Skip to content

Detecting Adversarial State Manipulation in In-Network Fast ReRoute Systems

2026 · IEEE Transactions on Network and Service Management · Vol 23, pp. 6735-6750 · 0 citations · 47 references
Computer Science

Abstract

High-speed programmable data planes provide opportunities to implement data-driven fast reroute systems that quickly adapt to varying network conditions (e.g., congestion, failures) and improve network performance. The core of these systems has packet-processing algorithms running in the data plane that continuously look for traffic patterns (e.g., too many retransmissions) specific to a network condition (e.g., link failure) and take appropriate action (e.g., reroute). Despite their benefits, they also increase the potential attack surface. Adversaries can generate malicious traffic patterns resembling those anticipated by a fast reroute system and trick the system. Doing so would lead to poor network performance due to incorrect reroute decisions. In this paper, we propose a mechanism to detect whether the fast reroute systems are under the influence of malicious traffic patterns. Our key idea is to model the expected behavior using benign traffic features and use the model as a reference to determine whether the system is under the influence of adversaries. Using realistic attack traces, we demonstrate attacks on two fast reroute systems and successfully detect those attacks using the proposed detection mechanism.

View source

Similar papers

Preprint Aug 2026

XNET: Intelligent Dynamic Sampling for High-Speed Network Security Monitoring

This paper introduces XNET, a system that monitors traffic at line rate using commodity hardware and applies dynamic sampling to amplify the visibility of high security value traffic and demonstrates XNET's scalability up to 100Gbps.

Thomas Papastergiou, Karthika Subramani, Joseph W. Reilly et al. · 0 citations
Open access 2026

Hierarchical Adversarially-Driven Escalation System (HADES) for Network Intrusion Detection

The Hierarchical Adversarially-Driven Escalation System (hades) is introduced, a framework that addresses this vulnerability to adversarial examples through three coordinated mechanisms and maintains near-perfect detection accuracy under both normal and adversarial conditions.

A. Derhab, Adlen Kerboua, N. Seddari et al. · 0 citations
#artificial intelligence Preprint Oct 2026

Out of Sync, Out of Sight: Phantom State Attacks against IIoT Intrusion Detection

Machine learning-based intrusion detection systems (IDS) are critical for securing Industrial Internet of Things (IIoT) environments. Most adversarial research against them perturbs the feature vector or the traffic that produces it, and depends on gradient access, repeated model queries, or a learned model of benign t...

Sabrine Ennaji, E. Benkhelifa, Nadia Kabachi · 0 citations
#artificial intelligence Preprint Sep 2026

Adversarial Debiasing of Machine Learning Models for Enhanced Network Security against DDoS Attacks

Distributed Denial of Service attacks are a growing threat to network infrastructure, and new techniques, including the use of generative AI, make them harder to detect. Traditional detection systems, such as rule based firewalls, often fail to identify these evolving attack patterns. In this study, we propose a new me...

Aadith Sukumar, Isha Singh, Devershika Mohane et al. · 0 citations
Conference Open access Sep 2026

AI-ENHANCED DETECTION OF ARP SPOOFING-BASED MAN-IN-THE-MIDDLE ATTACKS IN LOCAL AREA NETWORKS

A hybrid LAN protection architecture that combines DAI with an AI-based behavioral detection module to improve the identification of stealthy and context-dependent MitM activity is proposed and indicates that AI can effectively complement traditional infrastructure-level network defenses by providing behavioral awarene...

Penka Markova, Georgi A. Markov · 0 citations

Exploiting Feature Non-IIDness for Untargeted Data Poisoning Attacks in Byzantine-Robust Federated Learning

This paper identifies and exploits feature non-IIDness, demonstrating that by manipulating only the features of local data on compromised clients, adversaries can generate malicious updates to bypass RA rules and significantly degrade the global model’s performance.

Junzhe Huang, Chong-Qi Guan, Guo-Hong Cao · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.