Pith. sign in

REVIEW 2 major objections 6 minor 1 cited by

Security and Privacy of Digital Twins for Advanced Manufacturing: A Survey

T0 review · 2 major / 6 minor · reviewed 2026-08-11 · deepseek-v4-flash

Pith's one-line read The paper argues that digital twins for advanced manufacturing face numerous and inadequately explored security and privacy vulnerabilities across data collection, data sharing, machine learning, and system-level operations, and it…

desk verdict A useful map for data-collection, data-sharing, and system-level security in manufacturing digital twins, but the ML/DL threat section imports a CV/NLP taxonomy without showing it transfers, so the survey's central claim is only half-supported. read the letter →

arxiv 2412.13939 v1 pith:VMQAFPI7 submitted 2024-12-18 eess.SY cs.SY

classification eess.SYcs.SY
keywords digitaltwinadvancedmanufacturingcybersecurityprivacymachinelearningsecuritydatasharingblockchainIndustry4.0
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This survey argues that digital twins in advanced manufacturing are exposed to security and privacy vulnerabilities at every stage of their lifecycle, from data collection through data sharing to the machine-learning models that power prediction and control. It organizes the threat landscape into four categories—data collection, data sharing, machine learning/deep learning, and system-level operations—and pairs each with candidate countermeasures. The central claim is that these vulnerabilities are numerous and inadequately explored, and that combining defenses such as blockchain-based provenance, access control, encryption, differential privacy, homomorphic encryption, secure multiparty computation, trusted execution environments, and anomaly detection can establish more trust in digital twins. The stakes matter because a digital twin failure can affect both the physical production line and the data-driven decisions built on it.

What carries the argument

The central organizing device is a four-part threat taxonomy for digital twins in advanced manufacturing: data collection, data sharing, machine learning/deep learning, and system-level operations. Within the ML/DL category, the paper uses the deep-learning lifecycle—training versus testing phases—as its organizing axis, placing data poisoning and backdoor attacks at training and model extraction, model inversion, membership inference, and adversarial attacks at testing, then matching each to defenses such as differential privacy, homomorphic encryption, secure multiparty computation, and trusted execution environments. This taxonomy carries the argument by turning a diffuse set of reported vulnerabilities into a structured checklist against which the paper matches countermeasures.

What would settle it

A direct falsifying test would be to run standard adversarial perturbations, membership inference, and model extraction attacks on a representative manufacturing digital-twin pipeline (sensor data to model to control action); if these attacks produce mispredictions or privacy leakage comparable to the image or text settings, the transfer assumption holds, and if physical constraints or control-loop feedback suppress them, it is weakened.

Watch

Extended reading notes

Core claim

On its own terms, the paper establishes a taxonomy of security and privacy threats to manufacturing digital twins, grouped into data collection (insider and privilege-escalation attacks, side-channel and man-in-the-middle attacks, denial of service), data sharing (provenance, storage, access control, safeguarding), machine learning and deep learning (model extraction, membership inference, adversarial attacks, poisoning attacks, and their defenses), and system-level security (anomaly detection and framework design). It contends that these threats are inadequately explored in the manufacturing context and that applying ML/DL models in manufacturing digital twins will inevitably raise the same security and privacy concerns as in computer vision and natural language processing. The paper's contribution is the synthesis: a structured map from attack surface to countermeasure across the whole digital-twin lifecycle.

Load-bearing premise

The load-bearing premise is that the ML/DL threat taxonomy imported from computer vision and natural language processing transfers unchanged to manufacturing digital twins operating on sensor data, control loops, and proprietary process models.

Editorial extensions

If this is right

  • Securing a manufacturing digital twin requires coordinated defenses at data collection, sharing, model training, and system level, not just network hardening.
  • Blockchain with smart contracts becomes a primary mechanism for data provenance, access control, and tamper-resistant audit trails in digital-twin data sharing.
  • ML/DL-based digital twins should be treated as vulnerable to adversarial and poisoning attacks, so model update and uncertainty-quantification pipelines need their own security controls.
  • Anomaly detection on both the digital replica and the physical system is a workable system-level defense, and defense-in-depth with isolation and pre-defined trust levels is a baseline requirement.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • The paper leaves implicit that its taxonomy argues for treating security and privacy as first-class design constraints at each digital-twin lifecycle stage, rather than as post-deployment additions.
  • Because the ML/DL threat model is imported from computer vision and NLP, a direct next step is to test whether sensor time-series and control-loop data show the same perturbation sensitivity as images, or whether physical constraints blunt the attacks.
  • The surveyed defenses carry real-time and computational costs that production settings often cannot absorb; benchmarking them on realistic manufacturing data with latency and throughput limits would test whether the proposed trust mechanisms are deployable.
  • The blockchain-based solutions point toward hybrid architectures that store hashes and metadata on-chain and raw sensor data off-chain; quantifying the actual integrity guarantees of such hybrids under insider access is an open question.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

2 major / 6 minor

Summary. This survey addresses security and privacy of digital twins in advanced manufacturing. It organizes the material into four categories: data collection (hardware/software attacks and countermeasures), data sharing (provenance, storage, access control, blockchain), machine learning/deep learning (privacy attacks, adversarial attacks, poisoning, defenses, plus model update/decision-making/UQ), and system-level security (anomaly detection and frameworks). For each category it lists representative attacks and defenses and concludes with opportunities and challenges. The paper's central descriptive claim is that digital twin adoption in advanced manufacturing introduces numerous, underexplored security and privacy vulnerabilities and that the surveyed countermeasures can contribute to trust.

