A canary injection protocol for linking observed AI agent behavior to the responsible account at the hosting vendor, with robust variants for adversarial filtering.
Outside the closed world: On using machine learning for network intrusion detection
8 Pith papers cite this work, alongside 1,867 external citations. Polarity classification is still indexing.
citation-role summary
citation-polarity summary
years
2026 8roles
background 2polarities
background 2representative citing papers
Two detectors achieve near-perfect accuracy detecting PANDA-style adversarial attacks on autoencoder NIDS using image-space error localization and packet-feature consistency checks on IoT traffic.
Learning-induced spectral structure in hybrid quantum models is diagnosed by edge-resolved two-boson interference correlated with Fiedler cuts and by absolute Bloch drift that separates anomalies from benign states.
Empirical evaluation on LID-DS-2021 shows CWE-level generalization of syscall anomaly detectors succeeds for CWE-307 (F1=0.6976 at FPR=0.05) but fails for CWE-89 and CWE-434 (F1<=0.21), with transfer strongly dependent on source normal-profile breadth.
A subnormal Gaussian fuzzy number model for risk-averse IDS alert prioritization that shows improved robustness over baselines on CIC-IDS2017 and NSL-KDD under detector degradation.
SentinelSphere integrates an AI threat detector using an enhanced DNN on benchmark datasets with a fine-tuned quantized LLM for user training and awareness.
A literature survey synthesizes 119 studies on AI-driven alert screening into a four-stage taxonomy of filtering, triage, correlation, and generative augmentation while identifying gaps in deployment realism and robustness.
citing papers explorer
-
Who Owns This Agent? Tracing AI Agents Back to Their Owners
A canary injection protocol for linking observed AI agent behavior to the responsible account at the hosting vendor, with robust variants for adversarial filtering.
-
Detecting Adversarial Evasion Attacks Against Autoencoder-Based Network Intrusion Detection Systems
Two detectors achieve near-perfect accuracy detecting PANDA-style adversarial attacks on autoencoder NIDS using image-space error localization and packet-feature consistency checks on IoT traffic.
-
Spectral Geometry and Bosonic-Bloch Probes: Explorations in Quantum Learning
Learning-induced spectral structure in hybrid quantum models is diagnosed by edge-resolved two-boson interference correlated with Fiedler cuts and by absolute Bloch drift that separates anomalies from benign states.
-
From CVE to CWE: Syscall-Based HIDS Generalisation
Empirical evaluation on LID-DS-2021 shows CWE-level generalization of syscall anomaly detectors succeeds for CWE-307 (F1=0.6976 at FPR=0.05) but fails for CWE-89 and CWE-434 (F1<=0.21), with transfer strongly dependent on source normal-profile breadth.
-
Risk Averse Alert Prioritization for IDS Using Subnormal Gaussian Fuzzy Models
A subnormal Gaussian fuzzy number model for risk-averse IDS alert prioritization that shows improved robustness over baselines on CIC-IDS2017 and NSL-KDD under detector degradation.
-
SentinelSphere: Integrating AI-Powered Real-Time Threat Detection with Cybersecurity Awareness Training
SentinelSphere integrates an AI threat detector using an enhanced DNN on benchmark datasets with a fine-tuned quantized LLM for user training and awareness.
-
AI-Driven Security Alert Screening and Alert Fatigue Mitigation in Security Operations Centers: A Comprehensive Survey
A literature survey synthesizes 119 studies on AI-driven alert screening into a four-stage taxonomy of filtering, triage, correlation, and generative augmentation while identifying gaps in deployment realism and robustness.
- ML Defender (aRGus NDR): An Open-Source Embedded ML NIDS for Botnet and Anomalous Traffic Detection in Resource-Constrained Organizations