{"id":"https://openalex.org/W4224329237","doi":"https://doi.org/10.48550/arxiv.2204.06113","title":"Liuer Mihou: A Practical Framework for Generating and Evaluating Grey-box Adversarial Attacks against NIDS","display_name":"Liuer Mihou: A Practical Framework for Generating and Evaluating Grey-box Adversarial Attacks against NIDS","publication_year":2022,"publication_date":"2022-01-01","ids":{"openalex":"https://openalex.org/W4224329237","doi":"https://doi.org/10.48550/arxiv.2204.06113"},"language":"en","primary_location":{"is_oa":true,"landing_page_url":"https://arxiv.org/abs/2204.06113","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"submittedVersion","is_accepted":false,"is_published":false},"type":"preprint","type_crossref":"posted-content","indexed_in":["arxiv","datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/abs/2204.06113","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5071390331","display_name":"Ke He","orcid":"https://orcid.org/0000-0001-5585-6859"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"He, Ke","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5019789320","display_name":"Dong Seong Kim","orcid":"https://orcid.org/0000-0003-2605-187X"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Kim, Dan Dongseong","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5000934031","display_name":"Jing Sun","orcid":"https://orcid.org/0000-0002-1979-6622"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Sun, Jing","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5090433388","display_name":"Jeong Yoo","orcid":"https://orcid.org/0000-0002-4269-6953"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Yoo, Jeong Do","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101639503","display_name":"Young Hun Lee","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Lee, Young Hun","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5091602017","display_name":"Huy Kang Kim","orcid":"https://orcid.org/0000-0002-0760-8807"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Kim, Huy Kang","raw_affiliation_strings":[],"affiliations":[]}],"institution_assertions":[],"countries_distinct_count":0,"institutions_distinct_count":0,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":2,"citation_normalized_percentile":{"value":0.826057,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":70,"max":75},"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9966,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9948,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/testbed","display_name":"Testbed","score":0.61412394},{"id":"https://openalex.org/keywords/transferability","display_name":"Transferability","score":0.6122157},{"id":"https://openalex.org/keywords/feature","display_name":"Feature (linguistics)","score":0.43658733}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.9365636},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.83296293},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.6805341},{"id":"https://openalex.org/C31395832","wikidata":"https://www.wikidata.org/wiki/Q1318674","display_name":"Testbed","level":2,"score":0.61412394},{"id":"https://openalex.org/C61272859","wikidata":"https://www.wikidata.org/wiki/Q7834031","display_name":"Transferability","level":3,"score":0.6122157},{"id":"https://openalex.org/C158379750","wikidata":"https://www.wikidata.org/wiki/Q214111","display_name":"Network packet","level":2,"score":0.55759686},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.50177264},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.4684413},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.46312153},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.4403024},{"id":"https://openalex.org/C2776401178","wikidata":"https://www.wikidata.org/wiki/Q12050496","display_name":"Feature (linguistics)","level":2,"score":0.43658733},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.35077402},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.15836033},{"id":"https://openalex.org/C41895202","wikidata":"https://www.wikidata.org/wiki/Q8162","display_name":"Linguistics","level":1,"score":0.0},{"id":"https://openalex.org/C138885662","wikidata":"https://www.wikidata.org/wiki/Q5891","display_name":"Philosophy","level":0,"score":0.0},{"id":"https://openalex.org/C140331021","wikidata":"https://www.wikidata.org/wiki/Q1868104","display_name":"Logit","level":2,"score":0.0}],"mesh":[],"locations_count":3,"locations":[{"is_oa":true,"landing_page_url":"https://arxiv.org/abs/2204.06113","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"submittedVersion","is_accepted":false,"is_published":false},{"is_oa":true,"landing_page_url":"http://arxiv.org/abs/2204.06113","pdf_url":"http://arxiv.org/pdf/2204.06113","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false},{"is_oa":false,"landing_page_url":"https://api.datacite.org/dois/10.48550/arxiv.2204.06113","pdf_url":null,"source":{"id":"https://openalex.org/S4393179698","display_name":"DataCite