arXiv

FlowGuard: Flow Matching for Identity-Independent Detection of Data-Free Model Stealing Attacks on Energy System Intrusion Detection Systems

Title: FlowGuard: Leveraging Flow Matching for Identity-Agnostic Detection of Data-Free Model Stealing Attacks on Energy System Intrusion Detection Systems

Abstract:

Intrusion Detection Systems (IDS) powered by Artificial Intelligence (AI) within energy infrastructure are increasingly susceptible to model theft. Such attacks enable adversaries to generate evasive network traffic offline. Existing mitigation strategies face significant limitations: identity-bound query monitoring fails to detect distributed Sybil attackers, while prediction poisoning via soft-label perturbation cannot be implemented in hard-label IDS environments. To address these gaps, we introduce FlowGuard, a defense mechanism that operates independently of user identity and utilizes flow matching to identify out-of-distribution (OOD) queries before they are processed by the IDS.

The core principle of FlowGuard relies on the observation that synthetic queries created for data-free model stealing attacks reside on a lower-dimensional manifold compared to authentic network traffic. Consequently, when evaluated using a Continuous Normalizing Flow trained on legitimate data, these synthetic queries exhibit significantly lower log-likelihoods. We benchmarked our approach against PRADA and FDINet, employing MAZE and DisGUIDE attacks across both single-client and distributed scenarios involving 100-client Sybil setups. The results demonstrated that while PRADA’s detection capability fell to 0% under distribution shifts, FlowGuard sustained consistent detection rates in both environments without requiring identity-specific data. Finally, we examine the limitations of this method and suggest its potential utility in countering data-dependent attacks.


Source: arXiv Generated at: 2026-06-03 00:00:00 UTC

Related Articles

TikTok Billionaire Tops Ambani as Asia’s Second-Richest
Bloomberg

TikTok Billionaire Tops Ambani as Asia’s Second-Richest

TikTok founder surpasses Mukesh Ambani to become Asia’s second-richest person, marking a significant shift in the region...

Publishers in UK can opt out of Google AI search results
BBC News

Publishers in UK can opt out of Google AI search results

UK publishers can now opt out of Google’s AI search summaries, a CMA ruling designed to boost their bargaining power and...

Kioxia Edges Nearer Toyota’s Market Cap in Shakeup to Japan Inc.
Bloomberg

Kioxia Edges Nearer Toyota’s Market Cap in Shakeup to Japan Inc.

Kioxia’s market cap nears Toyota’s, signaling a major shift in Japan’s corporate hierarchy. This narrowing gap highlight...

Reuters

Morning Bid: Marvell, a fitting name for the latest AI darling

Reuters highlights Marvell as a top AI stock, noting its name perfectly suits its status as the newest market darling.

Financial Times

Tim Hayward: I built the Jaguar E-Type of computer keyboards

Tim Hayward compares his bespoke keyboard designs to the Jaguar E-Type. He explores high-end customization for personal ...

Financial Times

AI Labs: Zuckerberg’s $100bn gamble

Meta’s $100 billion AI investment aims to secure AI dominance, but questions remain whether sheer spending can outpace c...