| With the rapid development of artificial intelligence technology,the related methods of artificial intelligence technology represented by deep learning also provide new security requirements and new technical solutions for network security protection,and these technologies have increasingly prominent advantages in network intrusion detection system.This paper focuses on the research oriented network intrusion detection system against the attack and defense technology,to solve the deep learning applied in the distributed network intrusion detection algorithm vulnerability problem.Based on the analysis of the potential and effective forms of adversarial attacks against the distributed network intrusion detection model,the purpose of defending against multiple adversarial attacks is realized,and the robustness of the distributed network intrusion detection system is improved.The main research contents of this paper are as follows:In order to realize the adversarial attack against network intrusion detection system,this paper proposes an improved adversarial attack model attackGAN based on Wasserstein GAN,which adds the feedback of network intrusion detection system and realizes effective attack against network intrusion detection system under the premise of ensuring the function of network traffic.In order to improve the training stability of the model and the quality of adversarial samples,the corresponding loss function is proposed based on the model structure.Experimental results show that attackGAN algorithm can achieve higher attack success rate than the existing adversarial attack algorithms.Considering the possible forms of adversarial attack in the training stage of distributed network intrusion detection system,combined with the poisoned sample generation model pGAN,this paper proposes a distributed poisoning attack algorithm based on clean label data poisoning.Poisoned sample generation model is deployed at the attacker side,and the poisoned samples generated by the attack model are injected into the training data set to affect the learning process,and the system performance is reduced in a targeted way to realize the systematic poisoning attack on network nodes.At the same time,detailed experiments are carried out to prove the effectiveness of the proposed clean label data poisoning attack method in the distributed network intrusion detection system based on federated learning.The fundamental challenge of defending against attack comes from its adaptability and variability.In this paper,a novel distributed network intrusion detection system defense model based on poisoned sample detection algorithm is proposed to defend against poisoning attack.We use the poisoned sample feature extraction based on important neuron activation,and use the unsupervised anomaly detection algorithm to detect poisoned samples.The evaluations on the advanced clean label data poisoning attacks shows that our proposed defense strategy can detect up to 100%of the poisoned samples,increase the reliability of the local model,and thus the security of the distributed network intrusion detection system based on federated learning is improved. |