To Örebro University

oru.seÖrebro University Publications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
A Random Deep Feature Selection Approach to Mitigate Transferable Adversarial Attacks
Centre for Sustainable Cyber Security, University of Greenwich, London, U.K. .
Smart Automation and Cyber Resilience, Digital Systems, RISE Research Institute of Sweden, Stockholm, Sweden.
School of Electrical and Computer Engineering, Shiraz University, Shiraz, Iran.
PAIDS Research Centre, School of Computing, University of Portsmouth, Portsmouth, U.K..
Show others and affiliations
2025 (English)In: IEEE Transactions on Network and Service Management, E-ISSN 1932-4537, Vol. 22, no 6, p. 5301-5310Article in journal (Refereed) Published
Abstract [en]

Machine learning and deep learning are transformative forces reshaping our networks, industries, services, and ways of life. However, the susceptibility of these intelligent systems to adversarial attacks remains a significant issue. On the one hand, recent studies have demonstrated the potential transferability of adversarial attacks across diverse models. On the other hand, existing defense mechanisms are vulnerable to advanced attacks or are often limited to certain attack types. This study proposes a random deep feature selection approach to mitigate such transferability and improve the robustness of models against adversarial manipulations. Our approach is designed to strengthen deep models against poisoning (e.g., label flipping) and exploratory (e.g., DeepFool, BIM, FGSM, I-FGSM, L-BFGS, C&W, JSMA, and PGD) attacks that are applied in both the training and testing stages, and Transfer Learning-Based Adversarial Attacks. We consider scenarios involving perfect and semi-knowledgeable attackers. The performance of our approach is evaluated through extensive experiments on the renowned UNSW-NB15 dataset, including both real-world and synthetic data, covering a wide range of modern attack behaviors and benign activities. The results indicate that our approach boosts the effectiveness of the target network to over 80% against label-flipping poisoning attacks and over 60% against all major types of exploratory attacks.

Place, publisher, year, edition, pages
IEEE, 2025. Vol. 22, no 6, p. 5301-5310
Keywords [en]
Training, Resource description framework, Data models, Vectors, Robustness, Computational modeling, Training data, Feature extraction, Computer vision, Computer architecture, Adversarial machine learning, poisoning attacks, backdoor attacks, exploratory attacks, transferability, deep learning, network security
National Category
Computer Sciences
Identifiers
URN: urn:nbn:se:oru:diva-125807DOI: 10.1109/TNSM.2025.3594253ISI: 001631860800012OAI: oai:DiVA.org:oru-125807DiVA, id: diva2:2025469
Available from: 2026-01-07 Created: 2026-01-07 Last updated: 2026-01-07Bibliographically approved

Open Access in DiVA

No full text in DiVA

Other links

Publisher's full text

Authority records

Conti, Mauro

Search in DiVA

By author/editor
Conti, Mauro
By organisation
School of Science and Technology
In the same journal
IEEE Transactions on Network and Service Management
Computer Sciences

Search outside of DiVA

GoogleGoogle Scholar

doi
urn-nbn

Altmetric score

doi
urn-nbn
Total: 42 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf