Pith. sign in

REVIEW 3 major objections 5 minor 122 references

A Review of the Duality of Adversarial Learning in Network Intrusion: Attacks and Countermeasures

T0 review · 3 major / 5 minor · reviewed 2026-08-11 · deepseek-v4-flash

Pith's one-line read This paper claims adversarial learning research focused on network intrusion detection is a small niche, under 10% of the field, bottlenecked by scarce real data, unrealistic feature-space attacks, and outdated benchmarks.

desk verdict Competent but low-novelty NIDS adversarial-ML survey; the headline gap statistic rests on an unreported Dimensions.ai query, but the qualitative conclusions hold up. read the letter →

arxiv 2412.13880 v1 pith:6E5IIO3F submitted 2024-12-18 cs.CR cs.ET

classification cs.CRcs.ET
keywords adversariallearningnetworkintrusiondetectiondatapoisoningtest-timeevasionreverseengineeringbenchmarkdatasetsattackerknowledgedeepsecurity
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This review paper tries to establish that adversarial learning research focused on Network Intrusion Detection Systems (NIDS) is a small, under-studied niche relative to the broader adversarial-learning field, and that its progress is blocked by specific, domain-internal problems. The paper surveys attacks and defenses for three attack families — data poisoning, test-time evasion, and reverse engineering — organized by attacker knowledge (white-box, black-box, gray-box). It argues that scarce real-world attack data, unrealistic feature-space attacks, and outdated benchmark datasets are the main constraints, and that these are more binding than any lack of attack algorithms. A careful reader would care because the size and shape of this gap determines where defensive research should concentrate.

What carries the argument

The organizing device is a three-part cross-cutting taxonomy: attack phase (data poisoning before training, test-time evasion at inference, reverse engineering to extract model or data information) crossed with attacker knowledge (white-box full, black-box zero, gray-box partial). The paper uses this grid to classify the surveyed literature, then overlays a second axis — feature-space versus problem-space attacks — borrowed from prior work to explain why many published attacks are not deployable in real networks. Benchmark datasets (KDD99, NSL-KDD, UNSW-NB15, CIC-IDS2017/2018, CICDDoS2019, CIC IoT 2023) function as the third element, because the authors argue dataset realism and recency determine whether attack and defense results are meaningful.

What would settle it

Run a transparent, reproducible bibliometric search over the scholarly repositories the paper reports using, with published query strings for adversarial learning and for NIDS-specific adversarial learning over 2018–2023, and compare the counts. If the NIDS share reaches or exceeds 10%, or if the claimed five-fold growth does not reproduce, the paper's central gap claim loses its evidentiary foundation.

Watch

Extended reading notes

Core claim

The paper's central claim is that adversarial learning in the NIDS context accounts for less than 10% of all adversarial learning research, even as the broader field has grown roughly five-fold from 2018 to 2023. Within that small body of work, the authors find that most effort has gone to image-, audio-, and video-domain attacks, while NIDS-specific studies remain comparatively rare and are concentrated in test-time evasion, with fewer on data poisoning and reverse engineering. The review identifies the load-bearing obstacles: real network attack data is scarce and hard to share; feature-space perturbations do not translate into actual packet-level attacks; and widely used benchmark datasets such as KDD99 and NSL-KDD are outdated and heavily redundant. The authors position their contribution as a baseline map of the existing research breadth that future work can use to target resilient defense development.

Load-bearing premise

The paper's quantitative headline — that NIDS adversarial learning is under 10% of the field — rests on a web-search query whose exact parameters and deduplication rules are not disclosed in the footnote, so the size of the gap cannot be independently verified from the paper alone.

Editorial extensions

If this is right

  • Future NIDS robustness research should shift priority from novel attack algorithms toward realistic packet-level attack generation and shared real-world traffic data.
  • Defenses validated on image benchmarks cannot be assumed to transfer to network traffic; they must be evaluated in problem space on NIDS-specific datasets.
  • The small size of the NIDS adversarial-learning niche implies that systematic benchmarks and standardized feature sets would have an outsized impact on progress.
  • Reported detection accuracies on KDD99/NSL-KDD are likely optimistic because of heavy redundancy and outdated attack scenarios, so conclusions from those studies should be treated cautiously.
  • Security-by-design approaches and synthetic-data generation from existing attack corpora are the paper's stated directions to close the data-scarcity gap.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • The 'less than 10%' statistic should be read as a provisional estimate: reproducing the web-search query with a disclosed protocol could strengthen or overturn the paper's headline.
  • Because the paper shows reverse engineering often sharpens or enables poisoning and evasion, a unified threat model that treats the three phases as coupled could yield more effective defenses than studying them in isolation.
  • A testable extension is a meta-analysis of the reviewed tables to measure whether data-poisoning studies skew toward older datasets than evasion studies, which would indicate where dataset renewal is most urgent.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 5 minor

Summary. This paper is a survey of adversarial learning in the network intrusion detection (NIDS) domain, organized around three attack families (data poisoning, test-time evasion, reverse engineering) and an attacker-knowledge taxonomy (white-, gray-, black-box). It reviews benchmark NIDS datasets, tabulates representative attacks and defenses, identifies limitations of existing work, and proposes future directions. The paper's headline quantitative claim is that NIDS-specific adversarial learning research is limited, accounting for less than 10% of all adversarial learning research, with a five-fold growth over 2018-2023 (Section 5, Figure 2). This statistic is supported only by an undocumented Dimensions.ai link in footnote 1.

Significance. If the survey's organization and qualitative summaries are reliable, it provides a useful entry point to adversarial learning for NIDS, particularly in bringing together data poisoning, test-time evasion, and reverse engineering under one taxonomy. The paper has concrete strengths: it lists explicit inclusion/exclusion criteria, provides tabular summaries with methods and datasets, discusses dataset limitations with reference to prior analyses, and includes a candid limitations section. However, the central contribution as framed in the abstract and introduction is the identification of a research gap, and that gap is quantified by statistics that are not reproducible from the text. The qualitative observation that NIDS-specific adversarial learning is relatively uncommon is probably correct, but the paper currently asks the reader to take the numerical claims on faith.