Significance. The survey's value lies in its breadth: it collects a wide range of references, identifies concrete examples (Triton, DHALSIM, model extraction, membership inference, BadNet, clean-label poisoning), and organizes defenses (differential privacy, homomorphic encryption, secure multi-party computation, trusted execution environments, blockchain). It also makes a useful distinction between DT-specific and adjacent ICS anomaly-detection work in Table 3. The paper is an ordinary citation-based survey, so there is no derivation or prediction to verify; its correctness depends on accurate representation of the cited literature. If the ML/DL transfer question is resolved, the survey could serve as a useful entry point to the area.

major comments (2)
  1. [Section 4, including §4.1-§4.5 and Tables 1-2] Section 4 does not establish that the CV/NLP-derived ML/DL threat taxonomy transfers to manufacturing digital twins. The section first asserts that applying ML/DL in manufacturing digital twins 'will inevitably raise security and privacy concerns' and states that the surveyed literature 'could be applied to the context of digital twins in advanced manufacturing'; §4.3-§4.5 then repeatedly say model updates, decision-making, and uncertainty quantification 'might have cybersecurity issues discussed in subsection 4.1 and subsection 4.2.' None of the cited attacks or defenses in §4.1-§4.2 is shown to involve sensor streams, control loops, or digital-twin architectures; several entries, such as the one-pixel attack [162], JPEG-compression defenses [34, 184], and image super-resolution defenses [122], are image-specific and are not adapted to time-series or physically constrained manufacturing data. As written, the ML/DL pillar of the central claim is a hypothesis rather than an analysis, which is stronger than the abstract's claim to 'analyze' these threats. The revision should either supply manufacturing-specific evidence or explicitly reframe this section as open research directions.
  2. [Abstract and Section 7] The survey does not report a systematic search protocol, so its coverage claim cannot be independently assessed. The manuscript describes itself as comprehensive ('a comprehensive exploration' in Section 7) and claims in the abstract that numerous vulnerabilities 'remain inadequately explored,' but it does not specify databases, time range, keywords, or inclusion criteria; Section 4 relies on 'to the best of our knowledge' and 'gathers relevant literature.' A reproducible search and screening description, or an explicit statement that this is a narrative/illustrative review, is needed to calibrate the central descriptive claim.
minor comments (6)
  1. [Table 1] The entry 'Trust Execution Environment' should be 'Trusted Execution Environment.'
  2. [Table 1 and §4.1.1] The Model Extraction row of Table 1 includes reference [177], but the corresponding text in §4.1.1 does not discuss it; the citation should either be integrated into the narrative or removed from the table.
  3. [References [47] and [48]; §2.2 and §3.4] References [47] and [48] are bibliographically identical (Gehrmann and Gunnarsson 2020, same title, venue, and pages). Section 3.4 cites [48] as if it further explores access control for sharing data with external digital twins or third parties, but since [48] is the same paper as [47], that claim lacks the independent support it appears to have. The duplicate should be removed and the access-control statement re-cited to a genuinely different work or qualified.
  4. [Table 3] Table 3's 'Digital Twin' column marks many entries as 'No'; the table header, 'Summary of Research on System Security and Digital Twin in Advanced Manufacturing,' should clarify that these rows are adjacent ICS/critical-infrastructure studies rather than digital-twin security studies, so readers are not misled about the directness of the evidence.
  5. [§4.3, §4.4, §4.5] The phrase 'might have cybersecurity issues discussed in subsection 4.1 and subsection 4.2' is repeated in each of these subsections; this repetitive hedge should be replaced by specific risk statements tied to the model-update, decision-making, or uncertainty-quantification context, or removed.
  6. [§5.2.2] The framing examples in §5.2.2 come from heterogeneous domains (forestry [94], industrial robotics [102], wind turbine gearboxes [112], mobile CPS [43]) without a synthesis for advanced manufacturing; a comparison table or an explicit discussion of transferability to advanced manufacturing would strengthen the section.

