Skip to Main Content (Press Enter)

Logo UNIMORE
  • ×
  • Home
  • Corsi
  • Insegnamenti
  • Professioni
  • Persone
  • Pubblicazioni
  • Strutture
  • Terza Missione
  • Attività
  • Competenze

UNI-FIND
Logo UNIMORE

|

UNI-FIND

unimore.it
  • ×
  • Home
  • Corsi
  • Insegnamenti
  • Professioni
  • Persone
  • Pubblicazioni
  • Strutture
  • Terza Missione
  • Attività
  • Competenze
  1. Pubblicazioni

Evading ML Network Intrusion Detection Systems for Modbus TCP with Problem-Space Perturbations

Contributo in Atti di convegno
Data di Pubblicazione:
2026
Citazione:
Evading ML Network Intrusion Detection Systems for Modbus TCP with Problem-Space Perturbations / Galli, D., Zoccoli, G.G., Bianchini, D., Stabili, D., Marchetti, M.. - 4198:(2026). (2026 Joint National Conference on Cybersecurity, ITASEC and SERICS 2026 ita 2026).
Abstract:
Machine Learning (ML) plays a central role in Network Intrusion Detection Systems (NIDS), as it can be used to analyze complex traffic patterns and detect previously unseen attacks. With Industrial Control Systems (ICS) becoming increasingly connected and exposed to novel threats, ML-NIDS have been widely adopted to provide automated detection of cyberattacks targeting control processes and critical infrastructures. While ML-NIDS demonstrate good effectiveness and high performance, adversarial ML attacks based on input data manipulation have been shown to undermine their robustness. However, existing adversarial strategies against ML-NIDS in ICS primarily focus on modifying traffic attributes at the flow level, without considering the constraints imposed by the underlying network protocols. In this paper, we propose a packet-level adversarial attack to evade ML-NIDS for Modbus TCP. We modify raw packet captures using two manipulation methods, namely jitter and padding, which reshape the features of the resulting flows while preserving Modbus functionalities. We evaluate the impact of these perturbations on the CIC Modbus 2023 dataset, considering three different attacker scenarios and targeting three popular ML models (Decision Tree, Random Forest, Histogram Gradient Boosting). Results show that our attack strategies degrade ML-NIDS performance, with detection rates falling below 0.5 in 31 out of 45 cases.
Tipologia CRIS:
Relazione in Atti di Convegno
Keywords:
Adversarial Attacks; Industrial Control Systems; Machine Learning; Modbus TCP; Network Intrusion Detection Systems; Problem-Space Perturbations
Elenco autori:
Galli, D.; Zoccoli, G. G.; Bianchini, D.; Stabili, D.; Marchetti, M.
Autori di Ateneo:
GALLI DIMITRI
MARCHETTI Mirco
Stabili Dario
Link alla scheda completa:
https://iris.unimore.it/handle/11380/1412209
Link al Full Text:
https://iris.unimore.it//retrieve/handle/11380/1412209/992193/paper25.pdf
Titolo del libro:
CEUR Workshop Proceedings
Pubblicato in:
CEUR WORKSHOP PROCEEDINGS
Journal
CEUR WORKSHOP PROCEEDINGS
Series
  • Utilizzo dei cookie

Realizzato con VIVO | Designed by Cineca | 26.7.2.0