major comments (3)
  1. [Section 5 (before Figure 2) and footnote 1] The claims that NIDS adversarial learning research is 'less than 10% of all adversarial learning research' and that the field experienced 'five-fold growth' are not supported by any reproducible analysis. Footnote 1 is only a bare URL to app.dimensions.ai/discover/publication; Table 1 lists search themes rather than actual query strings, and Section 2 mentions 'around hundred initial queries' without specifying query syntax, Boolean operators, date filters, database-specific settings, or deduplication rules. Because the abstract, introduction, and Section 7 all lean on the existence of a research gap, these statistics are load-bearing. The authors should either provide a fully reproducible query protocol (exact query strings, date ranges, databases, deduplication and inclusion steps) with raw counts, or replace the quantitative claim with an explicitly qualitative statement that NIDS-specific work is relatively scarce.
  2. [Table 3, Kuppa et al. row] The placement of Kuppa et al. 2019 [55] as a 'Data Poisoning' attack is a substantive mischaracterization. The cited paper is titled 'Black box attacks on deep anomaly detectors' and describes an evasion-style attack that uses manifold approximation and spherical adversarial subspaces to bypass anomaly detection thresholds; it does not poison training data. The corresponding text in Section 5.4 ('Black-Box DP Attacks') likewise describes an attack on decision thresholds rather than a poisoning attack. This should either be moved to the test-time evasion discussion or removed from the data-poisoning table.
  3. [Section 4 and Section 5.3 (KDD99 duplicate records)] The statement that KDD99 has 'above 75% duplicate records in test and train data' is supported in Section 4 by citations [90, 99], but [90] is the CICIDS2017 dataset paper by Sharafaldin et al., which is not the source of the duplicate-records analysis. That claim originates in Tavallaee et al. [99]. Citing [90] in this context is misleading and should be corrected throughout the dataset discussion.
minor comments (5)
  1. [Figure 2] The figure has no axis labels, numeric values, or source breakdown, so the 'five-fold growth' claim cannot be checked from the figure alone; a small data table or explicit counts would be helpful.
  2. [Section 4] The text says the review focuses on '2018 to 2023-24', but Table 2 excludes material older than five years while several seminal older works (e.g., [25, 41, 97]) are deliberately included. The authors should clarify how older foundational papers were handled under the stated inclusion/exclusion criteria.
  3. [Section 2, Table 1] Table 1 is labelled 'Key Search Queries' but contains search themes rather than query strings; the authors should either rename the table or provide representative actual query examples.
  4. [Section 5.3] There is a typo: 'Sarhen et al.' should be 'Sarhan et al.' (reference [85]).
  5. [Section 5.4] There are minor writing inconsistencies in this subsection, such as 'Alrawashdeh et al. demonstrated... For instance, the researchers analyze...' and later 'was introcuded by Venkatesan et al.'; these should be corrected.

Circularity Check

0 steps flagged · score 2.0 of 10

No significant circularity: the review's claims rest on external literature rather than a self-derived chain; the only self-citation is minor and non-load-bearing.

full rationale

The paper is a survey of adversarial learning attacks and defenses for network intrusion detection systems. There is no fitted parameter, derived equation, or predictive model whose output is constructed from its own inputs, so no step in the paper reduces to a self-definitional identity. The Section 5 statistic that NIDS adversarial learning is 'less than 10% of all adversarial learning research' is supported only by an undocumented Dimensions.ai URL (footnote 1), which is an evidence-reproducibility concern rather than circularity, because the claim is asserted from an external database rather than being manufactured by the paper's own definitions. The paper's research-gap framing is rhetorical and is backed by external prior reviews (e.g., [17, 43, 82]) rather than by renaming the authors' own computations. One self-citation appears (reference [84], by author Saini and Saxena), but it supports a general introductory statement about embedded-system security and plays no load-bearing role in any attack, defense, dataset, or gap analysis in the paper. Consequently, there is no equation-level or argument-level circularity, and the only mild issues are a non-load-bearing self-citation and an under-documented bibliometric source.

Assumptions & free parameters 0 free parameters · 2 assumptions · 0 invented entities

The review introduces no free parameters and no invented entities. Its claims rest on two domain assumptions: that the literature search is representative enough to support quantitative statements, and that the DP/TTE/RE categorization is a valid organizing framework. Both assumptions are plausible but not formally justified with a screening protocol.

assumptions (2)
  • domain assumption The queried databases (IEEE Xplore, ACM, Springer, Google Scholar, Base, arXiv, Dimensions.ai) with the stated inclusion/exclusion criteria capture a representative sample of adversarial learning research in NIDS.
    The quantitative claims (<10%, five-fold growth) depend on this coverage being representative; no screening counts or full query strings are provided.
  • domain assumption The tripartite categorization of attacks into Data Poisoning, Test-Time Evasion, and Reverse Engineering is the appropriate organizing framework for the field.
    The review's structure and gap analysis assume these three families cover the meaningful attack surface; other taxonomies (e.g., poisoning/evasion/transferability) exist in the cited literature.

how reviews work

0 comments
Cite this review

Pith. "Pith review of A Review of the Duality of Adversarial Learning in Network Intrusion: Attacks and Countermeasures." pith.science (2026). https://pith.science/paper/6E5IIO3F

@misc{pith2026241213880,
  author       = {Pith},
  title        = {Pith review of: A Review of the Duality of Adversarial Learning in Network Intrusion: Attacks and Countermeasures},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/6E5IIO3F}},
  note         = {Machine review of arXiv:2412.13880}
}
read the original abstract

Deep learning solutions are instrumental in cybersecurity, harnessing their ability to analyze vast datasets, identify complex patterns, and detect anomalies. However, malevolent actors can exploit these capabilities to orchestrate sophisticated attacks, posing significant challenges to defenders and traditional security measures. Adversarial attacks, particularly those targeting vulnerabilities in deep learning models, present a nuanced and substantial threat to cybersecurity. Our study delves into adversarial learning threats such as Data Poisoning, Test Time Evasion, and Reverse Engineering, specifically impacting Network Intrusion Detection Systems. Our research explores the intricacies and countermeasures of attacks to deepen understanding of network security challenges amidst adversarial threats. In our study, we present insights into the dynamic realm of adversarial learning and its implications for network intrusion. The intersection of adversarial attacks and defenses within network traffic data, coupled with advances in machine learning and deep learning techniques, represents a relatively underexplored domain. Our research lays the groundwork for strengthening defense mechanisms to address the potential breaches in network security and privacy posed by adversarial attacks. Through our in-depth analysis, we identify domain-specific research gaps, such as the scarcity of real-life attack data and the evaluation of AI-based solutions for network traffic. Our focus on these challenges aims to stimulate future research efforts toward the development of resilient network defense strategies.

Figures

Figures reproduced from arXiv: 2412.13880 by the authors.

