TIGP (SNHCC) -- GAN-Based Adversarial Sample Generation for Low-Rate DDoS Attack Detection
- LecturerProf. Shan-Hsiang Shen (Department of Computer Science and Information Engineering, National Taiwan University of Science and Technology)
Host: TIGP (SNHCC) - Time2026-11-02 (Mon.) 14:00 ~ 16:00
- LocationAuditorium 106 at IIS new Building
Abstract
As the application of machine learning in cybersecurity becomes increasingly widespread, the threats posed by adversarial attacks have drawn growing attention. This study investigates the vulnerability of machine learning models in the context of Slowloris—a typical low-rate DDoS attack—and proposes an adversarial sample generation architecture targeting packet features named AdvGAN, which generates adversarial samples by applying slight perturbations to actual samples. Using Support Vector Machines (SVM) as the target model, this research analyzes changes in the model's misclassification
rate across multiple hyperparameter configurations.
Experimental results demonstrate that adversarial samples generated by the traditional GAN architecture increase the model's misclassification rate by up to approximately 12.57%, while the AdvGAN-based architecture achieves a
maximum increase of about 8% under perturbation constraints. Further analysis of sample plausibility confirms that the generated adversarial samples retain both the core characteristics and the stealthiness of a Slowloris attack. These findings validate the effectiveness of adversarial samples in fooling traffic classification models and highlight the potential
security risks facing existing defense mechanisms when exposed to adversarial attacks.
rate across multiple hyperparameter configurations.
Experimental results demonstrate that adversarial samples generated by the traditional GAN architecture increase the model's misclassification rate by up to approximately 12.57%, while the AdvGAN-based architecture achieves a
maximum increase of about 8% under perturbation constraints. Further analysis of sample plausibility confirms that the generated adversarial samples retain both the core characteristics and the stealthiness of a Slowloris attack. These findings validate the effectiveness of adversarial samples in fooling traffic classification models and highlight the potential
security risks facing existing defense mechanisms when exposed to adversarial attacks.
BIO
Shan-Hsiang received the M.S. degree from National Chiao Tung University, Republic of China, in 2004, and the Ph.D. degree from the University of Wisconsin, USA, in 2014.
He is currently an Associate Professor with the Computer Science and Information Engineering Department, National Taiwan University of Science and Technology, Taiwan.
His main research interests include software-defined networking, network function virtualization, network security, and cloud computing.
He is currently an Associate Professor with the Computer Science and Information Engineering Department, National Taiwan University of Science and Technology, Taiwan.
His main research interests include software-defined networking, network function virtualization, network security, and cloud computing.