from the plurality of network packets; and add the one or more backdoor trigger packets to the one or more benign network packets.
19. The media of any one of Claims 13-18, wherein the plurality of network packets are transmitted from a source device to a destination device, and wherein generating the plurality of backdoored packets is based on a unidirectional transmission from the source device to the destination device.
20. The media of any one of Claims 13-19, wherein the plurality of network packets are transmitted in both directions between a source device and a destination device, and wherein generating the plurality of backdoored packets is based on a bidirectional transmission between the source device and the destination device.
21. The media of any one of Claims 13-20, wherein modifying the statistics associated with the network packets is based on an algorithm, and wherein the algorithm is associated with one or more control parameters comprising one or more of:a control parameter controlling a number of backdoor trigger packets to be added to the network packets;a control parameter specifying a delay between any two adjacent backdoor trigger packets; ora control parameter specifying a proportion of network packets to be backdoored.
22. The media of any one of Claims 13-21, wherein the software is further operable when executed to:extract one or more parameter values corresponding to a user configuration; and determine whether to inject backdoor trigger packets based on the parameter values.
23. The media of any one of Claims 13-22, wherein generating the plurality of backdoored packets comprises:analyzing the network packets to determine statistics associated with the network packets; anddetermining, based on the statistics, one or more modifications for modifying the network packets.38ACTIVE 126368586.1072396.111624. The media of any one of Claims 13-23, wherein the network packets comprise one or more of an Internet-of-Things (IoT) data packet, a cyber-physical system (CPS) data packet, or a transmission control protocol (TCP) data packet.
25. A system comprising: one or more processors; and a non-transitory memory coupled to the processors comprising instructions executable by the processors, the processors operable when executing the instructions to:access a plurality of network packets;generate a plurality of backdoored packets by modifying statistics associated with the network packets;execute a model configured for intrusion detection systems to classify the backdoored packets;determine a misclassification accuracy associated with the classifying of the backdoored packets; anddetermine whether the model is vulnerable based on the misclassification accuracy.
26. The system of Claim 2520, wherein the processors are further operable when executing the instructions to:access a user configuration; andtrain the model based on the user configuration using the backdoored packets.
27. The system of Claim 26, wherein the processors are further operable when executing the instructions to:determine the model is vulnerable based on the misclassification accuracy exceeding a threshold; andstore, in a database, the user configuration associated with an indication that the model is vulnerable with respect to the user configuration.
28. The system of any one of Claims 25-27, wherein the processors are further operable when executing the instructions to:determine the model is vulnerable based on the misclassification accuracy exceeding a threshold.39ACTIVE 126368586.1072396.111629. The system of any one of Claims 25-28, wherein generating the plurality of backdoored packets comprises adding one or more backdoor trigger packets.
30. The system of Claim 29, wherein the processors are further operable when executing the instructions to:identify one or more benign network packets from the plurality of network packets; and add the one or more backdoor trigger packets to the one or more benign network packets.
31. The system of any one of Claims 25-30, wherein the plurality of network packets are transmitted from a source device to a destination device, and wherein generating the plurality of backdoored packets is based on a unidirectional transmission from the source device to the destination device.
32. The system of any one of Claims 25-31, wherein the plurality of network packets are transmitted in both directions between a source device and a destination device, and wherein generating the plurality of backdoored packets is based on a bidirectional transmission between the source device and the destination device.
33. The system of any one of Claims 25-32, wherein modifying the statistics associated with the network packets is based on an algorithm, and wherein the algorithm is associated with one or more control parameters comprising one or more of:a control parameter controlling a number of backdoor trigger packets to be added to the network packets;a control parameter specifying a delay between any two adjacent backdoor trigger packets; ora control parameter specifying a proportion of network packets to be backdoored.
34. The system of any one of Claims 25-33, wherein the processors are further operable when executing the instructions to:extract one or more parameter values corresponding to a user configuration; and determine whether to inject backdoor trigger packets based on the parameter values.40ACTIVE 126368586.1072396.111635. The system of any one of Claims 25-34, wherein generating the plurality of backdoored packets comprises:analyzing the network packets to determine statistics associated with the network packets; anddetermining, based on the statistics, one or more modifications for modifying the network packets.
36. The system of any one of Claims 25-35, wherein the network packets comprise one or more of an Internet-of-Things (IoT) data packet, a cyber-physical system (CPS) data packet, or a transmission control protocol (TCP) data packet.41ACTIVE 126368586.1