Figure 1
Figure 1. Data Poisoning, Test-Time Evasion, and Re [PITH_FULL_IMAGE:figures/full_fig_p002_1.png] view at source ↗
Figure 2
Figure 2. 2018-2023: Adversarial Learning Research [PITH_FULL_IMAGE:figures/full_fig_p007_2.png] view at source ↗

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

122 extracted references · 69 canonical work pages

  1. [90]

    Toward generating a new intru- sion detection dataset and intrusion traffic charac- terization

    Iman Sharafaldin, Arash Habibi Lashkari, and Ali A Ghorbani. Toward generating a new intru- sion detection dataset and intrusion traffic charac- terization. ICISSp, 1:108–116, 2018

  2. [99]

    A detailed analysis of the kdd cup 99 data set

    Mahbod Tavallaee, Ebrahim Bagheri, Wei Lu, and Ali A Ghorbani. A detailed analysis of the kdd cup 99 data set. In 2009 IEEE symposium on computational intelligence for security and defense applications, pages 1–6. Ieee, 2009

  3. [55]

    Black box attacks on deep anomaly detectors

    Aditya Kuppa, Slawomir Grzonkowski, Muham- mad Rizwan Asghar, and Nhien-An Le-Khac. Black box attacks on deep anomaly detectors. In Proceedings of the 14th international conference on availability, reliability and security, pages 1–10, 2019

  4. [1]

    https:// www.cisco.com/en/US/technologies/ tk648/tk362/technologies_white_ paper09186a00800a3db9.pdf, Accessed online on 01/10/2024

    Cisco ios netflow version 9 flow-record format - white paper, 2011. https:// www.cisco.com/en/US/technologies/ tk648/tk362/technologies_white_ paper09186a00800a3db9.pdf, Accessed online on 01/10/2024

  5. [2]

    https: //research.unsw.edu.au/projects/ unsw-nb15-dataset, Accessed online on 01/09/2024

    Unsw-nb15 dataset, 2015. https: //research.unsw.edu.au/projects/ unsw-nb15-dataset, Accessed online on 01/09/2024

  6. [3]

    https://www.unb.ca/ cic/datasets/ids-2018.html, Accessed online on 12/20/2023

    Cse-cic-ids2018, 2018. https://www.unb.ca/ cic/datasets/ids-2018.html, Accessed online on 12/20/2023

  7. [4]

    https: //archive.ics.uci.edu/dataset/516/ kitsune+network+attack+dataset, Accessed online on 12/20/2023

    Kitsune network attack dataset, 2019. https: //archive.ics.uci.edu/dataset/516/ kitsune+network+attack+dataset, Accessed online on 12/20/2023

  8. [5]

    https: //cybersecurityonline.utulsa.edu/ blog/why-is-cybersecurity- important-top-six-reasons/ , Accessed online on 11/29/2023

    Why is cybersecurity important?, 2021. https: //cybersecurityonline.utulsa.edu/ blog/why-is-cybersecurity- important-top-six-reasons/ , Accessed online on 11/29/2023

Show all 122 references
  1. [6]

    Linked research data from idea to impact,

  2. [7]

    Gartner forecasts global security and risk management spending to grow 14% in 2024,

  3. [8]

    https: //www.statista.com/statistics/ 325706/global-internet-user- penetration/, Accessed online on 06/04/2024

    Percentage of global population accessing the internet by april 2024, 2024. https: //www.statista.com/statistics/ 325706/global-internet-user- penetration/, Accessed online on 06/04/2024

  4. [9]

    Federated learning for intrusion detection system: Concepts, challenges and future directions

    Shaashwat Agrawal, Sagnik Sarkar, Ons Aouedi, Gokul Yenduri, Kandaraj Piamrat, Mamoun Alazab, Sweta Bhattacharya, Praveen Ku- mar Reddy Maddikunta, and Thippa Reddy Gadekallu. Federated learning for intrusion detection system: Concepts, challenges and future directions. Comput...

  5. [10]

    Inves- tigating adversarial attacks against network intru- sion detection systems in sdns

    James Aiken and Sandra Scott-Hayward. Inves- tigating adversarial attacks against network intru- sion detection systems in sdns. In 2019 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN), pages 1–7. IEEE, 2019

  6. [11]

    Adding robustness to support vec- tor machines against adversarial reverse engineer- ing

    Ibrahim M Alabdulmohsin, Xin Gao, and Xian- gliang Zhang. Adding robustness to support vec- tor machines against adversarial reverse engineer- ing. In Proceedings of the 23rd ACM International Conference on Conference on Information and Knowledge Management, pages 231–240, 201...

  7. [12]

    Adver- sarial machine learning in network intrusion detec- tion domain: A systematic review

    Huda Ali Alatwi and Charles Morisset. Adver- sarial machine learning in network intrusion detec- tion domain: A systematic review. arXiv preprint arXiv:2112.03315, 2021

  8. [13]

    De- fending deep learning based anomaly detection systems against white-box adversarial examples and backdoor attacks

    Khaled Alrawashdeh and Stephen Goldsmith. De- fending deep learning based anomaly detection systems against white-box adversarial examples and backdoor attacks. In 2020 IEEE International Symposium on Technology and Society (ISTAS), pages 294–301. IEEE, 2020

  9. [14]

    A review of big data in network intrusion detection system: Chal- lenges, approaches, datasets, and tools

    Reem Alshamy and Mossa Ghurab. A review of big data in network intrusion detection system: Chal- lenges, approaches, datasets, and tools. Journal of Computer Sciences and Engineering, 8(7):62–74, 2020

  10. [15]

    Secure network intrusion detec- tion system using nid-rnn based deep learn- ing

    S Amutha, R Kavitha, R Srinivasan, and M Kavitha. Secure network intrusion detec- tion system using nid-rnn based deep learn- ing. In 2022 International Conference on Advances in Computing, Communication and Applied Informatics (ACCAI), pages 1–5. IEEE, 2022

  11. [16]

    Reverse engineering of protocols from network traces

    Joao Antunes, Nuno Neves, and Paulo Verissimo. Reverse engineering of protocols from network traces. In 2011 18th Working Conference on Reverse Engineering, pages 169–178. IEEE, 2011

  12. [17]

    Modeling realistic adversarial attacks against net- work intrusion detection systems

    Giovanni Apruzzese, Mauro Andreolini, Luca Fer- retti, Mirco Marchetti, and Michele Colajanni. Modeling realistic adversarial attacks against net- work intrusion detection systems. Digital Threats: Research and Practice (DTRAP), 3(3):1–19, 2022

  13. [18]

    Reverse engineering of generative models: In- ferring model hyperparameters from generated im- ages

    Vishal Asnani, Xi Yin, Tal Hassner, and Xiaoming Liu. Reverse engineering of generative models: In- ferring model hyperparameters from generated im- ages. IEEE Transactions on Pattern Analysis and Machine Intelligence, 2023

  14. [19]

    Synthesizing robust adversarial examples

    Anish Athalye, Logan Engstrom, Andrew Ilyas, and Kevin Kwok. Synthesizing robust adversarial examples. In International conference on machine learning, pages 284–293. PMLR, 2018

  15. [20]

    Reverse tcp and social engineering attacks in the era of big data

    Christine Atwell, Thomas Blasi, and Thaier Haya- jneh. Reverse tcp and social engineering attacks in the era of big data. In 2016 IEEE 2nd International Conference on Big Data Security on Cloud (BigDataSecurity), IEEE International Conference on High Performance and Smart Comp...

