Adversarial Robustness of Traffic Classification under Resource Constraints: Input Structure Matters
Traffic classification (TC) plays a critical role in cybersecurity, particularly in IoT and embedded contexts, where inspection must often occur locally under tight hardware constraints. We use hardware-aware neural architecture search (HW-NAS) to derive lightweight TC models that are accurate, efficient, and deployable on edge platforms. Two input formats are considered: a flattened byte sequence and a 2D packet-wise time series; we examine how input structure affects adversarial vulnerability when using resource-constrained models. Robustness is assessed against white-box attacks, specifically Fast Gradient Sign Method (FGSM) and Projected Gradient Descent (PGD). On USTC-TFC2016, both HW-NAS models achieve over 99% clean-data accuracy while remaining within 65k parameters and 2M FLOPs. Yet under perturbations of strength 0.1, their robustness diverges: the flat model retains over 85% accuracy, while the time-series variant drops below 35%. Adversarial fine-tuning delivers robust gains, with flat-input accuracy exceeding 96% and the time-series variant recovering over 60 percentage points in robustness, all without compromising efficiency. The results underscore how input structure influences adversarial vulnerability, and show that even compact, resource-efficient models can attain strong robustness, supporting their practical deployment in secure edge-based TC.
Code (0)
등록된 구현이 없습니다.
Tasks
Neural Architecture SearchAdversarial RobustnessSimilar Papers 제목 키워드 기반
Darknet Traffic Classification and Adversarial Attacks
The anonymous nature of darknets is commonly exploited for illegal activities. Previous research has employed machine learning and deep learning techniques to automate the detection of darknet traffic in an attempt to bl…
Adversarial AttackBIG-bench Machine LearningClassificationTraffic ClassificationEvaluating the Impact of Adversarial Attacks on Traffic Sign Classification using the LISA Dataset
Adversarial attacks pose significant threats to machine learning models by introducing carefully crafted perturbations that cause misclassification. While prior work has primarily focused on MNIST and similar datasets, t…
Traffic Sign RecognitionBenchmarking Local Robustness of High-Accuracy Binary Neural Networks for Enhanced Traffic Sign Recognition
Traffic signs play a critical role in road safety and traffic management for autonomous driving systems. Accurate traffic sign classification is essential but challenging due to real-world complexities like adversarial e…
Autonomous DrivingBenchmarkingTraffic Sign RecognitionReliable Feature Selection for Adversarially Robust Cyber-Attack Detection
The growing cybersecurity threats make it essential to use high-quality data to train Machine Learning (ML) models for network traffic analysis, without noisy or missing data. By selecting the most relevant features for …
Computational EfficiencyCyber Attack Detectionfeature selectionAdversarial Attack and Defense of YOLO Detectors in Autonomous Driving Scenarios
Visual detection is a key task in autonomous driving, and it serves as a crucial foundation for self-driving planning and control. Deep neural networks have achieved promising results in various visual tasks, but they ar…
Adversarial AttackAdversarial DefenseAutonomous DrivingAutonomous Vehicles+2