VLDB 2026 Research / reviewers in the wild / expert
Giovanni Apruzzese
dblp:210/6087
· DBLP profile ↗
26ranked-venue papers
11as first author
22since 2021 · last 2026
0000-0002-6890-9611ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 15 · 5 first-author · 15 since 2021Computer networks · 4 · 3 first-author · 3 since 2021Databases, data management, data science and information retrieval · 3 · 3 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SoK: Reshaping Research on Network Intrusion Detection SystemsabstractNetwork Intrusion Detection Systems (NIDS) have been studied for decades. Hundreds of papers have, e.g., proposed ways to enhance, harden or bypass NIDS. However, the findings of prior literature are hardly reflected in real-world operational contexts. Such a disconnection is problematic for research itself: it is unclear what scenario envisioned by prior work can be used as a baseline for future advancements. Giovanni Apruzzese |
AsiaCCS | 1 |
| 2026 | "What is the Problem Space?" Defining Host-space Adversarial Perturbations against Network Intrusion Detection SystemsabstractNetwork Intrusion Detection Systems (NIDS) are now increasingly leveraging Machine Learning (ML) techniques to detect malicious network activities. Numerous papers have scrutinized the security of ML-based NIDS (ML-NIDS) by testing them against various attacks involving adversarial perturbations. The findings were oftentimes worrying: by making imperceptible changes to a given input, powerful ML models would be bypassed. In this context, we took a step back and wondered: where (i.e., in what “space”) have these perturbations been applied? Miel Verkerken, Laurens D'hooge, Bruno Volckaert, Filip De Turck, Giovanni Apruzzese |
AsiaCCS | 5 |
| 2026 | I can't recognize (yet): Delayed Rendering to Defeat Visual Phishing Detectors
Ying Yuan 0002, Cristiano Alex Rado, Giovanni Apruzzese, Mauro Conti, Luigi V. Mancini |
EuroS&P | 3 |
| 2026 | It's Not Easy: Applying Supervised Machine Learning to Detect Malicious Extensions in the Chrome Web StoreabstractGoogle Chrome is the most popular Web browser. Users can customize it with extensions that enhance their browsing experience. The most well-known marketplace of such extensions is the Chrome Web Store (CWS). Developers can upload their extensions on the CWS, but such extensions are made available to users only after a vetting process carried out by Google itself. Unfortunately, some malicious extensions bypass such checks, putting the security and privacy of downstream browser extension users at risk. In this article, we carry out a comprehensive real-world security analysis of malicious extensions in the CWS. Specifically, we scrutinize the extent to which automated mechanisms reliant on supervised machine learning (ML) can be used to detect malicious extensions on the CWS. To this end, we first collect 7,140 malicious extensions published in 2017–2023 and which have been flagged as malicious by Google. We combine this dataset with 63,598 benign extensions published or updated on the CWS before 2023, and we develop three supervised-ML-based classifiers—leveraging both original features as well as techniques inspired by prior work. We show that, in a “lab setting”, our classifiers work well (e.g., 98% accuracy). Then, we collect a new, and more recent, set of 35,462 extensions from the CWS, published or last updated in 2023, with unknown ground truth. We were eventually able to identify 68 malicious extensions that bypassed the vetting process of the CWS. However, our classifiers also reported over 1k likely malicious extensions which may overestimate their true number. Based on this finding (further supported with other experiments and realistic analyses), we elucidate, for the first time, a strong concept drift effect on browser extensions. We also provide factual evidence that commercial detectors (e.g., VirusTotal) work poorly to detect known malicious extensions. Altogether, our results highlight the fact that detecting malicious browser extensions is a fundamentally hard problem which has not (yet) received an adequate degree of attention. This requires additional work both by the research community and by Google itself—potentially by revising their approaches. In the meantime, we informed Google of our discoveries, and we released our artifacts. Ben Rosenzweig, Valentino Dalla Valle, Giovanni Apruzzese, Aurore Fass |
ACM Trans. Web | 3 |
