LATIDIA · Ciberseguridad
RL adversario para la evasión de escaneo de puertos: visibilidad de la función de atacante en IDS desplegados en el borde
arXiv: 2610.08864v1Tipo de anuncio: nuevo Resumen: Los sistemas de detección de intrusos (IDS) basados en el aprendizaje automático se utilizan cada vez más en entornos de Internet de las cosas (IoT) con recursos limitados, sin embargo, su robustez es a menudo
WhatsApp ↗Telegram ↗
La noticia
arXiv:2610.08864v1 Announce Type: new Abstract: Machine learning-based intrusion detection systems (IDS) are increasingly used in resource-constrained Internet of Things (IoT) environments, yet their robustness is often evaluated against static attacks rather than adversaries that adapt to detection feedback. This paper investigates adaptive port-scan evasion against ML-based IDS models deployed on a Raspberry Pi 3B+. We implement a live Zeek-based IDS pipeline with XGBoost, a multi-layer perceptron, and a 1D convolutional neural network trained on TON_IoT telemetry, and use a Deep Q-Network (DQN) adversary to learn evasive combinations of probe timing, TCP flags, and payload size under black-box, gray-box, and white-box feature-visibility settings. Although the deployed IDS models detect conventional port