[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-145598-en":3,"doc-seo-145598-105":31,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":28,"seo_description":14,"update_tm":29,"read_time":30},145598,1099523882367,"Jordan Avery","https://ap-avatar.wpscdn.com/davatar_9964176cb1d06d4a9deccf72a44ae3dc",6,"Technology","A Network Security Classifier Defense - Against Adversarial Machine Learning Attacks","Practical adversarial machine learning attacks against machine learning-based wired and wireless network security detectors create a direct need for effective defensive mechanisms. Without AML-aware defenses, classifier outputs can be evaded, allowing malicious activity to go unnoticed and reducing overall detector effectiveness. Existing AML defenses largely target image recognition and do not transfer well to network security, where features are derived by domain experts. This work presents a defense-in-depth hierarchical ensemble for robust detection and discusses feature discovery for scanning activity.","A Network Security Classifier Defense:  \nAgainst Adversarial Machine Learning Attacks  \nMichael J. De Lucia  \nNetwork Science Division U.S. Army Research Laboratory Aberdeen Proving Ground, MD [michael.j.delucia2.civ@mail.mil](michael.j.delucia2.civ@mail.mil)  \nChase Cotton  \nDepartment of Electrical and Computer Engineering University of Delaware Newark, DE[ccotton@udel.edu](ccotton@udel.edu)  \nABSTRACT  \nThe discovery of practical adversarial machine learning (AML) attacks against machine learning-based wired and wireless network security detectors has driven the necessity of a defense. Without a defense mechanism against AML, attacks in wired and wireless networks will go unnoticed by network security classifiers resulting in their ineffectiveness. Therefore, it is essential to motivate a defense against AML attacks for network security classifiers. Existing AML defenses are generally within the context of image recognition. However, these AML defenses have limited transferability to a network security context. Unlike image recognition, a subject matter expert generally derives the features of a network security classifier. Therefore, a network security classifier requires a distinctive strategy for defense. We propose a novel defense-in-depth approach for network security classifiers using a hierarchical ensemble of classifiers, each using a disparate feature set. Subsequently we show the effective use of our hierarchical ensemble to defend an existing network security classifier against an AML attack. Additionally, we discover a novel set of features to detect network scanning activity. Lastly, we propose to enhance our AML defense approach in future work. A shortcoming of our approach is the increased cost to the defender for implementation of each independent classifier. Therefore, we propose combining our AML defense with a moving target defense approach. Additionally, we propose to evaluate our AML defense with a variety of datasets and classifiers and evaluate the effectiveness of decomposing aclassifier with many features into multiple classifiers, each with a small subset of the features.  \nACM acknowledges that this contribution was authored or co-authored by an employee, contractor, or affiliate of the United States government. As such, the United States government retains a nonexclusive, royalty-free right to publish or reproduce this article, or to allow others to do so, for Government purposes only.  \nWiseML '20, July 13, 2020, Linz (Virtual Event), Austria © 2020 Association for Computing Machinery.  \nACM ISBN 978-1-4503-8007-2/20/07   $15 .00 [https://doi.org/10.1145/3395352](https://doi.org/10.1145/3395352) .  \nCCS CONCEPTS  \n• Security and privacy~Intrusion/anomaly detection and malware mitigation~Intrusion detection systems • Security and privacy~Network security • Computing methodologies~Machine learning~Machine learning algorithms~Ensemble methods  \nKEYWORDS  \nAdversarial Machine Learning, Machine Learning, Network Security, Cyber Security, Cyber Defense  \nACM Reference format:  \nMichael J. De Lucia and Chase Cotton. 2020. A Network Security Classifier Defense: Against Adversarial Machine Learning Attacks. In Proceedings ofACM Workshop on Wireless Security Machine Learning (WiseML ’20). ACM, New York, NY, USA, 6 pages.  \n1 Introduction  \nThe discovery of practical adversarial machine learning (AML) attacks against machine learning-based wired and wireless network security detectors has driven the necessity of a defense. Without a defense mechanism against AML, attacks in wired and wireless networks will go unnoticed by network security classifiers resulting in their ineffectiveness. Therefore, it is essential to motivate a defense against AML attacks for network security classifiers.  \nAn increased reliance on the use of machine learning in network security detectors stimulates the risk of adversarial employment of AML, to evade detection. Historically, traditional network security detectors have encoun","cbCaivNSAerAWTyN","https://ap.wps.com/l/cbCaivNSAerAWTyN","pdf",373940,2,1,7,"English","en",105,"# 1 Introduction\n# 2 Related Work\n# 3 Background\n# 4 Proposed Defense and Evaluation\n# 5 Conclusion and Future Work","[{\"question\":\"Why are defenses needed for network security classifiers against adversarial machine learning (AML) attacks?\",\"answer\":\"AML attacks can evade wired and wireless network security detectors, causing their ineffectiveness because malicious traffic goes unnoticed by the classifiers.\"},{\"question\":\"How does the proposed approach differ from common AML defenses used in image recognition?\",\"answer\":\"The method targets network security classifiers where feature sets are derived by subject matter experts, requiring a distinctive defense strategy instead of relying on defenses designed for image recognition.\"},{\"question\":\"What are the main contributions of the proposed defense?\",\"answer\":\"It introduces a defense-in-depth hierarchical ensemble using disparate feature sets, evaluates it against an existing network security classifier under an AML attack, and identifies new features for detecting network scanning activity.\"}]","A Network Security Classifier Defense - Against Adversarial Machine Learning Attacks | PDF",1787725621,18,{"code":4,"msg":32,"data":33},"ok",{"site_id":25,"language":24,"slug":34,"title":13,"keywords":35,"description":14,"schema_data":36,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":29},"a-network-security-classifier-defense-against-adversarial-machine-learning-attacks","",{"@graph":37,"@context":86},[38,54,69],{"@type":39,"itemListElement":40},"BreadcrumbList",[41,45,48,51],{"item":42,"name":43,"@type":44,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":46,"name":47,"@type":44,"position":20},"https://docshare.wps.com/document/","Document",{"item":49,"name":12,"@type":44,"position":50},"https://docshare.wps.com/document/technology/",3,{"item":52,"name":13,"@type":44,"position":53},"https://docshare.wps.com/document/a-network-security-classifier-defense-against-adversarial-machine-learning-attacks/145598/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":24,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":42,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-31","2026-08-26",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"Why are defenses needed for network security classifiers against adversarial machine learning (AML) attacks?","Question",{"text":76,"@type":77},"AML attacks can evade wired and wireless network security detectors, causing their ineffectiveness because malicious traffic goes unnoticed by the classifiers.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"How does the proposed approach differ from common AML defenses used in image recognition?",{"text":81,"@type":77},"The method targets network security classifiers where feature sets are derived by subject matter experts, requiring a distinctive defense strategy instead of relying on defenses designed for image recognition.",{"name":83,"@type":74,"acceptedAnswer":84},"What are the main contributions of the proposed defense?",{"text":85,"@type":77},"It introduces a defense-in-depth hierarchical ensemble using disparate feature sets, evaluates it against an existing network security classifier under an AML attack, and identifies new features for detecting network scanning activity.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":93},[94,98,102,106,111,114,118,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":47,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":47,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":47,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":107,"doc_module":4,"doc_module_name":47,"category_name":108,"show_sort_weight":109,"slug":110},5,"Comic",60,"comic",{"id":11,"doc_module":4,"doc_module_name":47,"category_name":12,"show_sort_weight":112,"slug":113},50,"technology",{"id":22,"doc_module":4,"doc_module_name":47,"category_name":115,"show_sort_weight":116,"slug":117},"Healthcare",40,"healthcare",{"id":119,"doc_module":4,"doc_module_name":47,"category_name":120,"show_sort_weight":121,"slug":122},8,"Research & Report",30,"research-report",{"id":124,"doc_module":4,"doc_module_name":47,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":47,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":47,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":47,"category_name":137,"show_sort_weight":107,"slug":138},19,"General","general"]