  16. [21]

    Model evasion attack on intrusion detection systems using adversarial machine learning

    Md Ahsan Ayub, William A Johnson, Douglas A Talbert, and Ambareen Siraj. Model evasion attack on intrusion detection systems using adversarial machine learning. In 2020 54th annual conference on information sciences and systems (CISS), pages 1–6. IEEE, 2020

  17. [22]

    Recent advances in adversarial train- ing for adversarial robustness

    Tao Bai, Jinqi Luo, Jun Zhao, Bihan Wen, and Qian Wang. Recent advances in adversarial train- ing for adversarial robustness. arXiv preprint arXiv:2102.01356, 2021

  18. [23]

    Malicious packet classification based on neural network using kitsune features

    Tao Ban, Takeshi Takahashi, and Jun’ichi Takeuchi. Malicious packet classification based on neural network using kitsune features. In Intelligent Systems and Pattern Recognition: Second International Conference, ISPR 2022, Hammamet, Tunisia, March 24–26, 2022, Revised Selected...

  19. [24]

    Towards effective feature selection in machine learning- based botnet detection approaches

    Elaheh Biglar Beigi, Hossein Hadian Jazi, Na- talia Stakhanova, and Ali A Ghorbani. Towards effective feature selection in machine learning- based botnet detection approaches. In 2014 IEEE Conference on Communications and Network Security, pages 247–255. IEEE, 2014

  20. [25]

    Evasion at- tacks against machine learning at test time

    Battista Biggio, Igino Corona, Davide Maiorca, Blaine Nelson, Nedim Šrndi´c, Pavel Laskov, Gior- gio Giacinto, and Fabio Roli. Evasion at- tacks against machine learning at test time. In Machine Learning and Knowledge Discovery in Databases: European Conference, ECML PKDD 2013...

  21. [26]

    Wild patterns: Ten years after the rise of adversarial machine learning

    Battista Biggio and Fabio Roli. Wild patterns: Ten years after the rise of adversarial machine learning. Pattern Recognition, 84:317–331, 2018

  22. [27]

    Evad- edroid: A practical evasion attack on machine learning for black-box android malware detection

    Hamid Bostani and Veelasha Moonsamy. Evad- edroid: A practical evasion attack on machine learning for black-box android malware detection. Computers & Security, 139:103676, 2024

  23. [28]

    Sniff: reverse engi- neering of neural networks with fault attacks

    Jakub Breier, Dirmanto Jap, Xiaolu Hou, Shivam Bhasin, and Yang Liu. Sniff: reverse engi- neering of neural networks with fault attacks. IEEE Transactions on Reliability, 71(4):1527– 1539, 2021

  24. [29]

    On evaluating adversarial robustness

    Nicholas Carlini, Anish Athalye, Nicolas Papernot, Wieland Brendel, Jonas Rauber, Dimitris Tsipras, Ian Goodfellow, Aleksander Madry, and Alexey Kurakin. On evaluating adversarial robustness. arXiv preprint arXiv:1902.06705, 2019. 18 Approved for Public Release; Distribution U...

  25. [30]

    De-pois: An attack-agnostic defense against data poisoning attacks

    Jian Chen, Xuxin Zhang, Rui Zhang, Chen Wang, and Ling Liu. De-pois: An attack-agnostic defense against data poisoning attacks. IEEE Transactions on Information Forensics and Security, 16:3412– 3425, 2021

  26. [31]

    Stateful detection of black-box adversarial attacks, 2019

    Steven Chen, Nicholas Carlini, and David Wagner. Stateful detection of black-box adversarial attacks, 2019

  27. [32]

    Intrusion detection for wireless edge networks based on federated learning

    Zhuo Chen, Na Lv, Pengfei Liu, Yu Fang, Kun Chen, and Wu Pan. Intrusion detection for wireless edge networks based on federated learning. IEEE Access, 8:217463–217472, 2020

  28. [33]

    Certified adversarial robustness via randomized smoothing

    Jeremy Cohen, Elan Rosenfeld, and Zico Kolter. Certified adversarial robustness via randomized smoothing. In international conference on machine learning, pages 1310–1320. PMLR, 2019

  29. [34]

    Adversarial attacks against intrusion detection sys- tems: Taxonomy, solutions and open issues

    Igino Corona, Giorgio Giacinto, and Fabio Roli. Adversarial attacks against intrusion detection sys- tems: Taxonomy, solutions and open issues. Information Sciences, 239:201–225, 2013

  30. [35]

    Tad: Transfer learning-based multi- adversarial detection of evasion attacks against network intrusion detection systems

    Islam Debicha, Richard Bauwens, Thibault De- batty, Jean-Michel Dricot, Tayeb Kenaza, and Wim Mees. Tad: Transfer learning-based multi- adversarial detection of evasion attacks against network intrusion detection systems. Future Generation Computer Systems, 138:185–197, 2023

  31. [36]

    Adv-bot: Realistic adversarial botnet at- tacks against network intrusion detection systems

    Islam Debicha, Benjamin Cochez, Tayeb Kenaza, Thibault Debatty, Jean-Michel Dricot, and Wim Mees. Adv-bot: Realistic adversarial botnet at- tacks against network intrusion detection systems. Computers & Security, 129:103176, 2023

  32. [37]

    A hybrid adversarial attack for different application scenarios

    Xiaohu Du, Jie Yu, Zibo Yi, Shasha Li, Jun Ma, Yusong Tan, and Qinbo Wu. A hybrid adversarial attack for different application scenarios. Applied Sciences, 10(10):3559, 2020

  33. [38]

    The state of ransomware in the us: Report and statistics 2022, 2023

    Emsisoft. The state of ransomware in the us: Report and statistics 2022, 2023. https: //www.emsisoft.com/en/blog/43258/ the-state-of-ransomware-in-the- us-report-and-statistics-2022/ , Accessed online on 11/30/2023

  34. [39]

    Backdoor attacks and countermea- sures on deep learning: A comprehensive review

    Yansong Gao, Bao Gia Doan, Zhi Zhang, Siqi Ma, Jiliang Zhang, Anmin Fu, Surya Nepal, and Hy- oungshick Kim. Backdoor attacks and countermea- sures on deep learning: A comprehensive review. arXiv preprint arXiv:2007.10760, 2020

