详细信息
Dynamic stealthy backdoor attack against anomaly detectors in industrial control systems ( SCI-EXPANDED收录 EI收录)
文献类型:期刊文献
英文题名:Dynamic stealthy backdoor attack against anomaly detectors in industrial control systems
作者:Jiang, Qingchao[1,3];Zu, Yu[1,3];Zhu, Zhiying[1,3];Zhong, Weimin[1,3];Xu, Yiran[2];Qian, Zhenxing[2];Zhang, Xinpeng[2]
机构:[1]Minist Educ, Key Lab Smart Mfg Energy Chem Proc, Shanghai 200237, Peoples R China;[2]Fudan Univ, Coll Comp Sci & Artificial Intelligence, Shanghai 200433, Peoples R China;[3]East China Univ Sci & Technol, Sch Informat Sci & Engn, Shanghai 200237, Peoples R China
年份:2026
卷号:735
外文期刊名:INFORMATION SCIENCES
收录:;EI(收录号:20260219900244);WOS:【SCI-EXPANDED(收录号:WOS:001662956600001)】;
基金:This work was supported by the National Natural Science Foundation of China under Grant (62402182, 62322309, 62572125) , the Natural Science Foundation of Shanghai under Grant 25ZR1401019, the Shanghai Explorer Program under Grant 24TS1411700, and the Open Research Fund of The State Key Laboratory of Blockchain and Data Security, Zhejiang University. The authors are extremely grateful to the editors and anonymous reviewers for their insightful and constructive comments on this work.
语种:英文
外文关键词:Backdoor attack; Anomaly detection; Industrial control systems; Deep neural networks; Dynamic trigger generation
摘要:Industrial Control Systems (ICSs) serve as the core components of modern critical infrastructure. As an essential function of ICS, deep neural network (DNN)-based anomaly detection methods have significantly enhanced the security of industrial production. However, their high dependency on training data renders them vulnerable to backdoor attacks. Existing backdoor methods suffer from static trigger patterns, insufficient stealthiness, and limited attack effectiveness in industrial scenarios. To address these issues, we propose a dynamic stealthy poisoning-based backdoor attack method tailored for ICS. This method achieves a sample-adaptive trigger generation mechanism. To train the trigger generator, we employ an encoder-decoder architecture. The encoder encodes the training set features into triggers and creates backdoored samples. The decoder reconstructs the training set features from these samples to facilitate the encoder's training. During the backdoor implantation in the target model, a multi-objective joint optimization strategy is applied to simultaneously achieve both the stealth and effectiveness of the attack. Experimental results demonstrate the effectiveness of our proposed attack method on three different ICS datasets, achieving an attack success rate of over 94% on each. The generated triggers can effectively evade existing anomaly detection mechanisms and provide a novel testing benchmark for evaluating defense solutions.
参考文献:
正在载入数据...
