arrow
返回

XSS adversarial example attacks based on deep reinforcement learning

delete2022-09-01
delete7
PRE
AI
L
Li Chen
T
Tang Cong
J
Junjiang He
H
Hui Zhao *
兰小龙 封面图
兰小龙 (Xiaolong Lan)
T
Tao Li
DOI:10.1016/j.cose.2022.102831delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Cross-site scripting (XSS) attack is one of the most serious security problems in web applications. Although deep neural network (DNN) has been used in XSS attack detection and achieved unprecedented success, it is vulnerable to adversarial example attacks because its input-output mapping is quite discontinuous to a large extent. The existence of adversarial examples have raised concerns in applying deep learning to key security fields. Therefore, to evaluate the effectiveness of these detection methods, a XSS adversarial example attack technique using Soft Actor-Critic (SAC) reinforcement learning algorithm is presented in the paper. A key aspect of our idea is to train an agent using SAC algorithm to build adversarial examples for several popular XSS detection models which have been proved can achieve very high accuracy rate by simulation experiments. We first design mutation strategies for different modules of XSS attack vectors to ensure the validity of the generated adversarial examples. Then, the agent selects an appropriate escape strategy according to the feedback of the detection model until it bypasses the detection model. The final experiment results show that our model can achieve an escape rate of more than 92% and outperforms the latest method by up to 6%. In other words, the effectiveness of these detection models needs to be improved, at least in terms of defense adversarial example attacks. (C) 2022 Elsevier Ltd. All rights reserved.
Keyword:
Web security
Cross site scripting
Adversarial examples
Adversarial attack
SAC
Reinforcement learning

期刊

C
Computers and Security
IF:
5.4
论文数:
4.6K
被引数:
1.4W

机构

S
sichuan university
学者数:
12.1W
论文数: 7.8W
被引数: 100
引用论文

引用论文

Black-box adversarial attacks on XSS attack detection model
err2022-02-01
err18
PREAI
errWang, Qiuhua; Yang, Hui; Wu, Guohua; Choo, Kim-Kwang Raymond; Zhang, Zheng; Miao, Gongxun; Ren, Yizhi
err分享
err收藏
err分享
err收藏
Humorous cognitive reappraisal: More benign humour and less "dark" humour is affiliated with more adaptive cognitive reappraisal strategies
err2019-01-31
err0
errOAAI
errCorinna M. Perchtold; Elisabeth M. Weiss; Christian Rominger; Kurt Feyaerts; Willibald Ruch; Andreas Fink; Ilona Papousek
err分享
err收藏
Deep Neural Networks for Acoustic Modeling in Speech Recognition深度神经网络在语音识别声学建模中的应用
err2012-11-01
err8.2K
PREAI
errHinton, Geoffrey; Deng, Li; Yu, Dong; Dahl, George E.; Mohamed, Abdel-rahman; Jaitly, Navdeep; Senior, Andrew; Vanhoucke, Vincent; Patrick Nguyen; Sainath, Tara N.; Kingsbury, Brian
err分享
err收藏
MLPXSS: An Integrated XSS-Based Attack Detection Scheme in Web Applications Using Multilayer Perceptron Technique
err2019-01-01
err51
errOAAI
errMokbal, Fawaz Mahiuob Mohammed; Dan, Wang; Imran, Azhar; Lin Jiuchuan; Akhtar, Faheem; Wang Xiaoxi
err分享
err收藏
Mechanisms of nonequilibrium electron-phonon coupling and thermal conductance at interfaces界面处非平衡电子-声子耦合和热导的机制
err2015-03-13
err0
PREAI
errAshutosh Giri; John T. Gaskins; Brian F. Donovan; Chester Szwejkowski; Ronald J. Warzoha; Mark A. Rodriguez; Jon Ihlefeld; Patrick E. Hopkins
err分享
err收藏
没有更多内容