  35. [40]

    A detailed anal- ysis of benchmark datasets for network intrusion detection system

    Mossa Ghurab, Ghaleb Gaphari, Faisal Alshami, Reem Alshamy, and Suad Othman. A detailed anal- ysis of benchmark datasets for network intrusion detection system. Asian Journal of Research in Computer Science, 7(4):14–33, 2021

  36. [41]

    Explaining and harnessing adversarial ex- amples

    Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. Explaining and harnessing adversarial ex- amples. arXiv preprint arXiv:1412.6572, 2014

  37. [42]

    Evaluating and improving adversarial ro- bustness of machine learning-based network intru- sion detectors

    Dongqi Han, Zhiliang Wang, Ying Zhong, Wenqi Chen, Jiahai Yang, Shuqiang Lu, Xingang Shi, and Xia Yin. Evaluating and improving adversarial ro- bustness of machine learning-based network intru- sion detectors. IEEE Journal on Selected Areas in Communications, 39(8):2632–2647, 2021

  38. [43]

    Adversarial machine learning for network intrusion detection systems: a compre- hensive survey

    Ke He, Dan Dongseong Kim, and Muham- mad Rizwan Asghar. Adversarial machine learning for network intrusion detection systems: a compre- hensive survey. IEEE Communications Surveys & Tutorials, 2023

  39. [44]

    Li- uer mihou: A practical framework for generating and evaluating grey-box adversarial attacks against nids

    Ke He, Dan Dongseong Kim, Jing Sun, Jeong Do Yoo, Young Hun Lee, and Huy Kang Kim. Li- uer mihou: A practical framework for generating and evaluating grey-box adversarial attacks against nids. arXiv preprint arXiv:2204.06113, 2022

  40. [45]

    Fooling neural network interpretations via adver- sarial model manipulation

    Juyeon Heo, Sunghwan Joo, and Taesup Moon. Fooling neural network interpretations via adver- sarial model manipulation. Advances in neural information processing systems, 32, 2019

  41. [46]

    Deep packgen: A deep reinforcement learning framework for adversarial network packet generation

    Soumyadeep Hore, Jalal Ghadermazi, Diwas Paudel, Ankit Shah, Tapas K Das, and Nathaniel D Bastian. Deep packgen: A deep reinforcement learning framework for adversarial network packet generation. arXiv preprint arXiv:2305.11039, 2023

  42. [47]

    The threat of adversarial attacks on machine learning in network security–a survey

    Olakunle Ibitoye, Rana Abou-Khamis, Ashraf Matrawy, and M Omair Shafiq. The threat of adversarial attacks on machine learning in network security–a survey. arXiv preprint arXiv:1911.02621, 2019

  43. [48]

    Inves- tigation malware analysis depend on reverse en- gineering

    Maher F Ismael and Karam H Thanoon. Inves- tigation malware analysis depend on reverse en- gineering. In 2022 International Conference on Data Science and Intelligent Computing (ICDSIC), pages 251–256. IEEE, 2022

  44. [49]

    A deep learning approach for net- work intrusion detection system

    Ahmad Javaid, Quamar Niyaz, Weiqing Sun, and Mansoor Alam. A deep learning approach for net- work intrusion detection system. In Proceedings of the 9th EAI International Conference on 19 Approved for Public Release; Distribution Unlimited: AFRL-2023-2308, 12 May 2023 Bio-inspi...

  45. [50]

    Adver- sarial machine learning for network intrusion de- tection: A comparative study

    Houda Jmila and Mohamed Ibn Khedher. Adver- sarial machine learning for network intrusion de- tection: A comparative study. Computer Networks, 214:109073, 2022

  46. [51]

    Deep learning for intrusion detection and security of internet of things (iot): current analysis, challenges, and possible solu- tions

    Amjad Rehman Khan, Muhammad Kashif, Rutvij H Jhaveri, Roshani Raut, Tanzila Saba, and Saeed Ali Bahaj. Deep learning for intrusion detection and security of internet of things (iot): current analysis, challenges, and possible solu- tions. Security and Communication Networks, 2...

  47. [52]

    Channel-aware adversarial attacks against deep learning-based wireless signal classifiers

    Brian Kim, Yalin E Sagduyu, Kemal Davaslioglu, Tugba Erpek, and Sennur Ulukus. Channel-aware adversarial attacks against deep learning-based wireless signal classifiers. IEEE Transactions on Wireless Communications, 21(6):3868–3880, 2021

  48. [53]

    Deep learning- based network intrusion detection using multiple image transformers

    Taehoon Kim and Wooguil Pak. Deep learning- based network intrusion detection using multiple image transformers. Applied Sciences, 13(5):2754, 2023

  49. [54]

    Reverse engineering of net- work signatures

    C Kruegel, D Mutz, W Robertson, G Vigna, and R Kemmerer. Reverse engineering of net- work signatures. In Proceedings of the AusCERT Asia Pacific Information Technology Security Conference, Gold Coast, Australia, 2005

  50. [56]

    Two-phase defense against poisoning attacks on federated learning- based intrusion detection

    Yuan-Cheng Lai, Jheng-Yan Lin, Ying-Dar Lin, Ren-Hung Hwang, Po-Chin Lin, Hsiao-Kuang Wu, and Chung-Kuan Chen. Two-phase defense against poisoning attacks on federated learning- based intrusion detection. Computers & Security, 129:103205, 2023

  51. [57]

    Survey on intrusion detec- tion systems based on deep learning

    Ali Azawii Abdul Lateef, Sufyan Al-Janabi, and Belal Al-Khateeb. Survey on intrusion detec- tion systems based on deep learning. Periodicals of Engineering and Natural Sciences, 7(3):1074– 1095, 2019

  52. [58]

    A review of adversarial at- tack and defense for classification methods

    Yao Li, Minhao Cheng, Cho-Jui Hsieh, and Thomas CM Lee. A review of adversarial at- tack and defense for classification methods. The American Statistician, 76(4):329–345, 2022

  53. [59]

    Deeppayload: Black-box backdoor attack on deep learning models through neural payload injection

    Yuanchun Li, Jiayi Hua, Haoyu Wang, Chunyang Chen, and Yunxin Liu. Deeppayload: Black-box backdoor attack on deep learning models through neural payload injection. In 2021 IEEE/ACM 43rd International Conference on Software Engineering (ICSE), pages 263–274. IEEE, 2021

  54. [60]

    Machine learning and deep learning methods for intrusion detection sys- tems: A survey