| 2025 | The Impact of Emerging Phishing Threats: Assessing Quishing and LLM-generated Phishing Emails against OrganizationsabstractModern organizations are persistently targeted by phishing emails. Despite advances in detection systems and widespread employee training, attackers continue to innovate, posing ongoing threats. Two emerging vectors stand out in the current landscape: QR-code baits and LLM-enabled pretexting. Yet, little is known about the effectiveness of current defenses against these attacks, particularly when it comes to real-world impact on employees. This gap leaves uncertainty around to what extent related countermeasures are justified or needed. Our work addresses this issue. We conduct three phishing simulations across organizations of varying sizes - from small-medium businesses to a multinational enterprise. In total, we send over 71k emails targeting employees, including: a "traditional"phishing email with a click-through button; a nearly-identical "quishing"email with a QR code instead; and a phishing email written with the assistance of an LLM and open-source intelligence. Our results show that quishing emails have the same effectiveness as traditional phishing emails at luring users to the landing webpage - which is worrying, given that quishing emails are much harder to identify even by operational detectors. We also find that LLMs can be very good "social engineers": in one company, over 30% of the emails opened led to visiting the landing webpage - a rate exceeding some prior benchmarks. Finally, we complement our study by conducting a survey across the organizations' employees, measuring their "perceived"phishing awareness. Our findings suggest a correlation between higher self-reported awareness and organizational resilience to phishing attempts. Marie Weinz, Nicola Zannone, Luca Allodi, Giovanni Apruzzese |
AsiaCCS | 4 |
| 2025 | The Ephemeral Threat: Assessing the Security of Algorithmic Trading Systems powered by Deep LearningabstractWe study the security of stock price forecasting using Deep Learning (DL) in computational finance.Despite abundant prior research on vulnerability of DL to adversarial perturbations, such work has hitherto hardly addressed practical adversarial threat models in the context of DL-powered algorithmic trading systems (ATS).Specifically, we investigate the vulnerability of ATS to adversarial perturbations launched by a realistically constrained attacker.We first show that existing literature has paid limited attention to DL security in the financial domain-which is naturally attractive for adversaries.Then, we formalize the concept of ephemeral perturbations (EP), which can be used to stage a novel type of attack tailored for DL-based ATS.Finally, we carry out an end-to-end evaluation of our EP against a profitable ATS.Our results reveal that the introduction of small changes to the input stock-prices not only (i) induces the DL model to behave incorrectly but also (ii) leads to the whole ATS to make suboptimal buy/sell decisions, resulting in a worse financial performance of the targeted ATS. Advije Rizvani, Giovanni Apruzzese, Pavel Laskov |
CODASPY | 2 |
| 2025 | Elephant in the Room: Dissecting and Reflecting on the Evolution of Online Social Network ResearchabstractBillions of individuals engage with Online Social Networks (OSN) daily. The owners of OSN try to meet the demands of their end-users while complying with business necessities. Such necessities may, however, lead to the adoption of restrictive data access policies that hinder research activities from "external"' scientists---who may, in turn, resort to other means (e.g., rely on static datasets) for their studies. Given the abundance of literature on OSN, we - as academics - should take a step back and reflect on what we have done so far, after having written thousands of papers on OSN. This is the first paper that provides a holistic outlook to the entire body of research that focused on OSN - since the seminal work by Acquisti and Gross (2006). First, we search through over 1 million peer-reviewed publications, and derive 13,842 papers that focus on OSN: we organize the metadata of these works in the Minerva-OSN dataset, the first of its kind - which we publicly release. Next, by analyzing Minerva-OSN, we provide factual evidence elucidating trends and aspects that deserve to be brought to light - such as the predominant focus on Twitter or the difficulty in obtaining OSN data. Finally, as a constructive step to guide future research, we carry out an expert survey (n=50) with established scientists in this field, and coalesce suggestions to improve the status quo - such as an increased involvement of OSN owners. Our findings should inspire a reflection to "rescue" research on OSN. Doing so would improve the overall OSN ecosystem, benefiting both their owners and end-users - and, hence, our society. Luca Pajola, Saskia Laura Schröer, Pier Paolo Tricomi, Mauro Conti, Giovanni Apruzzese |
ICWSM | 5 |
