[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-120648-en":3,"doc-seo-120648-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},120648,1099513958607,"Jiven","https://ap-avatar.wpscdn.com/avatar/100002390cf8733938c?x-image-process=image/resize,m_fixed,w_180,h_180&k=1778829742770036399",8,"Research & Report","Defending against Adversarial Machine Learning Attacks using Hierarchical Learning - A case study on Network Traffic Attack Classification","Machine learning supports automated detection of malicious network activity to protect organizations from cyber security attacks. Adversarial machine learning studies how an adversary can manipulate inputs to force misclassification, a risk that applies beyond vision to network traffic analysis. The study investigates adversarial attacks against a well-trained network traffic classification model, showing adversarial examples that mislabel known attacks as benign. A hierarchical learning defense reduces the exploitable attack surface within the intended parameter constraints, preserving robustness and maintaining accuracy under non-attack conditions.","Defending against Adversarial Machine Learning Attacks using Hierarchical Learning: A case study on Network Traffic Attack Classification  \nAndrew McCarthya , Essam Ghadafia , Panagiotis Andriotisa , Phil Leggaa Computer Science Research Centre, University of the West of England, Bristol, UK  \nAbstract  \nMachine learning is key for automated detection of malicious network activity to ensure that computer networks and organizations are protected against cyber security attacks. Recently, there has been growing interest in the domain of adversarial machine learning, which explores how a machine learning model can be compromised by an adversary, resulting in misclassified output. Whilst to date, most focus has been given to visual domains, the challenge is present in all applications of machine learning where a malicious attacker would want to cause unintended functionality, including cyber security and network traffic analysis. We first present a study on conducting adversarial attacks against a well-trained network traffic classification model. We show how well-crafted adversarial examples can be constructed so that known attack types are misclassified by the model as benign activity. To combat this, we present a novel defensive strategy based on hierarchical learning to help reduce the attack surface that an adversarial example can exploit within the constraints of the parameter space of the intended attack. Our results show that our defensive learning model can withstand crafted adversarial attacks and can achieve classification accuracy in line with our original model when not under attack.  \nKeywords: adversarial learning, hierarchical classification, network traffic analysis, functionality preservation, machine learning, model robustness  \n1. Introduction  \nCyber security and the protection of associated computer and network systems is fundamental for most organizations. The recent Cyber Security  \nPreprint submitted to Journal of Information Security and ApplicationsDecember 6, 2022  \nBreaches survey 2022 conducted by the UK Government found that 39% businesses had experienced a cyber attack in the last 12 months, with the average cost of a cyber attack currently estimated as £2.2 million [1] . The sheer scale and magnitude of modern cyber attacks requires automated response and intervention. Machine learning (ML) is becoming widely used for the detection and classification of malicious network activity to aid the response to cyber attacks, where a mathematical model is learned to relate input feature observations to a set of possible output classes. For the classification of network traffic attacks, input features may be derived from the observed network communications and packet header information, which maybe indicative of either benign traffic, or a malicious attack such as a Denial of Service, a Remote Access Trojan, a BotNet, or other network-based attack.  \nWhilst machine learning can help manage this wealth of information, it is not without limitation. Recent years have seen a growing interest in the domain of adversarial machine learning [2] that seeks to identify well-crafted examples that knowingly force misclassification by the model. This has been particularly effective in the computer vision domain since the manipulation of few input features (i.e., image pixels) may inadvertently adjust the performance of the model without being noticeable to the human observer, due to small perturbations of pixel intensity values. The challenge in adversarial learning is to determine which features are most susceptible such that a minimal change can result in misclassification by the model, whilst the overall input to the model appears unchanged or unaltered to the human observer. Drawing a parallel to the challenge of network traffic classification, a malicious attack should exhibit the same characteristics such that the activity is still deemed as malicious, whilst identifying the minimal amount of perturbation in the der","cbCairB2fA3Hdw6r","https://ap.wps.com/l/cbCairB2fA3Hdw6r","pdf",7263838,1,36,"English","en",105,"# Introduction\n## Cyber security context and ML-based traffic classification\n## Adversarial machine learning and functionality preservation\n## Paper contributions\n# Related Work\n# Adversarial Attack Study\n# Hierarchical Learning Defense\n# Discussion","[{\"question\":\"What problem does adversarial machine learning target in network traffic classification?\",\"answer\":\"It targets the model’s ability to classify traffic correctly by crafting inputs that cause misclassification, such as turning known malicious activities into outputs labeled as benign.\"},{\"question\":\"How do the authors define functionality preservation in adversarial attacks?\",\"answer\":\"Functionality preservation refers to keeping the attack’s essential malicious characteristics while introducing minimal perturbations in the derived features so the model still believes the observation is benign.\"},{\"question\":\"What defense strategy is proposed to counter adversarial network attacks?\",\"answer\":\"The paper proposes a defensive strategy based on hierarchical learning to reduce the attack surface an adversarial example can exploit while staying within the constraints of the intended attack’s parameter space.\"}]","Defending against Adversarial Machine Learning Attacks using Hierarchical Learning - A case study on Network Traffic Attack Classification | PDF",1785731157,91,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"defending-against-adversarial-machine-learning-attacks-using-hierarchical-learning-a-case-study-on-network-traffic-attack-classification","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/defending-against-adversarial-machine-learning-attacks-using-hierarchical-learning-a-case-study-on-network-traffic-attack-classification/120648/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-03",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does adversarial machine learning target in network traffic classification?","Question",{"text":75,"@type":76},"It targets the model’s ability to classify traffic correctly by crafting inputs that cause misclassification, such as turning known malicious activities into outputs labeled as benign.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How do the authors define functionality preservation in adversarial attacks?",{"text":80,"@type":76},"Functionality preservation refers to keeping the attack’s essential malicious characteristics while introducing minimal perturbations in the derived features so the model still believes the observation is benign.",{"name":82,"@type":73,"acceptedAnswer":83},"What defense strategy is proposed to counter adversarial network attacks?",{"text":84,"@type":76},"The paper proposes a defensive strategy based on hierarchical learning to reduce the attack surface an adversarial example can exploit while staying within the constraints of the intended attack’s parameter space.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]