Skip to main navigation Skip to search Skip to main content

Poisoning Attacks and Defenses to Learned Bloom Filters for Malicious URL Detection

  • Xi'an Jiaotong University
  • Zhejiang CreateLink Technology Company Ltd
  • Tsinghua University

Research output: Contribution to journalArticlepeer-review

6 Scopus citations

Abstract

Approximate membership query (AMQ) structures represented by the Bloom Filter and its variants have been popularly researched in recent years. Researchers have recently combined machine learning with this type of structure to reduce space consumption and computation overhead further and make remarkable progress. However, with the booming performance in space or other metrics, researchers tend to ignore the security of the trained model. The machine learning model is vulnerable to poisoning attacks, and naturally, we infer that the learning-based filters also have the same deficiencies. Hence, in this article, to confirm the inference mentioned above, experiments on the real-world datasets of URLs are conducted and prove that it is necessary to consider the security issue when using learning-based filters. We show that by data poisoning, the attacker can deflect learned Bloom Filters to make a false identification, which can lead to a significant loss in some cases. Aiming to solve this issue, we put forward a method named Defensive Learned Bloom Filter (DLBF) to diminish the influence of data poisoning and achieve a better performance compared to types of learned Bloom Filters.

Original languageEnglish
Pages (from-to)3275-3288
Number of pages14
JournalIEEE Transactions on Dependable and Secure Computing
Volume22
Issue number4
DOIs
StatePublished - 2025

Keywords

  • Bloom filter
  • data poisoning
  • learned bloom filter
  • security of approximate membership query structure

Fingerprint

Dive into the research topics of 'Poisoning Attacks and Defenses to Learned Bloom Filters for Malicious URL Detection'. Together they form a unique fingerprint.

Cite this