| 2025 | Beyond the west: Revealing and bridging the gap between Western and Chinese phishing website detectionabstractPhishing attacks are on the rise, and phishing websites are everywhere, denoting the brittleness of security mechanisms reliant on blocklists. To cope with this threat, many works proposed to enhance Phishing Website Detectors (PWD) with data-driven techniques powered by Machine Learning (ML). Despite achieving promising results both in research and practice, existing solutions mostly focus “on the West”, e.g., they consider websites in English, German, or Italian. In contrast, phishing websites targeting “Eastern” countries, such as China, have been mostly neglected—despite phishing being rampant also in this side of the world. In this paper, we scrutinize whether current PWD can simultaneously work against Western and Chinese phishing websites. First, after highlighting the difficulties of practically testing PWD on Chinese phishing websites, we create CghPghrg—a dataset which enables assessment of PWD on Chinese websites. Then, we evaluate 72 PWD developed by industry practitioners and 10 ML-based PWD proposed in recent research on Western and Chinese websites: our results highlight that existing solutions, despite achieving low false positive rates, exhibit unacceptably low detection rates (sometimes inferior to 1%) on phishing websites of different regions . Next, to bridge the gap we brought to light, we elucidate the differences between Western and Chinese websites, and devise an enhanced feature set that accounts for the unique characteristics of Chinese websites. We empirically demonstrate the effectiveness of our proposed feature set by replicating (and testing) state-of-the-art ML-PWD: our results show a small but statistically significant improvement over the baselines. Finally, we review all our previous contributions and combine them to develop practical PWD that simultaneously work on Chinese and Western websites, achieving over 0.98 detection rate while maintaining only 0.01 false positive rate in a cross-regional setting. We openly release all our tools, disclose all our benchmark results, and also perform proof-of-concept experiments revealing that the problem tackled by our paper extends to other “Eastern” countries that have been overlooked by prior research on PWD. Ying Yuan 0002, Giovanni Apruzzese, Mauro Conti |
Comput. Secur. | 2 |
| 2024 | "Hey Players, there is a problem...": On Attribute Inference Attacks against VideogamersabstractWe focus on a subtle privacy issue that affects (potentially hundreds of) millions of videogamers: attribute inference attacks (AIA). Through AIA, evildoers can infer gamers’ private attributes (e.g., age, gender, occupation) by leveraging ingame statistics that are publicly available. Despite some previous research efforts highlighting the practicality of AIA in DOTA2, the overarching gaming community is not yet aware of this threat. We argue that AIA can only be mitigated through the collaboration of the entire videogaming community, and hence all stakeholders should be cognizant of the potential threat of AIA. In this work, we first assess the risk of AIA in a broad range of online video games through a set of (original) criteria that make a game prone to AIA. We further examine some practical ways in which attackers can collect personal user data in order to subsequently correlate it with their publicly available in-game data. Finally, we confirm in a representative user study (n=460) that the gamers are hardly aware of subtle issues related to AIA. In particular, 24% of our participants revealed that they would publicly share their personal data. Clearly, such data can be leveraged by evildoers to launch AIA against other players. Linus Eisele, Giovanni Apruzzese |
CoG | 2 |
| 2024 | It Doesn't Look Like Anything to Me: Using Diffusion Model to Subvert Visual Phishing Detectors
Qingying Hao, Nirav Diwan, Ying Yuan 0002, Giovanni Apruzzese, Mauro Conti, Gang Wang 0011 |
USENIX Security Symposium | 4 |
| 2024 | "Are Adversarial Phishing Webpages a Threat in Reality?" Understanding the Users' Perception of Adversarial WebpagesabstractMachine learning based phishing website detectors (ML-PWD) are a critical part of today's anti-phishing solutions in operation. Unfortunately, ML-PWD are prone to adversarial evasions, evidenced by both academic studies and analyses of real-world adversarial phishing webpages. However, existing works mostly focused on assessing adversarial phishing webpages against ML-PWD, while neglecting a crucial aspect: investigating whether they can deceive the actual target of phishing---the end users. In this paper, we fill this gap by conducting two user studies (n=470) to examine how human users perceive adversarial phishing webpages, spanning both synthetically crafted ones (which we create by evading a state-of-the-art ML-PWD) as well as real adversarial webpages (taken from the wild Web) that bypassed a production-grade ML-PWD. Our findings confirm that adversarial phishing is a threat to both users and ML-PWD, since most adversarial phishing webpages have comparable effectiveness on users w.r.t. unperturbed ones. However, not all adversarial perturbations are equally effective. For example, those with added typos are significantly more noticeable to users, who tend to overlook perturbations of higher visual magnitude (such as replacing the background). We also show that users' self-reported frequency of visiting a brand's website has a statistically negative correlation with their phishing detection accuracy, which is likely caused by overconfidence. We release our resources. Ying Yuan 0002, Qingying Hao, Giovanni Apruzzese, Mauro Conti, Gang Wang 0011 |
