DOI: https://doi.org/10.1038/s41598-026-48715-9
PMID: https://pubmed.ncbi.nlm.nih.gov/42115644
تاريخ النشر: 2026-05-11
المؤلف: Uzma Ghulam Mohammad وآخرون
الموضوع الرئيسي: الصلابة ضد الهجمات في تعلم الآلة
نظرة عامة
تقدم الورقة البحثية نهجًا جديدًا لتعزيز اكتشاف هجمات حجب الخدمة الموزعة (DDoS) في بيئات إنترنت الأشياء (IoT) من خلال معالجة الثغرات في أنظمة الأمان المعتمدة على التعلم الآلي الحالية. يقدم المؤلفون مجموعة بيانات AdvCICDDoS2019، التي تتضمن أربعة أنواع من الهجمات العدائية – الاضطراب العدائي (AP)، حقن القيم الشاذة العدائية (AOI)، حقن الضوضاء العدائية (ANI)، والعدائية الحميدة (AB) – في مجموعة بيانات CICDDoS2019 الأصلية. يستخدم الإطار المقترح الشبكات العصبية البيانية (GNNs) والشبكات العصبية العميقة (DNNs) جنبًا إلى جنب مع تقنيات التدريب العدائي، وتحديدًا طريقة DeepFool وطريقة أول تدرج (FGSM)، لتحسين دقة الاكتشاف والصلابة ضد الهجمات التكيفية. تظهر النتائج التجريبية أن الإطار يحقق معدلات دقة اكتشاف تصل إلى 97%، متفوقًا بشكل كبير على الطرق التقليدية بنسبة تتراوح بين 4% إلى 12% عبر سيناريوهات هجوم مختلفة.
على الرغم من أدائه القوي، تعترف الدراسة بعدة قيود، بما في ذلك الطبيعة الاصطناعية للهجمات العدائية في مجموعة البيانات والتحديات التي تطرحها ظروف التقييم الثابتة. تهدف الأعمال المستقبلية إلى تعزيز مجموعة البيانات بمحاكاة عدائية ديناميكية في الوقت الحقيقي ودمج نماذج التعلم الزمني المتقدمة وتقنيات التدريب العدائي. بالإضافة إلى ذلك، يخطط المؤلفون لاستكشاف أطر التعلم الفيدرالي لتسهيل اكتشاف التسلل عن بُعد مع الحفاظ على أمان البيانات وخصوصيتها. كما يُقترح دمج تقنيات الذكاء الاصطناعي القابلة للتفسير (XAI) المتقدمة لتحسين القابلية للتفسير وتوفير رؤى أعمق في عمليات اتخاذ القرار للنماذج.
مقدمة
تسلط المقدمة الضوء على النمو السريع لإنترنت الأشياء (IoT) على مدار العقد الماضي، مع التأكيد على تأثيره التحويلي على مختلف القطاعات مثل النقل، والمدن الذكية، وأنظمة الطاقة، وبناء المنازل. تسهل هذه الزيادة في الأجهزة المتصلة الأتمتة ونقل البيانات؛ ومع ذلك، فإنها تعرض أيضًا ثغرات أمنية كبيرة. تفتقر العديد من أجهزة إنترنت الأشياء إلى ميزات الأمان المدمجة ويتم نشرها في بيئات ذات موارد حسابية محدودة، مما يجعلها عرضة للهجمات الإلكترونية.
من بين التهديدات المختلفة، تشكل هجمات حجب الخدمة الموزعة (DDoS) تحديًا كبيرًا بسبب العدد الكبير وطبيعة أنظمة إنترنت الأشياء. تهدف هذه الهجمات إلى تعطيل الوصول المصرح به إلى أجهزة وخدمات إنترنت الأشياء من خلال إغراق موارد الشبكة. يمكن أن تكون تداعيات مثل هذه الهجمات شديدة، خاصة في القطاعات الحيوية مثل الرعاية الصحية، حيث يمكن أن تعيق هجمة DDoS تسليم البيانات الطبية، مما يؤدي إلى علاجات غير صحيحة أو استجابات متأخرة. علاوة على ذلك، يمكن أن تكون العواقب الاقتصادية لهجمات DDoS كبيرة، خاصة في البيئات الصناعية حيث يمكن أن تعطل عمليات الإنتاج.
