Lightweight SPIT Detection Under Adversarial Mimicry

  • Antonio Jorge Andrade CESAR School
  • Luciano Barbosa CESAR School

Resumo


Spam over Internet Telephony (SPIT) detection faces escalating adversarial evasion via behavioral mimicry, while deep learning defenses often struggle to meet real-time scalability and transparency requirements. We formalize the “Fraudster’s Trilemma” and evaluate lightweight classifiers over an eight-dimensional feature space spanning physical, volumetric, and behavioral planes, using a simulation of 500,000 subscriber profiles across three stages of adversarial complexity (E1–E3). Ablation evidence indicates that the behavioral vector collapses under calibrated mimicry (F0.5 = 0.03 under Random Forest at E3), while the infrastructure-bound physical vector sustains an independent boundary of F0.5 = 0.98; the volumetric vector collapses under a linear boundary but persists under tree ensembles, which recover the class boundary from dispersion statistics that this benchmark does not equalize. Lightweight ensembles sustain high precision on this benchmark while scoring each subscriber independently, and per-decision SHAP attributions give operators an auditable justification for each blocking decision.

Palavras-chave: adversarial mimicry, anomaly detection, machine learning, SPIT detection

Referências

Azad, M. A., Morla, R., and Salah, K. Systems and methods for SPIT detection in VoIP: Survey and future directions. Computers & Security vol. 77, pp. 1–20, 2018.

Breiman, L. Random Forests. Machine Learning 45 (1): 5–32, 2001.

Calabrese, F., Diao, M., Di Lorenzo, G., Ferreira Jr., J., and Ratti, C. Understanding individual mobility patterns from urban sensing data: A mobile phone trace example. Transportation Research Part C: Emerging Technologies vol. 26, pp. 301–313, 2013.

Forghani, M., Karimipour, F., and Claramunt, C. From cellular positioning data to trajectories: Steps towards a more accurate mobility exploration. Transportation Research Part C: Emerging Technologies vol. 117, pp. 102666, 2020.

Hu, X., Chen, H., Liu, S., Jiang, H., Wang, K., and Wang, Y. Who are the evil backstage manipulators: Boosting graph attention networks against deep fraudsters. Computer Networks vol. 232, pp. 109848, 2023.

Ke, G., Meng, Q., Finley, T., Wang, T., Chen, W., Ma, W., Ye, Q., and Liu, T.-Y. LightGBM: A Highly Efficient Gradient Boosting Decision Tree. In Advances in Neural Information Processing Systems (NeurIPS). Vol. 30. Curran Associates, Inc., Red Hook, NY, USA, 2017.

Liu, J., Rahbarinia, B., Perdisci, R., Du, H., and Su, L. Augmenting Telephone Spam Blacklists by Mining Large CDR Datasets. In Proceedings of the 2018 ACM Asia Conference on Computer and Communications Security (ASIACCS). ACM, Incheon, Republic of Korea, pp. 273–284, 2018.

Murynets, I., Zabarankin, M., Piqueras Jover, R., and Panagia, A. Analysis and detection of SIMbox fraud in mobility networks. In IEEE INFOCOM 2014 - IEEE Conference on Computer Communications. IEEE, Toronto, ON, Canada, pp. 1519–1526, 2014.

Reaves, B., Shernan, E., Bates, A., Carter, H., and Traynor, P. Boxed Out: Blocking Cellular Interconnect Bypass Fraud at the Network Edge. In Proceedings of the 24th USENIX Security Symposium. USENIX Association, Washington, D.C., USA, pp. 833–848, 2015.

Zhong, M., Lin, M., Zhang, C., and Xu, Z. A survey on graph neural networks for intrusion detection systems: Methods, trends and challenges. Computers & Security vol. 141, pp. 103821, 2024.
Publicado
19/10/2026
ANDRADE, Antonio Jorge; BARBOSA, Luciano. Lightweight SPIT Detection Under Adversarial Mimicry. In: SYMPOSIUM ON KNOWLEDGE DISCOVERY, MINING AND LEARNING (KDMILE), 14. , 2026, Cuiabá/MT. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 145-152. ISSN 2763-8944. DOI: https://doi.org/10.5753/kdmile.2026.32002.