    Hongyu Liu and Bo Lang. Machine learning and deep learning methods for intrusion detection sys- tems: A survey. applied sciences, 9(20):4396, 2019

  55. [61]

    Mitigating reverse engineering attacks on deep neural networks

    Yuntao Liu, Dana Dachman-Soled, and Ankur Sri- vastava. Mitigating reverse engineering attacks on deep neural networks. In 2019 IEEE Computer Society Annual Symposium on VLSI (ISVLSI), pages 657–662. IEEE, 2019

  56. [62]

    Functionality-preserving ad- versarial machine learning for robust classification in cybersecurity and intrusion detection domains: A survey

    Andrew McCarthy, Essam Ghadafi, Panagiotis An- driotis, and Phil Legg. Functionality-preserving ad- versarial machine learning for robust classification in cybersecurity and intrusion detection domains: A survey. Journal of Cybersecurity and Privacy, 2(1):154–190, 2022

  57. [63]

    Black-box model inversion attribute inference at- tacks on classification models

    Shagufta Mehnaz, Ninghui Li, and Elisa Bertino. Black-box model inversion attribute inference at- tacks on classification models. arXiv preprint arXiv:2012.03404, 2020

  58. [64]

    Is deep learning safe for robot vision? adversar- ial examples against the icub humanoid

    Marco Melis, Ambra Demontis, Battista Biggio, Gavin Brown, Giorgio Fumera, and Fabio Roli. Is deep learning safe for robot vision? adversar- ial examples against the icub humanoid. CoRR, abs/1708.06939, 2017

  59. [65]

    Inves- tigating the practicality of adversarial evasion at- tacks on network intrusion detection

    Mohamed Amine Merzouk, Frédéric Cuppens, Nora Boulahia-Cuppens, and Reda Yaich. Inves- tigating the practicality of adversarial evasion at- tacks on network intrusion detection. Annals of Telecommunications, 77(11-12):763–775, 2022

  60. [66]

    Gradient-based adversarial attack detection via deep feature extrac- tion

    Andy Michel and Rickard Ewetz. Gradient-based adversarial attack detection via deep feature extrac- tion. In SoutheastCon 2022, pages 213–220. IEEE, 2022

  61. [67]

    Adversarial learning targeting deep neural network classification: A comprehensive review of defenses against attacks

    David J Miller, Zhen Xiang, and George Ke- sidis. Adversarial learning targeting deep neural network classification: A comprehensive review of defenses against attacks. Proceedings of the IEEE, 108(3):402–433, 2020. 20 Approved for Public Release; Distribution Unlimited: AFRL-...

  62. [68]

    Kitsune: an ensemble of au- toencoders for online network intrusion detection

    Yisroel Mirsky, Tomer Doitshman, Yuval Elovici, and Asaf Shabtai. Kitsune: an ensemble of au- toencoders for online network intrusion detection. arXiv preprint arXiv:1802.09089, 2018

  63. [69]

    An ensemble intrusion detection technique based on proposed statistical flow features for protecting network traffic of in- ternet of things

    Nour Moustafa, Benjamin Turnbull, and Kim- Kwang Raymond Choo. An ensemble intrusion detection technique based on proposed statistical flow features for protecting network traffic of in- ternet of things. IEEE Internet of Things Journal, 6(3):4815–4830, 2018

  64. [70]

    Machine learning for anomaly detection: A systematic review

    Ali Bou Nassif, Manar Abu Talib, Qassim Nasir, and Fatima Mohamad Dakalbab. Machine learning for anomaly detection: A systematic review. Ieee Access, 9:78658–78700, 2021

  65. [71]

    Ciciot2023: A real-time dataset and benchmark for large-scale attacks in iot environment, 2023

    Euclides Carlos Pinto Neto, Sajjad Dadkhah, Raphael Ferreira, Alireza Zohourian, Rongxing Lu, and Ali A Ghorbani. Ciciot2023: A real-time dataset and benchmark for large-scale attacks in iot environment, 2023

  66. [72]

    Invisible poison: A blackbox clean label backdoor attack to deep neural networks

    Rui Ning, Jiang Li, Chunsheng Xin, and Hongyi Wu. Invisible poison: A blackbox clean label backdoor attack to deep neural networks. In IEEE INFOCOM 2021-IEEE Conference on Computer Communications, pages 1–10. IEEE, 2021

  67. [73]

    Practical black-box attacks against ma- chine learning

    Nicolas Papernot, Patrick McDaniel, Ian Goodfel- low, Somesh Jha, Z Berkay Celik, and Ananthram Swami. Practical black-box attacks against ma- chine learning. In Proceedings of the 2017 ACM on Asia conference on computer and communications security, pages 506–519, 2017

  68. [74]

    Distillation as a defense to adversarial perturbations against deep neural networks

    Nicolas Papernot, Patrick McDaniel, Xi Wu, Somesh Jha, and Ananthram Swami. Distillation as a defense to adversarial perturbations against deep neural networks. In 2016 IEEE symposium on security and privacy (SP), pages 582–597. IEEE, 2016

  69. [75]

    Label sanitization against label flipping poisoning attacks

    Andrea Paudice, Luis Muñoz-González, and Emil C Lupu. Label sanitization against label flipping poisoning attacks. In ECML PKDD 2018 Workshops: Nemesis 2018, UrbReas 2018, SoGood 2018, IW AISe 2018, and Green Data Mining 2018, Dublin, Ireland, September 10-14, 2018, Proceeding...

  70. [76]

    Defending network intrusion detec- tion systems against adversarial evasion attacks

    Marek Pawlicki, Michał Chora ´s, and Rafał Kozik. Defending network intrusion detec- tion systems against adversarial evasion attacks. Future Generation Computer Systems, 110:148– 154, 2020

  71. [77]

    A deep learning method to detect network intrusion through flow-based features

    Abdurrahman Pekta¸ s and Tankut Acarman. A deep learning method to detect network intrusion through flow-based features. International Journal of Network Management, 29(3):e2050, 2019

  72. [78]

    Intriguing proper- ties of adversarial ml attacks in the problem space, 2020

    Fabio Pierazzi, Feargus Pendlebury, Jacopo Cortel- lazzi, and Lorenzo Cavallaro. Intriguing proper- ties of adversarial ml attacks in the problem space, 2020

  73. [79]

    Review of kdd cup ‘99, nsl- kdd and kyoto 2006+ datasets

    Danijela D Proti ´c. Review of kdd cup ‘99, nsl- kdd and kyoto 2006+ datasets. V ojnotehniˇcki glasnik/Military Technical Courier, 66(3):580– 596, 2018

  74. [80]