طرق
يستعرض قسم “الطرق” المنهجية المستخدمة في الدراسة، بدءًا من وصف مجموعة البيانات وخطوات المعالجة المسبقة، تليها تطبيق نماذج التعلم العميق (DL). تخضع مجموعة بيانات DDoS، الممثلة بـ \( D \)، للمعالجة المسبقة لإزالة العينات ذات القيم المفقودة أو غير الصالحة، وتحويل الميزات الفئوية إلى تمثيلات عددية عبر دالة الترميز \( \phi(\cdot) \). لمعالجة عدم توازن الفئات في بيانات حركة الشبكة، يتم تطبيق دالة إعادة أخذ العينات \( R(\cdot) \)، مما يؤدي إلى مجموعات تدريب متوازنة (\( D_{\text{train}} \)) واختبار (\( D_{\text{test}} \)). تستخدم الدراسة الشبكات العصبية البيانية (GNNs) لالتقاط كل من الارتباطات على مستوى الميزات والهيكل في حركة الشبكة، الممثلة كرسوم بيانية \( G = (G, H) \)، حيث تمثل العقد تدفقات الشبكة أو المضيفين وتوضح الحواف علاقات الاتصال. يتضمن النموذج تقنيات التدريب العدائي، مثل طريقة تدرج الإشارة السريعة (FGSM) وDeepFool، لتعزيز الصلابة ضد التلاعبات العدائية.
تعتبر مجموعة بيانات CICDDoS2019، التي تم تطويرها بواسطة المعهد الكندي للأمن السيبراني، مجموعة البيانات التجريبية، التي تشمل أنواعًا مختلفة من هجمات DDoS وحركة المرور الحميدة. تحتوي هذه المجموعة، التي تحتوي على أكثر من 2.5 مليون صف و21 ميزة بعد المعالجة المسبقة، على أهمية كبيرة لدراسة التعلم العدائي وتقييم الصلابة. يتم تفصيل منهجية بناء الحواف للرسوم البيانية المعتمدة على التدفق، حيث تتشكل الحواف بناءً على معايير مثل تشابه IP، القرب الزمني، والارتباط الإحصائي للميزات. تمكن هذه البنية الشبكة العصبية البيانية من تعلم العلاقات المهمة اللازمة لاكتشاف التسلل. يختتم القسم بوصف سير العمل لاكتشاف التسلل المقاوم للعدائية، مع التأكيد على قدرة النموذج على التعامل مع كل من الاضطرابات الهيكلية والميزات خلال عملية التعلم.
مناقشة
في قسم المناقشة من الورقة، يبرز المؤلفون ثغرات أنظمة اكتشاف هجمات DDoS التقليدية، وخاصة حساسيتها للهجمات العدائية التي تتلاعب ببيانات الإدخال لتفادي الاكتشاف. يمكن أن تؤدي هذه الهجمات، التي تم تحديدها في البداية في رؤية الكمبيوتر، إلى تصنيفات خاطئة كبيرة وفشل في النظام. يؤكد المؤلفون على عدم كفاية الدفاعات الحالية، التي تم تصميمها بشكل أساسي للتعلم الدفعي ولا تتكيف جيدًا مع الطبيعة الديناميكية لبيئات إنترنت الأشياء. يجادلون بضرورة استراتيجيات التعلم عبر الإنترنت التي يمكن أن تحدث نماذجها باستمرار بناءً على البيانات الواردة، مما يعزز المرونة ضد التهديدات المتطورة.
تناقش الورقة أيضًا أهمية قابلية تفسير النموذج والصلابة في سياق الهجمات العدائية. غالبًا ما تعمل نماذج التعلم الآلي الحالية كـ “صناديق سوداء”، مما يجعل من الصعب على محللي الأمان فهم عمليات اتخاذ القرار. يقترح المؤلفون دمج تقنيات الذكاء الاصطناعي القابلة للتفسير (XAI)، مثل SHAP وLIME، لتحسين الشفافية والثقة في أنظمة اكتشاف DDoS. من خلال استخدام هذه الأساليب، تهدف الدراسة إلى تحديد الميزات الحرجة التي تؤثر على توقعات النموذج مع الحفاظ على الكفاءة الحسابية. في النهاية، يدعو المؤلفون إلى أنظمة اكتشاف التسلل القابلة للتوسع، القابلة للتفسير، والصلبة التي يمكن أن تستجيب بفعالية للتحديات التي تطرحها الهجمات العدائية في شبكات إنترنت الأشياء الحقيقية ذات الموارد المحدودة.
DOI: https://doi.org/10.1038/s41598-026-48715-9
PMID: https://pubmed.ncbi.nlm.nih.gov/42115644
Publication Date: 2026-05-11
Author(s): Uzma Ghulam Mohammad et al.