WWW | 3 |
| 2023 | Attribute Inference Attacks in Online Multiplayer Video Games: A Case Study on DOTA2abstractDid you know that over 70 million of Dota2 players have their ingame data freely accessible?What if such data is used in malicious ways?This paper is the first to investigate such a problem.Motivated by the widespread popularity of video games, we propose the first threat model for Attribute Inference Attacks (AIA) in the Dota2 context.We explain how (and why) attackers can exploit the abundant public data in the Dota2 ecosystem to infer private information about its players.Due to lack of concrete evidence on the efficacy of our AIA, we empirically prove and assess their impact in reality.By conducting an extensive survey on ∼500 Dota2 players spanning over 26k matches, we verify whether a correlation exists between a player's Dota2 activity and their real-life.Then, after finding such a link (𝑝 < 0.01 and 𝜌 > 0.3), we ethically perform diverse AIA.We leverage the capabilities of machine learning to infer real-life attributes of the respondents of our survey by using their publicly available in-game data.Our results show that, by applying domain expertise, some AIA can reach up to 98% precision and over 90% accuracy.This paper hence raises the alarm on a subtle, but concrete threat that can potentially affect the entire competitive gaming landscape.We alerted the developers of Dota2. Pier Paolo Tricomi, Lisa Facciolo, Giovanni Apruzzese, Mauro Conti |
CODASPY | 3 |
| 2023 | Attacking Logo-Based Phishing Website Detectors with Adversarial Perturbations
Jehyun Lee, Zhe Xin, Melanie Ng Pei See, Kanav Sabharwal, Giovanni Apruzzese, Dinil Mon Divakaran |
ESORICS (3) | 5 |
| 2023 | SoK: Pragmatic Assessment of Machine Learning for Network Intrusion DetectionabstractMachine Learning (ML) has become a valuable asset to solve many real-world tasks. For Network Intrusion Detection (NID), however, scientific advances in ML are still seen with skepticism by practitioners. This disconnection is due to the intrinsically limited scope of research papers, many of which primarily aim to demonstrate new methods "outperforming" prior work—oftentimes overlooking the practical implications for deploying the proposed solutions in real systems. Unfortunately, the value of ML for NID depends on a plethora of factors, such as hardware, that are often neglected in scientific literature.This paper aims to reduce the practitioners’ skepticism towards ML for NID by changing the evaluation methodology adopted in research. After elucidating which factors influence the operational deployment of ML in NID, we propose the notion of pragmatic assessment, which enable practitioners to gauge the real value of ML methods for NID. Then, we show that the state-of-research hardly allows one to estimate the value of ML for NID. As a constructive step forward, we carry out a pragmatic assessment. We re-assess existing ML methods for NID, focusing on the classification of malicious network traffic, and consider: hundreds of configuration settings; diverse adversarial scenarios; and four hardware platforms. Our large and reproducible evaluations enable estimating the quality of ML for NID. We also validate our claims through a user-study with security practitioners. Giovanni Apruzzese, Pavel Laskov, Johannes Schneider 0002 |
EuroS&P | 1 |
| 2023 | Dual adversarial attacks: Fooling humans and classifiersabstractAdversarial samples mostly aim at fooling machine learning (ML) models. They often involve minor pixel-based perturbations that are imperceptible to human observers. In this work, adversarial samples should fool both humans and ML models, which is important in two-stage decision processes. We perform changes on a higher abstraction level so that a target sample exhibits properties of a desired sample. Technically, we contribute by deriving a regularization scheme for autoencoders incorporating a classifier loss for smoothly interpolating between wildly different samples. The realism and effectiveness of generated samples are confirmed with a user study and other evaluations. Our experiments consider neural networks of four architectures, assessed on MNIST, FashionMNIST, QuickDraw and CIFAR-10. Results show that our scheme leads to superior performance compared to existing interpolation techniques: on average, other methods have an 11% higher failure rate when producing a sample that is of any of two interpolated classes. Furthermore, our attacks work in both white- and black-box settings. Johannes Schneider 0002, Giovanni Apruzzese |
J. Inf. Secur. Appl. | 2 |
