Pith. sign in

REVIEW 3 cited by

The Threat of Adversarial Attacks on Machine Learning in Network Security -- A Survey

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1911.02621 v3 pith:5TVTPHTJ submitted 2019-11-06 cs.CR cs.LGcs.NI

classification cs.CRcs.LGcs.NI
keywords adversarialnetworksecuritymachinelearningattacksapplicationsclassification
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Machine learning models have made many decision support systems to be faster, more accurate, and more efficient. However, applications of machine learning in network security face a more disproportionate threat of active adversarial attacks compared to other domains. This is because machine learning applications in network security such as malware detection, intrusion detection, and spam filtering are by themselves adversarial in nature. In what could be considered an arm's race between attackers and defenders, adversaries constantly probe machine learning systems with inputs that are explicitly designed to bypass the system and induce a wrong prediction. In this survey, we first provide a taxonomy of machine learning techniques, tasks, and depth. We then introduce a classification of machine learning in network security applications. Next, we examine various adversarial attacks against machine learning in network security and introduce two classification approaches for adversarial attacks in network security. First, we classify adversarial attacks in network security based on a taxonomy of network security applications. Secondly, we categorize adversarial attacks in network security into a problem space vs feature space dimensional classification model. We then analyze the various defenses against adversarial attacks on machine learning-based network security applications. We conclude by introducing an adversarial risk grid map and evaluating several existing adversarial attacks against machine learning in network security using the risk grid map. We also identify where each attack classification resides within the adversarial risk grid map.

Discussion (0). Sign in to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Is Crunching Public Data the Right Approach to Detect BGP Hijacks?

    cs.CR 2025-07 conditional novelty 5.0 of 10

    BGP hijackers can make ML-based detectors DFOH and BEAM miss forged-origin hijacks by injecting a few crafted announcements that poison the public monitoring data.

  2. Position: Certified Robustness Does Not (Yet) Imply Model Security

    cs.CR 2025-06 conditional novelty 4.0 of 10

    A certified robustness radius says nothing about whether a sample is clean or correctly predicted, so certification does not yet imply model security.

  3. Mal-D2GAN: Double-Detector based GAN for Malware Generation

    cs.CR 2025-05 reject novelty 4.0 of 10

    Mal-D2GAN, a GAN with two detectors and a least-squares loss, produced adversarial malware that lowered the true positive rate of eight classifiers to near zero on a 20,000-sample dataset.

Pith tools