    Flow-based benchmark data sets for intrusion detection

    Markus Ring, Sarah Wunderlich, Dominik Grüdl, Dieter Landes, and Andreas Hotho. Flow-based benchmark data sets for intrusion detection. In Proceedings of the 16th European conference on cyber warfare and security. ACPI, pages 361–369, 2017

  75. [81]

    A sur- vey of network-based intrusion detection data sets

    Markus Ring, Sarah Wunderlich, Deniz Scheur- ing, Dieter Landes, and Andreas Hotho. A sur- vey of network-based intrusion detection data sets. Computers & Security, 86:147–167, 2019

  76. [82]

    Adversarial machine learning at- tacks and defense methods in the cyber security do- main

    Ishai Rosenberg, Asaf Shabtai, Yuval Elovici, and Lior Rokach. Adversarial machine learning at- tacks and defense methods in the cyber security do- main. ACM Computing Surveys (CSUR), 54(5):1– 36, 2021

  77. [83]

    Adversarial network traffic: Towards evaluating the robustness of deep-learning-based network traffic classification

    Amir Mahdi Sadeghzadeh, Saeed Shiravi, and Ra- sool Jalili. Adversarial network traffic: Towards evaluating the robustness of deep-learning-based network traffic classification. IEEE Transactions on Network and Service Management, 18(2):1962– 1976, 2021

  78. [84]

    Predatory medicine: Exploring and measuring the vulnera- bility of medical ai to predatory science

    Shalini Saini and Nitesh Saxena. Predatory medicine: Exploring and measuring the vulnera- bility of medical ai to predatory science. arXiv preprint arXiv:2203.06245, 2022

  79. [85]

    Towards a standard feature set for net- work intrusion detection system datasets

    Mohanad Sarhan, Siamak Layeghy, and Marius Portmann. Towards a standard feature set for net- work intrusion detection system datasets. Mobile networks and applications, pages 1–14, 2022

  80. [86]

    Just how toxic is data poisoning? a unified bench- mark for backdoor and data poisoning attacks

    Avi Schwarzschild, Micah Goldblum, Arjun Gupta, John P Dickerson, and Tom Goldstein. Just how toxic is data poisoning? a unified bench- mark for backdoor and data poisoning attacks. In International Conference on Machine Learning, pages 9389–9398. PMLR, 2021. 21 Approved for P...

  81. [87]

    {Explanation-Guided} backdoor poison- ing attacks against malware classifiers

    Giorgio Severi, Jim Meyer, Scott Coull, and Alina Oprea. {Explanation-Guided} backdoor poison- ing attacks against malware classifiers. In 30th USENIX security symposium (USENIX security 21), pages 1487–1504, 2021

  82. [88]

    Poison frogs! tar- geted clean-label poisoning attacks on neural net- works

    Ali Shafahi, W Ronny Huang, Mahyar Najibi, Octavian Suciu, Christoph Studer, Tudor Dumi- tras, and Tom Goldstein. Poison frogs! tar- geted clean-label poisoning attacks on neural net- works. Advances in neural information processing systems, 31, 2018

  83. [89]

    The sunburst hack was massive and devastating, 2021

    Paulo Shakarian. The sunburst hack was massive and devastating, 2021. https: //www.salon.com/2021/01/04/the- sunburst-hack-was-massive-and- devastating--5-observations-from- a-cybersecurity-expert_partner/, Accessed online on 11/29/2023

  84. [91]

    Developing realistic distributed denial of service (ddos) attack dataset and taxonomy

    Iman Sharafaldin, Arash Habibi Lashkari, Saqib Hakak, and Ali A Ghorbani. Developing realistic distributed denial of service (ddos) attack dataset and taxonomy. In 2019 International Carnahan Conference on Security Technology (ICCST), pages 1–8. IEEE, 2019

  85. [92]

    Evasion and causative attacks with adversarial deep learn- ing

    Yi Shi and Yalin E Sagduyu. Evasion and causative attacks with adversarial deep learn- ing. In MILCOM 2017-2017 IEEE Military Communications Conference (MILCOM), pages 243–248. IEEE, 2017

  86. [93]

    Toward developing a systematic approach to generate benchmark datasets for intru- sion detection

    Ali Shiravi, Hadi Shiravi, Mahbod Tavallaee, and Ali A Ghorbani. Toward developing a systematic approach to generate benchmark datasets for intru- sion detection. computers & security, 31(3):357– 374, 2012

  87. [94]

    A deep learning approach to network intrusion detection

    Nathan Shone, Tran Nguyen Ngoc, Vu Dinh Phai, and Qi Shi. A deep learning approach to network intrusion detection. IEEE transactions on emerging topics in computational intelligence, 2(1):41–50, 2018

  88. [95]

    Statistical analysis of honeypot data and build- ing of kyoto 2006+ dataset for nids evaluation

    Jungsuk Song, Hiroki Takakura, Yasuo Okabe, Masashi Eto, Daisuke Inoue, and Koji Nakao. Statistical analysis of honeypot data and build- ing of kyoto 2006+ dataset for nids evaluation. In Proceedings of the first workshop on building analysis datasets and gathering experience ...

  89. [96]

    Adversarial at- tacks against deep generative models on data: a survey

    Hui Sun, Tianqing Zhu, Zhiqiu Zhang, Dawei Jin, Ping Xiong, and Wanlei Zhou. Adversarial at- tacks against deep generative models on data: a survey. IEEE Transactions on Knowledge and Data Engineering, 2021

  90. [97]

    Intriguing properties of neural networks

    Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Good- fellow, and Rob Fergus. Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199, 2013

  91. [98]

    A sensitivity analysis of poisoning and evasion attacks in network intrusion detection system machine learning models

    Kevin Talty, John Stockdale, and Nathaniel D Bastian. A sensitivity analysis of poisoning and evasion attacks in network intrusion detection system machine learning models. In MILCOM 2021-2021 IEEE Military Communications Conference (MILCOM), pages 1011–1016. IEEE, 2021

  92. [100]

    A review of the advancement in intrusion detection datasets

    Ankit Thakkar and Ritika Lohiya. A review of the advancement in intrusion detection datasets. Procedia Computer Science, 167:636–645, 2020

  93. [101]

    Data poisoning at- tacks against federated learning systems

    Vale Tolpegin, Stacey Truex, Mehmet Emre Gursoy, and Ling Liu. Data poisoning at- tacks against federated learning systems. In Computer Security–ESORICS 2020: 25th European Symposium on Research in Computer Security, ESORICS 2020, Guildford, UK, September 14–18, 2020, Proceedi...

