Introducing Perturb-ability Score (PS) to Enhance Robustness Against
Evasion Adversarial Attacks on ML-NIDS
- AAML

Main:15 Pages
13 Figures
Bibliography:2 Pages
Appendix:4 Pages
Abstract
This paper proposes a novel Perturb-ability Score (PS) that can be used to identify Network Intrusion Detection Systems (NIDS) features that can be easily manipulated by attackers in the problem-space. We demonstrate that using PS to select only non-perturb-able features for ML-based NIDS maintains detection performance while enhancing robustness against adversarial attacks.
View on arXivComments on this paper
