יום חמישי, 8 באוקטובר 2026 LIVE
AI־INFO

כתבה arXiv cs.LG ·

היחלצות סריקת נמלים באמצעות RL

Adversarial RL for Port-Scan Evasion: Attacker Feature Visibility in Edge-Deployed IDS
חוקרים בדוויקה של היחלצות סריקת נמלים באמצעות למידת חיזוק (RL) נגד מערכות גילוי חדירות (IDS) מבוססות מודלים של XGBoost ו-DQN. התוצאות מראות כי ניתן לחמוק מגילוי גם עם ידע מוגבל על המאפיינים.
תקציר מקורי באנגליתarXiv:2610.08864v1 Announce Type: cross Abstract: Machine learning-based intrusion detection systems (IDS) are increasingly used in resource-constrained Internet of Things (IoT) environments, yet their robustness is often evaluated against static attacks rather than adversaries that adapt to detection feedback. This paper investigates adaptive port-scan evasion against ML-based IDS models deployed on a Raspberry Pi 3B+. We implement a live Zeek-based IDS pipeline with XGBoost, a multi-layer perceptron, and a 1D convolutional neural network trained on TON_IoT telemetry, and use a Deep Q-Network (DQN) adversary to learn evasive combinations of probe timing, TCP flags, and payload size under black-box, gray-box, and white-box feature-visibility settings. Although the deployed IDS models detec
קרא במקור המקורי