Primary Topic: Adversarial Robustness in Machine Learning
Overview
The research paper presents a novel approach to enhancing DDoS detection in IoT environments by addressing vulnerabilities in existing machine learning-based security systems. The authors introduce the AdvCICDDoS2019 dataset, which incorporates four types of adversarial attacks—Adversarial Perturbation (AP), Adversarial Outlier Injection (AOI), Adversarial Noise Injection (ANI), and Adversarial Benign (AB)—into the original CICDDoS2019 dataset. The proposed framework employs Graph Neural Networks (GNNs) and Deep Neural Networks (DNNs) alongside adversarial training techniques, specifically the DeepFool and First Gradient Sign Method (FGSM), to improve detection accuracy and robustness against adaptive attacks. The experimental results demonstrate that the framework achieves detection accuracy rates of up to 97%, significantly outperforming traditional methods by 4% to 12% across various attack scenarios.
Despite its strong performance, the study acknowledges several limitations, including the artificial nature of the adversarial attacks in the dataset and the challenges posed by stationary evaluation conditions. Future work aims to enhance the dataset with dynamic, real-time adversarial simulations and to incorporate advanced temporal learning models and adversarial training techniques. Additionally, the authors plan to explore federated learning frameworks to facilitate remote intrusion detection while maintaining data security and privacy. The integration of advanced explainable AI (XAI) techniques is also proposed to improve interpretability and provide deeper insights into the decision-making processes of the models.
Introduction
The introduction highlights the rapid growth of the Internet of Things (IoT) over the past decade, emphasizing its transformative impact on various sectors such as transportation, smart cities, energy systems, and home construction. This proliferation of interconnected devices facilitates automation and data transfer; however, it also exposes significant security vulnerabilities. Many IoT devices lack built-in security features and are deployed in environments with limited computational resources, making them susceptible to cyberattacks.
Among the various threats, Distributed Denial of Service (DDoS) attacks pose a considerable challenge due to the sheer number and nature of IoT systems. These attacks aim to disrupt authorized access to IoT devices and services by overwhelming network resources. The implications of such attacks can be severe, particularly in critical sectors like healthcare, where a DDoS attack could impede the delivery of medical data, potentially leading to incorrect treatments or delayed responses. Furthermore, the economic repercussions of DDoS attacks can be significant, particularly in industrial settings where they can disrupt production processes.
Methods
The “Methods” section outlines the methodology employed in the study, beginning with the dataset description and preprocessing steps, followed by the application of deep learning (DL) models. The DDoS dataset, denoted as \( D \), undergoes preprocessing to eliminate samples with missing or invalid values, transforming categorical features into numerical representations via an encoding function \( \phi(\cdot) \). To address class imbalance in network traffic data, a resampling function \( R(\cdot) \) is applied, resulting in balanced training (\( D_{\text{train}} \)) and testing (\( D_{\text{test}} \)) subsets. The study utilizes Graph Neural Networks (GNNs) to capture both feature-level and structural correlations in network traffic, represented as a graph \( G = (G, H) \), where nodes represent network flows or hosts and edges indicate communication relationships. The model incorporates adversarial training techniques, such as Fast Gradient Sign Method (FGSM) and DeepFool, to enhance robustness against adversarial manipulations.
The CICDDoS2019 dataset, developed by the Canadian Institute for Cybersecurity, serves as the experimental dataset, encompassing various DDoS attack types and benign traffic. This dataset, which contains over 2.5 million rows and 21 features after preprocessing, is pivotal for studying adversarial learning and robustness assessment. The edge construction methodology for flow-based graphs is detailed, where edges are formed based on criteria such as IP similarity, temporal proximity, and statistical correlation of features. This structure enables the GNN to learn meaningful relationships crucial for intrusion detection. The section concludes with a description of the adversarial resilient intrusion detection workflow, emphasizing the model’s capability to handle both feature and structural perturbations during the learning process.
Discussion
In the discussion section of the paper, the authors highlight the vulnerabilities of traditional DDoS attack detection systems, particularly their susceptibility to adversarial attacks that manipulate input data to evade detection. These attacks, initially identified in computer vision, can lead to significant misclassifications and system failures. The authors emphasize the inadequacy of current defenses, which are primarily designed for batch learning and do not adapt well to the dynamic nature of IoT environments. They argue for the necessity of online learning strategies that can continuously update models based on incoming data, thereby enhancing resilience against evolving threats.
The paper also addresses the importance of model interpretability and robustness in the context of adversarial attacks. Current machine learning models often operate as “black boxes,” making it difficult for security analysts to understand decision-making processes. The authors propose integrating explainable artificial intelligence (XAI) techniques, such as SHAP and LIME, to improve transparency and trust in DDoS detection systems. By employing these methods, the study aims to identify critical features influencing model predictions while maintaining computational efficiency. Ultimately, the authors call for scalable, interpretable, and resilient intrusion detection systems that can effectively respond to the challenges posed by adversarial attacks in real-world, resource-constrained IoT networks.
