Defeating Slow-and-Low Threats via Diffusion Model-based Generative Inference

Seyed Mohammad Mehdi Mirnajafizadeh and Prashant Khanduri, Wayne State University; DaeHun Nyang, Ewha Womans University; Rhongho Jang, Wayne State University

Content Delivery Networks (CDNs) are known to be vulnerable to slow-and-low threats that exploit trusted protocols while evading threshold-based defense at the edge. Our work addresses three limitations at edge defense: constrained resources, absence of a behavior monitor, and impractical assumptions for online detection. To defeat slow-and-low threats, we propose SketchVision, a vision-inspired detection framework that redefines flow behavior monitoring and attack detection under resource-constrained settings. We introduce a vision-inspired sketch that encodes packet-level temporal patterns of all flows into a compact image, a diffusion model tailored for sketch denoising, and a generative inference pipeline to forecast mature flow states from partial observations for early detection. Implemented with eBPF-enabled data planes and diffusion-based control, SketchVision achieves robust accuracy across 19 types of slow-and-low attacks, reaching an average AUC of 0.982 and F1 score of 0.913, improving detection by up to 29% over the state-of-the-art methods, while remaining efficient for large-scale CDN edge deployment.

NSDI '26 Open Access Sponsored by
King Abdullah University of Science and Technology (KAUST)

Open Access Media

USENIX is committed to Open Access to the research presented at our events. Papers and proceedings are freely available to everyone once the event begins. Any video, audio, and/or slides that are posted after the event are also free and open to everyone. Support USENIX and our commitment to Open Access.

BibTeX
@inproceedings {316680,
author = {Seyed Mohammad Mehdi Mirnajafizadeh and Prashant Khanduri and DaeHun Nyang and Rhongho Jang},
title = {Defeating {Slow-and-Low} Threats via Diffusion Model-based Generative Inference},
booktitle = {23rd USENIX Symposium on Networked Systems Design and Implementation (NSDI 26)},
year = {2026},
isbn = {978-1-939133-54-0},
address = {Renton, WA},
pages = {1053--1072},
url = {https://www.usenix.org/conference/nsdi26/presentation/mirnajafizadeh},
publisher = {USENIX Association},
month = may
}

Presentation Video