The broadcast nature of wireless communications and the widespread adoption of connected things increase attack surfaces and enable attackers to launch several cyber-attacks. Moreover, the increasing adoption of machine learning (ML) in many applications, including wireless communications, introduces new risks and vulnerabilities. Adversarial attacks craft and introduce small perturbations that fool ML models into making wrong decisions. Hence, they may compromise wireless communications tasks based on ML and jeopardize communication availability and connected objects’ security. Therefore, cyber-attacks and adversarial attacks may compromise security goals, causing severe damage and financial losses and even putting people’s lives at risk.
In this thesis, we advance the state-of-the-art in the security field by considering both the cyber-attacks and adversarial attacks problems. We enhance the security of connected objects by effectively and efficiently detecting cyber-attacks while defending systems that rely on machine learning from adversarial attacks.
In Chapter 2, we verify that while supervised ML-based intrusion detection system (IDS) cannot detect unknown attacks and require labeled training data, which is time-consuming, challenging, and sometimes impossible to obtain, unsupervised approaches usually present high false positive rates that cause service disruptions and derail security operation centers (SOCs). Moreover, we verify that most unsupervised IDSs struggle with the time required to model highly complex and heterogeneous systems so that they cannot detect cyber-attacks quickly enough to stop them before damage is caused. Thus, we propose a novel unsupervised IDS that detects known and unknown attacks using generative adversarial networks (GANs). Our approach combines the GAN discriminator’s output with a reconstruction loss that evaluates whether data samples comply with the training samples. It trains an encoder neural network that accelerates the reconstruction loss computation, significantly reducing detection times compared to state-of-the-art approaches.
Since many attacks have multiple steps and are launched from different applications and devices, Chapter 3 concerns different strategies for considering time dependencies among data in the detection of cyber-attacks. We verify that while most of the existing IDSs rely on long short-term memory (LSTM) networks, recent studies show that they present several drawbacks that increase detection times, such as a limited capacity to parallelize computations. Thus, we propose a novel unsupervised GAN-Based IDS that uses temporal convolutional networks (TCNs) and self-attention to replace LSTM networks for considering time dependencies among data. Our proposed approach successfully replaces LSTM networks for attack detection and achieves better detection results. Moreover, it allows different configurations of TCN and self-attention layers to achieve different trade-offs between detection rates and detection times and satisfy different requirements.
In contrast to Chapters 2 and 3, Chapter 4 concerns adversarial attacks that compromise modulation classifiers in wireless receivers, jeopardizing the availability of wireless communications. We verify that the existing adversarial attack techniques either require complete knowledge about the classifier’s model, which is an unrealistic assumption, or take too long to craft adversarial perturbations, such that they cannot tamper with the received modulated signals. Thus, we propose a novel black-box adversarial attack technique that reduces the accuracy of modulation classifiers more than other black-box adversarial attacks and crafts adversarial perturbations significantly faster than them. Our proposed technique is essential for assessing the risks of using machine learning-based modulation classifiers in wireless communications.
Finally, given the risks and damage that adversarial attacks may cause, Chapter 5 focuses on studying defense techniques against such sophisticated threats. We verify that only a few defense techniques exist for protecting modulation classifiers from them, most of which only marginally reduce their impact on the classifier’s accuracy. Therefore, we propose a defense technique for protecting modulation classifiers from adversarial attacks so that those attacks do not harm the availability of wireless communications. Our proposed approach detects and removes adversarial perturbations while reducing the sensitivity of machine learning-based classifiers to them. Hence, it successfully diminishes the accuracy reduction caused by different adversarial attack techniques.
| Date | 30 Mar 2023 |
|---|
| Original language | American English |
|---|
| Awarding Institution | - École de technologie supérieure
|
|---|
| Supervisor | Georges Kaddoum (Supervisor) & Divanilson R. Campelo (Co-supervisor) |
|---|
Freitas de Araujo Filho, P. (Author),
Kaddoum (Supervisor) & Campelo (Co-supervisor),
30 Mar 2023Student thesis: Doctoral thesis › Doctorate in Engineering: Engineering