| 2023 | Mitigating Adversarial Gray-Box Attacks Against Phishing DetectorsabstractAlthough machine learning based algorithms have been extensively used for detecting phishing websites, there has been relatively little work on how adversaries may attack such “phishing detectors” (PDs for short). In this paper, we propose a set of Gray-Box attacks on PDs that an adversary may use which vary depending on the knowledge that he has about the PD. We show that these attacks severely degrade the effectiveness of several existing PDs. We then propose the concept ofoperation chainsthat iteratively map an original set of features to a new set of features and develop the “Protective Operation Chain” (${{\sf POC}}$for short) algorithm.${{\sf POC}}$leverages the combination of random feature selection and feature mappings in order to increase the attacker's uncertainty about the target PD. Using 3 existing publicly available datasets plus a fourth that we have created and will release upon the publication of this article1, we show that${{\sf POC}}$is more robust to these attacks than past competing work, while preserving predictive performance when no adversarial attacks are present. Moreover,${{\sf POC}}$is robust to attacks on 13 different classifiers, not just one. These results are shown to be statistically significant at the$p < 0.001$level. Giovanni Apruzzese, V. S. Subrahmanian |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2022 | SpacePhish: The Evasion-space of Adversarial Attacks against Phishing Website Detectors using Machine LearningabstractExisting literature on adversarial Machine Learning (ML) focuses either on showing attacks that break every ML model, or defenses that withstand most attacks. Unfortunately, little consideration is given to the actual cost of the attack or the defense. Moreover, adversarial samples are often crafted in the “feature-space”, making the corresponding evaluations of questionable value. Simply put, the current situation does not allow to estimate the actual threat posed by adversarial attacks, leading to a lack of secure ML systems. Giovanni Apruzzese, Mauro Conti, Ying Yuan 0002 |
ACSAC | 1 |
| 2022 | SoK: The Impact of Unlabelled Data in Cyberthreat DetectionabstractMachine learning (ML) has become an important paradigm for cyberthreat detection (CTD) in the recent years. A substantial research effort has been invested in the development of specialized algorithms for CTD tasks. From the operational perspective, however, the progress of ML-based CTD is hindered by the difficulty in obtaining the large sets of labelled data to train ML detectors. A potential solution to this problem are semisupervised learning (SsL) methods, which combine small labelled datasets with large amounts of unlabelled data. This paper is aimed at systematization of existing work on SsL for CTD and, in particular, on understanding the utility of unlabelled data in such systems. To this end, we analyze the cost of labelling in various CTD tasks and develop a formal cost model for SsL in this context. Building on this foundation, we formalize a set of requirements for evaluation of SsL methods, which elucidates the contribution of unlabelled data. We review the state-of-the-art and observe that no previous work meets such requirements. To address this problem, we propose a framework for assessing the benefits of unlabelled data in SsL. We showcase an application of this framework by performing the first benchmark evaluation that highlights the tradeoffs of 9 existing SsL methods on 9 public datasets. Our findings verify that, in some cases, unlabelled data provides a small, but statistically significant, performance gain. This paper highlights that SsL in CTD has a lot of room for improvement, which should stimulate future research in this field. Giovanni Apruzzese, Pavel Laskov, Aliya Tastemirova |
EuroS&P | 1 |
| 2022 | The Cross-Evaluation of Machine Learning-Based Network Intrusion Detection SystemsabstractEnhancing Network Intrusion Detection Systems (NIDS) with supervised Machine Learning (ML) is tough. ML-NIDS must be trained and evaluated, operations requiring data where benign and malicious samples are clearly labeled. Such labels demand costly expert knowledge, resulting in a lack of real deployments, as well as on papers always relying on the same outdated data. The situation improved recently, as some efforts disclosed their labeled datasets. However, most past works used such datasets just as a ‘yet another’ testbed, overlooking the added potential provided by such availability. In contrast, we promote using such existing labeled data to cross-evaluate ML-NIDS. Such approach received only limited attention and, due to its complexity, requires a dedicated treatment. We hence propose the first cross-evaluation model. Our model highlights the broader range of realistic use-cases that can be assessed via cross-evaluations, allowing the discovery of still unknown qualities