2026· IEEE Transactions on Networking· Vol 34, pp. 6013-6028· 0 citations· 47 references
Computer Science
Abstract
Evasion attacks pose a significant threat to Network Intrusion Detection Systems (NIDS) by manipulating packets to bypass their defensive strategies. This paper presents a novel black-box evasion attack framework, BlackSlit, tailored against NIDS for encrypted traffic. Unlike traditional “buffer-and-perturb” pipelines that incur significant latency, BlackSlit enables live evasion by generating universal perturbations for incoming encrypted traffic without prior knowledge. To ensure practical applicability, BlackSlit generates packet-level perturbation sequences and imposes manipulability constraints on encrypted packet features, ensuring that the perturbations are executable at the packet level. BlackSlit comprises two core components, the Generator and the Simulator, which operate in a complementary manner. The Generator iteratively produces packet-level universal perturbations, while the Simulator mimics the behavior of black-box target NIDS to guide the update process of the Generator. Both components employ a hierarchical time-series Transformer (TST)-based architecture to account for temporal correlations intrinsic to encrypted traffic, aligning with the focus of state-of-the-art (SOTA) NIDS. This architecture ensures that temporal dependencies are effectively modeled during both perturbation generation and target system simulation, thereby enhancing the overall efficacy of evasion attacks. Evaluations are conducted on 3 real-world datasets, benchmarked against 6 leading evasion attack baselines and 9 NIDS. Results demonstrate that BlackSlit consistently outperforms state-of-the-art methods across all benchmarks. Moreover, experiments against defended NIDS confirm that BlackSlit maintains robustness.
Threat-Reactive Encryption (TRE), a four-layer framework that couples a real-time ML threat scorer to a PKCS#11-compatible key management pipeline, closing the gap between threat detection and cryptographic response, is presented.
Mohammed El-hajj· International Conference on...· 0 citations
Internet-of-Things (IoT) devices in smart homes are vulnerable to passive traffic fingerprinting, where an adversary captures encrypted IEEE 802.11 frames and identifies devices using MAC-layer metadata such as packet sizes and inter-arrival times. Existing defenses based on padding, traffic shaping, or synthetic cover traffic can remain vulnerable because artificial timing signatures are detectable by machine learning classifiers. This paper proposes a game-theoretic framework for evaluating Wi-Fi MAC-layer cover-traffic injection defenses. We introduce donor-based mimicry injection, in which the access point injects a replica of a paired device’s authentic traffic into each device’s stream. We compare donor mimicry with fixed-rate, exponential, and uniform synthetic baselines across 198 scenario instances (156 unique defender configurations) and eight classifiers using 10-fold cross-validation. Donor mimicry at 100% bandwidth overhead reduces the best attacker’s balanced accuracy to 33.5%, whereas synthetic methods at equal overhead reach 93.9%, showing that behavioral realism, rather than injected volume alone, drives effectiveness. Modeling the interaction as a finite two-player zero-sum game yields a mixed-strategy Nash equilibrium with game value 0.247 within the evaluated strategy space; a deployable deterministic defense holds the best pairing-unaware attacker to 25.9% balanced accuracy, near the four-class random baseline of 25%. A pairing-aware robustness analysis shows that an attacker who can orient the donor-induced identity swap recovers near-baseline accuracy, so the four-class protection presumes pairing secrecy and the durable effect is pair-level anonymity. The defense operates at the access point and requires no IoT device modifications.
Abdulmajeed Alghamdi, Mnassar Alyami, Inad Alqurashi et al.· Italian National Conference...· 0 citations
LogSanitizer is proposed, a family of input sanitization defenses operating at two levels: a pre-prompt log-transformation pipeline that disrupts trigger patterns in the structured log representation, and a post-tokenizer perturbation strategy that corrupts trigger-bearing token configurations before they reach the model.
