arXiv · 2609.31981
Evasion Attacks on Cost-Utility-Based Adversarial Training for Online AutoML in IoT Networks
Abstract
As Internet of Things (IoT) networks increasingly depend on machine learning for anomaly, malware, intrusion detection, and network monitoring, such systems have become attractive targets for evasion attacks. Evasion attacks pose a major security risk because an adversary intentionally modifies input data to mislead a trained model into producing incorrect predictions while evading detection. This study evaluates the impact of black-box evasion attacks on a cost-utility-based adversarial training defense strategy in an Online AutoML context for IoT networks. Specifically, evasion attacks were applied to online learners, including Hoeffding Tree (HT), Leveraging Bagging (LB), Streaming Random Patches (SRP), Hoeffding Adaptive Tree (HAT), and Adaptive Random Forest (ARF). By developing naive and adversarially trained (AT) versions of these online learners, we generated clean and adversarial accuracies for each model. The results show that the AT versions of LB and SRP performed best, achieving the highest adversarial accuracy (0.985) and high clean accuracy (0.993) at the highest cost budget of 1.00, with a maximum accuracy reduction of only 0.8%. Finally, drift detection was conducted using the Early Drift Detection Method (EDDM).
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Chukwunonso Henry Nwokoye, Wajiha Zaheer, Khalil El-Khatib, Li Yang. 2026-09-25. Evasion Attacks on Cost-Utility-Based Adversarial Training for Online AutoML in IoT Networks. https://arxiv.org/abs/2609.31981
Cite the original work for its findings. Save a collection to share your selection of sources.