Robustness and Defense of Anomaly Detection Model Against Adversarial Attack
Adversarial Attack, Black-box Attack, Tabular Data, Hyperparameter Tuning Algorithm, Outlier Detection
研究[1, 2]指出此類模型容易受到對抗式攻擊影響,攻擊者能擾動偵測結果甚至操弄預
發人員誤用後該系統將暴露於威脅中。滲透測試(Penetration Test, PT)模擬攻擊者
本研究提出基於真實企業 Active Directory(AD)事件記錄檔的可循環對抗式樣本
As the amount of data kept expanding, the era of big data has come. Artificial
intelligence (AI)-related technologies, including machine learning, deep learning, natural
language processing, have been applied to anomaly detection and many other application
fields and achieved efficient solutions. Comparing with human expert, AI approaches are
more suitable for solving complicated problems with repetitions. However, according to the
previous research [1, 2], deep learning models are vulnerable to adversarial attacks, where
an adversary manipulates the outcomes of a detection model by inserting adversarial samples.
Once the adversary exploits the vulnerability of the core algorithm of the target model, the
integrity and correctness of the model might be at risk.
To accelerate the development process of information system and support by theory,
system developer intends to use open source including labeled dataset, pre-trained model,
library and code published by other scholars. If these open resources have been contaminated
by cyber attacker, it will affect the practical system security. Fortunately, penetration testing
can simulate cyber-attack against the target system. With the hacking drill, it’s the most direct
way to help developer find out the exploitable vulnerabilities and keep target system away
from the threats.
This study proposes a cyclic adversarial sample training method based on real-world
Active Directory event log and it’s inspired by black-box attack. In order to challenge welldesigned anomaly detection system and find out the potential weakness of the target system,
the method proposed by this study train strong perturbative adversarial samples under the
specification of the event log. The experimental results provide the trained adversarial
samples can attack target system successfully and the attack achievement is better than other
studies performed. At the end of the paper, this study will provide an ingenious method
inspired by the attack process to truly improve the robustness of the anomaly detection