Leszek Wronski, Bogdan Ksiezopolski· International Conference on...· 0 citations
Vehicle-to-Everything (V2X) communication enables vehicles to exchange safety-critical messages, but its reliance on temporary pseudonymous identities makes it vulnerable to Sybil attacks, where a single attacker fabricates multiple identities to inject false information into the network. This paper presents a lightweight cryptographic mechanism that combines SHA-256 Proof-of-Work token mining with a time-windowed ratecontrol layer to limit the number of new identities a vehicle can activate within a given interval. The mechanism was implemented in Java and evaluated through a parametric simulation across three independent variables: PoW difficulty, rate limit, and attack intensity. Results show that a difficulty of 4 and a rate limit of 5 tokens per 10-second window provide an effective balance between Sybil resistance and legitimate vehicle access in an 8-vehicle scenario, with an average mining time of 0.227 seconds. The evaluation identifies the rate-control layer as the primary security mechanism, while PoW difficulty increases the computational cost per identity without independently capping accepted tokens. The proposed approach is infrastructure-free and suitable for regulated V2X deployments where attackers represent a minority of the network.
Maher Fayyad, Abdullah Awad, Edison Pignaton De Freitas et al.· International Conference on...· 0 citations
Mandatory end-to-end encryption across contemporary banking infrastructures essentially blinds legacy intrusion detection mechanisms. This review unpacks the ontological collision between applied cryptography and network data mining—a theoretical intersection currently paralyzed by an unresolved latency-privacy bottleneck. By systematically synthesizing recent literature on hybrid Intrusion Detection Systems (IDS), we map a highly fragmented academic landscape. Solutions that enforce absolute mathematical privacy via Fully Homomorphic Encryption (FHE) collapse under their own computational burden—often introducing latency overheads of up to six orders of magnitude—during high-frequency trading (HFT) simulations. Alternatively, heuristic metadata mining bypasses decryption entirely but is highly fragile to adversarial spoofing and generative traffic manipulation. Evaluating these disparate trajectories reveals a critical gap: existing frameworks rarely account for the strict microsecond tolerances required by institutional trading floors. Ultimately, this review argues that feature-level Order-Preserving Encryption (OPE) combined with gradient-boosted classifiers provides a highly operationally viable compromise. This paper concludes by identifying promising future research directions in targeted obfuscation and urges a pivot away from mathematically flawless encryption toward hardware-accelerated, latency-aware detection topologies that secure proprietary trading signals without sacrificing line-speed threat mitigation.
Safety classifiers ("guards") are the dominant black-box defense for vision-language models, yet a guard judges an input's surface form, not its meaning: a harmful request re-encoded as set theory, formal logic, a classical language, code, or text rendered inside an image slips past a guard that would block it in plain language - the decode gap. The standard fix is a preprocessor that recovers image content and decodes the encoding before the guard. We build one and evaluate it against an ensemble of eleven published encoding attacks, counting a behavior as broken if any attack succeeds. That metric separates two mechanisms such defenses conflate. Restoring a view the guard never had improves it on both axes at once: it blocks far more attacks, and, measured on a category-balanced benign set, it blocks fewer benign requests, because restating a request normalizes the borderline phrasing a classifier over-flags. It still does not make the system safer: against an attacker free to choose among eleven encodings, closing one channel relocates the success rather than removing it, and no ensemble contrast survives multiple-comparison correction. What does lower ensemble attack success is re-screening the recovered pre-decode surface, and that step is where the entire benign cost falls. The safety-utility trade-off is therefore not a property of recovery; it is localized to one step. Across the full guard x target x condition factorial, no configuration reaches an ensemble attack-success rate at or below 40% while holding benign over-refusal under 70%. The per-attack averages usually reported understate the attacker roughly fourfold, which is why this frontier is easy to miss. Composing across defense families is the one lever that moved the safety axis, beating every configuration we measured, and still landing far outside any deployable refusal budget.
Haoyu Zhang, Zhuoxiang Wang, Shibo Zheng et al.· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.