of state-of-the-art ML-NIDS. For instance, their detection surface can be extended—at no additional labeling cost. However, conducting such cross-evaluations is challenging. Hence, we propose the first framework, XeNIDS, for reliable cross-evaluations based on Network Flows. By using XeNIDS on six well-known datasets, we demonstrate the concealed potential, but also the risks, of cross-evaluations of ML-NIDS. Giovanni Apruzzese, Luca Pajola, Mauro Conti |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2022 | Wild Networks: Exposure of 5G Network Infrastructures to Adversarial ExamplesabstractFifth Generation (5G) networks must support billions of heterogeneous devices while guaranteeing optimal Quality of Service (QoS). Such requirements are impossible to meet with human effort alone, and Machine Learning (ML) represents a core asset in 5G. ML, however, is known to be vulnerable to adversarial examples; moreover, as our paper will show, the 5G context is exposed to a yet another type of adversarial ML attacks that cannot be formalized with existing threat models. Proactive assessment of such risks is also challenging due to the lack of ML-powered 5G equipment available for adversarial ML research. To tackle these problems, we propose a novel adversarial ML threat model that is particularly suited to 5G scenarios, and is agnostic to the precise function solved by ML. In contrast to existing ML threat models, our attacks do not require any compromise of the target 5G system while still being viable due to the QoS guarantees and the open nature of 5G networks. Furthermore, we propose an original framework for realistic ML security assessments based on public data. We proactively evaluate our threat model on 6 applications of ML envisioned in 5G. Our attacks affect both the training and the inference stages, can degrade the performance of state-of-the-art ML systems, and have a lower entry barrier than previous attacks. Giovanni Apruzzese, Rodion Vladimirov, Aliya Tastemirova, Pavel Laskov |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2021 | On the Evaluation of Sequential Machine Learning for Network Intrusion DetectionabstractRecent advances in deep learning renewed the research interests in machine learning for Network Intrusion Detection Systems (NIDS). Specifically, attention has been given to sequential learning models, due to their ability to extract the temporal characteristics of network traffic flows (NetFlows), and use them for NIDS tasks. However, the applications of these sequential models often consist of transferring and adapting methodologies directly from other fields, without an in-depth investigation on how to leverage the specific circumstances of cybersecurity scenarios; moreover, there is a lack of comprehensive studies on sequential models that rely on NetFlow data, which presents significant advantages over traditional full packet captures. We tackle this problem in this paper. We propose a detailed methodology to extract temporal sequences of NetFlows that denote patterns of malicious activities. Then, we apply this methodology to compare the efficacy of sequential learning models against traditional static learning models. In particular, we perform a fair comparison of a ‘sequential’ Long Short-Term Memory (LSTM) against a ‘static’ Feedforward Neural Networks (FNN) in distinct environments represented by two well-known datasets for NIDS: the CICIDS2017 and the CTU13. Our results highlight that LSTM achieves comparable performance to FNN in the CICIDS2017 with over 99.5% F1-score; while obtaining superior performance in the CTU13, with 95.7% F1-score against 91.5%. This paper thus paves the way to future applications of sequential learning models for NIDS. Andrea Corsini, Shanchieh Jay Yang, Giovanni Apruzzese |
ARES | 3 |
| 2021 | Towards an Efficient Detection of Pivoting Activity
Martin Husák, Giovanni Apruzzese, Shanchieh Jay Yang, Gordon Werner |
IM | 2 |
| 2020 | Deep Reinforcement Adversarial Learning Against Botnet Evasion AttacksabstractAs cybersecurity detectors increasingly rely on machine learning mechanisms, attacks to these defenses escalate as well. Supervised classifiers are prone to adversarial evasion, and existing countermeasures suffer from many limitations. Most solutions degrade performance in the absence of adversarial perturbations; they are unable to face novel attack variants; they are applicable only to specific machine learning algorithms. We propose the first framework that can protect botnet detectors from adversarial attacks through deep reinforcement learning mechanisms. It automatically generates realistic attack samples that can evade detection, and it uses these samples to produce an augmented training set for producing hardened detectors. In such a way, we obtain more resilient detectors that can work even against unforeseen evasion attacks with the great merit of not penalizing their performance in the absence of specific attacks. We validate our proposal through an extensive experimental campaign that considers multiple machine learning algorithms and public datasets. The results highlight the improvements of the proposed solution over the state-of-the-art. Our method paves the way to novel and more robust cybersecurity detectors based on machine learning applied to network traffic analytics. Giovanni Apruzzese, Mauro Andreolini, Mirco Marchetti, Andrea Venturi, Michele Colajanni |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2019 | Evaluating the effectiveness of Adversarial Attacks against Botnet DetectorsabstractClassifiers based on Machine Learning are vulnerable to adversarial attacks, which involve the creation of malicious samples that are not classified correctly. While this phenomenon has been extensively studied within the image processing domain, comprehensive analyses are scarce in the cybersecurity field. This is a critical problem because cyber-detectors are being increasingly integrated with machine learning methods, making them suitable targets for skilled attackers leveraging adversarial samples to evade detection. In this paper, we propose a thorough analysis of realistic adversarial attacks performed against network intrusion detection systems that focus on identifying botnet traffic through machine learning classifiers. Our large campaign of experiments involves the most recent public datasets, representing multiple realistic network scenarios. Moreover, we evaluate the impact of these attacks against state-of-the-art detectors relying on different machine learning algorithms, providing a clear overview of this problem. The results outline the fragility of these methods. Our study represent a stepping stone for devising suitable countermeasures to the menace of adversarial attacks against cyber-detectors. Giovanni Apruzzese, Michele Colajanni, Mirco Marchetti |
NCA | 1 |
| 2018 | Evading Botnet Detectors Based on Flows and Random Forest with Adversarial SamplesabstractMachine learning is increasingly adopted for a wide array of applications, due to its promising results and autonomous capabilities. However, recent research efforts have shown that, especially within the image processing field, these novel techniques are susceptible to adversarial perturbations. In this paper, we present an analysis that highlights and evaluates experimentally the fragility of network intrusion detection systems based on machine learning algorithms against adversarial attacks. In particular, our study involves a random forest classifier that utilizes network flows to distinguish between botnet and benign samples. Our results, derived from experiments performed on a public real dataset of labelled network flows, show that attackers can easily evade such defensive mechanisms by applying slight and targeted modifications to the network activity generated by their controlled bots. These findings pave the way for future techniques that aim to strengthen the performance of machine learning-based network intrusion detection systems. Giovanni Apruzzese, Michele Colajanni |
NCA | 1 |
| 2017 | Identifying malicious hosts involved in periodic communicationsabstractAfter many research efforts, Network Intrusion Detection Systems still have much room for improvement. This paper proposes a novel method for automatic and timely analysis of traffic generated by large networks, which is able to identify malicious external hosts even if their activities do not raise any alert by existing defensive systems. Our proposal focuses on periodic communications, since our experimental evaluation shows that they are more related to malicious activities, and it can be easily integrated with other detection systems. We highlight that periodic network activities can occur at very different intervals ranging from seconds to hours, hence a timely analysis of long time-windows of the traffic generated by large organizations is a challenging task in itself. Existing work is primarily focused on identifying botnets, whereas the method proposed in this paper has a broader target and aims to detect external hosts that are likely involved in any malicious operation. Since malware-related network activities can be considered as rare events in the overall traffic, the output of the proposed method is a manageable graylist of external hosts that are characterized by a considerably higher likelihood of being malicious compared to the entire set of external hosts contacted by the monitored large network. A thorough evaluation on a real large network traffic demonstrates the effectiveness of our proposal, which is capable of automatically selecting only dozens of suspicious hosts from hundreds of thousands, thus allowing security operators to focus their analyses on few likely malicious targets. Giovanni Apruzzese, Mirco Marchetti, Michele Colajanni, Gabriele Gambigliani Zoccoli, Alessandro Guido |
NCA | 1 |