API","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":"https://openalex.org/I4210145204","host_organization_name":"DataCite","host_organization_lineage":["https://openalex.org/I4210145204"],"host_organization_lineage_names":["DataCite"],"type":"metadata"},"license":null,"license_id":null,"version":null}],"best_oa_location":{"is_oa":true,"landing_page_url":"https://arxiv.org/abs/2204.06113","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"submittedVersion","is_accepted":false,"is_published":false},"sustainable_development_goals":[{"score":0.67,"id":"https://metadata.un.org/sdg/16","display_name":"Peace, justice, and strong institutions"}],"grants":[],"datasets":[],"versions":[],"referenced_works_count":0,"referenced_works":[],"related_works":["https://openalex.org/W4392340763","https://openalex.org/W4390585229","https://openalex.org/W4377864639","https://openalex.org/W4288055406","https://openalex.org/W4283325551","https://openalex.org/W4226402597","https://openalex.org/W4200630034","https://openalex.org/W3137894200","https://openalex.org/W3132910851","https://openalex.org/W3092178728"],"abstract_inverted_index":{"Due":[0],"to":[1,31,38,46,83,125,142,203],"its":[2],"high":[3],"expressiveness":[4],"and":[5,41,86,100,129,160,162,223],"speed,":[6],"Deep":[7],"Learning":[8],"(DL)":[9],"has":[10],"become":[11],"an":[12],"increasingly":[13],"popular":[14],"choice":[15],"as":[16],"the":[17,39,43,48,54,59,93,112,148,163,168,181,195,205,226],"detection":[18,186],"algorithm":[19,45],"for":[20],"Network-based":[21],"Intrusion":[22],"Detection":[23],"Systems":[24],"(NIDSes).":[25],"Unfortunately,":[26],"DL":[27,44],"algorithms":[28,156],"are":[29],"vulnerable":[30],"adversarial":[32,51,88,102,127,131,182,196,216,230],"examples":[33],"that":[34,97,105,213],"inject":[35],"imperceptible":[36],"modifications":[37],"input":[40],"cause":[42],"misclassify":[47],"input.":[49],"Existing":[50],"attacks":[52],"in":[53,74,111,198],"NIDS":[55,109,136],"domain":[56],"often":[57],"manipulate":[58],"traffic":[60,69],"features":[61,70],"directly,":[62],"which":[63],"hold":[64],"no":[65],"practical":[66,85,99],"significance":[67],"because":[68],"cannot":[71,218],"be":[72],"replayed":[73],"a":[75,80,134,190,199],"real":[76,200],"network.":[77],"It":[78],"remains":[79],"research":[81],"challenge":[82],"generate":[84,130],"evasive":[87],"attacks.":[89],"This":[90],"paper":[91],"presents":[92],"Liuer":[94,122,151,208,221],"Mihou":[95,123,152,222],"attack":[96,197],"generates":[98],"replayable":[101],"network":[103],"packets":[104,132],"can":[106],"bypass":[107],"anomaly-based":[108],"deployed":[110],"Internet":[113],"of":[114,150,170,184,207,228],"Things":[115],"(IoT)":[116],"networks.":[117],"The":[118],"core":[119],"idea":[120],"behind":[121],"is":[124],"exploit":[126],"transferability":[128,183],"on":[133,180],"surrogate":[135],"constrained":[137],"by":[138],"predefined":[139],"mutation":[140],"operations":[141],"ensure":[143],"practicality.":[144],"We":[145],"objectively":[146],"analyse":[147],"evasiveness":[149],"against":[153,220],"four":[154],"ML-based":[155],"(LOF,":[157],"OCSVM,":[158],"RRCF,":[159],"SOM)":[161],"state-of-the-art":[164],"NIDS,":[165],"Kitsune.":[166],"From":[167],"results":[169],"our":[171],"experiment,":[172],"we":[173,193,211],"gain":[174],"valuable":[175],"insights":[176],"into":[177],"necessary":[178],"conditions":[179],"anomaly":[185],"algorithms.":[187],"Going":[188],"beyond":[189],"theoretical":[191],"setting,":[192],"replay":[194],"IoT":[201],"testbed":[202],"examine":[204],"practicality":[206],"Mihou.":[209],"Furthermore,":[210],"demonstrate":[212],"existing":[214],"feature-level":[215,229],"defence":[217],"defend":[219],"constructively":[224],"criticise":[225],"limitations":[227],"defences.":[231]},"abstract_inverted_index_v3":null,"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W4224329237","counts_by_year":[{"year":2024,"cited_by_count":1},{"year":2023,"cited_by_count":1}],"updated_date":"2025-02-20T09:29:23.061857","created_date":"2022-04-26"}