  94. [102]

    Ensemble adversarial training: Attacks and defenses

    Florian Tramèr, Alexey Kurakin, Nicolas Paper- not, Ian Goodfellow, Dan Boneh, and Patrick Mc- Daniel. Ensemble adversarial training: Attacks and defenses. arXiv preprint arXiv:1705.07204, 2017

  95. [103]

    On adversarial examples and stealth attacks in artificial intelligence systems

    Ivan Y Tyukin, Desmond J Higham, and Alexan- der N Gorban. On adversarial examples and stealth attacks in artificial intelligence systems. In 2020 International Joint Conference on Neural Networks (IJCNN), pages 1–6. IEEE, 2020

  96. [104]

    Poisoning attacks and data sanitization mitigations for machine learning models in net- work intrusion detection systems

    Sridhar Venkatesan, Harshvardhan Sikka, Rauf Izmailov, Ritu Chadha, Alina Oprea, and Michael J De Lucia. Poisoning attacks and data sanitization mitigations for machine learning models in net- work intrusion detection systems. In MILCOM 2021-2021 IEEE Military Communications C...

  97. [105]

    Sok: Realistic adversarial attacks and defenses for intel- ligent network intrusion detection

    João Vitorino, Isabel Praça, and Eva Maia. Sok: Realistic adversarial attacks and defenses for intel- ligent network intrusion detection. Computers & Security, page 103433, 2023

  98. [106]

    Neural cleanse: Identifying and mitigating backdoor attacks in neural networks

    Bolun Wang, Yuanshun Yao, Shawn Shan, Huiy- ing Li, Bimal Viswanath, Haitao Zheng, and Ben Y Zhao. Neural cleanse: Identifying and mitigating backdoor attacks in neural networks. In 2019 IEEE Symposium on Security and Privacy (SP), pages 707–723. IEEE, 2019

  99. [107]

    In- trusion detection using few-shot learning based on triplet graph convolutional network

    Yue Wang, Yiming Jiang, and Julong Lan. In- trusion detection using few-shot learning based on triplet graph convolutional network. Journal of Web Engineering, 20(5):1527–1552, 2021

  100. [108]

    When not to classify: Detection of re- verse engineering attacks on dnn image classi- fiers

    Yujia Wang, David J Miller, and George Ke- sidis. When not to classify: Detection of re- verse engineering attacks on dnn image classi- fiers. In ICASSP 2019-2019 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP), pages 8063–8066. IEEE, 2019

  101. [109]

    Robust learning for data poisoning attacks

    Yunjuan Wang, Poorya Mianjy, and Raman Arora. Robust learning for data poisoning attacks. In International Conference on Machine Learning, pages 10859–10869. PMLR, 2021

  102. [110]

    In- visible adversarial attack against deep neural networks: An adaptive penalization approach

    Zhibo Wang, Mengkai Song, Siyan Zheng, Zhifei Zhang, Yang Song, and Qian Wang. In- visible adversarial attack against deep neural networks: An adaptive penalization approach. IEEE Transactions on Dependable and Secure Computing, 18(3):1474–1488, 2019

  103. [111]

    11 ad- versarial perturbations of deep neural networks

    David Warde-Farley and Ian Goodfellow. 11 ad- versarial perturbations of deep neural networks. Perturbations, Optimization, and Statistics, 311(5), 2016

  104. [112]

    Reverse engineering imperceptible backdoor at- tacks on deep neural networks for detection and training set cleansing

    Zhen Xiang, David J Miller, and George Kesidis. Reverse engineering imperceptible backdoor at- tacks on deep neural networks for detection and training set cleansing. Computers & Security, 106:102280, 2021

  105. [113]

    Targeted poisoning attacks on black- box neural machine translation

    Chang Xu, Jun Wang, Yuqing Tang, Francisco Guzmán, Benjamin IP Rubinstein, and Trevor Cohn. Targeted poisoning attacks on black- box neural machine translation. arXiv preprint arXiv:2011.00675, 2020

  106. [114]

    Adversar- ial attacks and defenses in images, graphs and text: A review

    Han Xu, Yao Ma, Hao-Chen Liu, Debayan Deb, Hui Liu, Ji-Liang Tang, and Anil K Jain. Adversar- ial attacks and defenses in images, graphs and text: A review. International Journal of Automation and Computing, 17:151–178, 2020

  107. [115]

    Defending against backdoor at- tack on deep neural networks

    Kaidi Xu, Sijia Liu, Pin-Yu Chen, Pu Zhao, and Xue Lin. Defending against backdoor at- tack on deep neural networks. arXiv preprint arXiv:2002.12162, 2020

  108. [116]

    Towards reverse engineering controller area network messages using machine learning

    Clinton Young, Jordan Svoboda, and Joseph Zam- breno. Towards reverse engineering controller area network messages using machine learning. In 2020 IEEE 6th World Forum on Internet of Things (WF-IoT), pages 1–6. IEEE, 2020

  109. [117]

    Tiki-taka: Attacking and defending deep learning-based intrusion detection systems

    Chaoyun Zhang, Xavier Costa-Pérez, and Paul Patras. Tiki-taka: Attacking and defending deep learning-based intrusion detection systems. In Proceedings of the 2020 ACM SIGSAC Conference on Cloud Computing Security Workshop, pages 27–39, 2020

  110. [118]

    Adversarial attacks against deep learning- based network intrusion detection systems and de- fense mechanisms

    Chaoyun Zhang, Xavier Costa-Perez, and Paul Pa- tras. Adversarial attacks against deep learning- based network intrusion detection systems and de- fense mechanisms. IEEE/ACM Transactions on Networking, 30(3):1294–1311, 2022

  111. [119]

    Robust feature learning for adversarial defense via hierarchical feature alignment

    Xiaoqin Zhang, Jinxin Wang, Tao Wang, Runhua Jiang, Jiawei Xu, and Li Zhao. Robust feature learning for adversarial defense via hierarchical feature alignment. Information Sciences, 560:256– 270, 2021

  112. [120]

    Adversarial attacks and defenses in deep learning: From a perspec- tive of cybersecurity

    Shuai Zhou, Chi Liu, Dayong Ye, Tianqing Zhu, Wanlei Zhou, and Philip S Yu. Adversarial attacks and defenses in deep learning: From a perspec- tive of cybersecurity. ACM Computing Surveys, 55(8):1–39, 2022. 23

  113. [2022]

    https://www.dimensions.ai/, Ac- cessed online on 02/24/2024

  114. [2023]

    https://www.gartner.com/en/ newsroom/press-releases/2023- 09-28-gartner-forecasts-global- security-and-risk-management- spending-to-grow-14-percent-in- 2024, Accessed online on 11/29/2023

Pith tools

Reviewed August 11, 2026 · model on record in the stance chip above.