Circularity Check

0 steps flagged · score 0.0 of 10

No circularity: survey claims are synthesized from external literature; self-citations are background references only.

full rationale

This paper is a citation-based survey, not a derivation. It contains no fitted parameters, no equations whose outputs equal their inputs by construction, and no predictions that reduce to fitted values. The central claim—that digital twins for advanced manufacturing face security and privacy vulnerabilities across data collection, data sharing, ML/DL, and system-level operations, with countermeasures that can build trust—is supported by citation to external literature throughout. The ML/DL threat taxonomy in Section 4 is explicitly described as 'inspired from the paper [103]' (an external survey by Liu et al.) and is introduced with the hedged phrase 'could be applied to the context of digital twins in advanced manufacturing,' which is weaker than the abstract's 'analyze' but is not circular. The self-citations in the paper ([77], [78], [178], [202]) are background references for digital twin definitions, ML-based uncertainty quantification, and federated learning in smart manufacturing; none of them is used to justify a unique theoretical claim, to forbid alternatives, or to serve as the load-bearing evidence for the security/privacy analysis. No uniqueness theorems from prior work by the authors are invoked, and no ansatz is smuggled in via self-citation. The concern that CV/NLP adversarial-ML threats may not transfer to manufacturing digital twins (Section 4.1-4.5, e.g., one-pixel attack [162], JPEG compression defenses [34, 184], image super-resolution defenses [122]) is a correctness/validity risk about the strength of the survey's synthesis, not a circularity. The paper is self-contained against external benchmarks in the sense that its claims are checkable against the cited literature. No circular step can be exhibited, so the score is 0.

Assumptions & free parameters 0 free parameters · 2 assumptions · 0 invented entities

No free parameters or invented entities exist in this survey. The main load-bearing assumptions are that generic ML/DL security taxonomies transfer to manufacturing digital twins, and that the convenience sample of cited references adequately represents the literature. The first is explicit but untested; the second is unavoidable for a survey.

assumptions (2)
  • domain assumption The ML/DL privacy and security threat taxonomy developed for computer vision and NLP applies to manufacturing digital twins without domain-specific adjustment.
    Section 4 asserts this contention and then imports attacks and defenses from the prior deep-learning survey without manufacturing-specific validation.
  • domain assumption The cited references are accurate and sufficiently representative of the security and privacy landscape for manufacturing digital twins.
    A survey's conclusions inherit the correctness of its sources; the paper provides no verification of the cited results or a systematic selection rationale.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Security and Privacy of Digital Twins for Advanced Manufacturing: A Survey." pith.science (2026). https://pith.science/paper/VMQAFPI7

@misc{pith2026241213939,
  author       = {Pith},
  title        = {Pith review of: Security and Privacy of Digital Twins for Advanced Manufacturing: A Survey},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/VMQAFPI7}},
  note         = {Machine review of arXiv:2412.13939}
}
read the original abstract

In Industry 4.0, the digital twin is one of the emerging technologies, offering simulation abilities to predict, refine, and interpret conditions and operations, where it is crucial to emphasize a heightened concentration on the associated security and privacy risks. To be more specific, the adoption of digital twins in the manufacturing industry relies on integrating technologies like cyber-physical systems, the Industrial Internet of Things, virtualization, and advanced manufacturing. The interactions of these technologies give rise to numerous security and privacy vulnerabilities that remain inadequately explored. Towards that end, this paper analyzes the cybersecurity threats of digital twins for advanced manufacturing in the context of data collection, data sharing, machine learning and deep learning, and system-level security and privacy. We also provide several solutions to the threats in those four categories that can help establish more trust in digital twins.

Figures

Figures reproduced from arXiv: 2412.13939 by the authors.

Figure 1
Figure 1. Key Components of Advanced Manufacturing [PITH_FULL_IMAGE:figures/full_fig_p002_1.png] view at source ↗
Figure 2
Figure 2. Digital Twin for Advanced Manufacturing twins are utilized for personalized medicine, the advancement of medical devices, and precision surgical planning. In the domain of smart cities, these digital counterparts contribute to the evolution of intelligent urban endeavors by crafting intricate models of urban infrastructure, transportation grids, and public services. The outcome is astute city planning and judicious … view at source ↗
Figure 3
Figure 3. Overview of Entities in Data Collection of cultivating trust, establishing traceability, upholding data integrity, implementing access control, employing encryption, and delving into the intricacies of centralized versus decentralized data sharing solutions. Section 4 discusses the potential cybersecurity threats when applying machine learning or deep learning techniques. Cybersecurity issues within model update, de… view at source ↗
Figures from the paper (3 more)
Figure 4
Figure 4. Figure 4: Data Sharing Challenges Areas: 1) Data Storage, 2) Data Access, 3) Data Provenance [PITH_FULL_IMAGE:figures/full_fig_p007_4.png]
Figure 5
Figure 5. Figure 5: The overview of attacks and defenses in ML or DL inspired from the paper [ [PITH_FULL_IMAGE:figures/full_fig_p011_5.png]
Figure 6
Figure 6. Figure 6: Digital Twin System Security in Advanced Manufacturing [PITH_FULL_IMAGE:figures/full_fig_p023_6.png]

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Uncertainty-Aware Digital Twins: Robust Model Predictive Control using Time-Series Deep Quantile Learning

    eess.SY 2025-01 conditional novelty 5.0 of 10

    A robust MPC framework that uses one-shot multi-step TiDE predictions and learned quantile bounds as safety tubes, demonstrated on a DED additive-manufacturing simulator.

Reference graph

Works this paper leans on

214 extracted references · 38 canonical work pages · cited by 1 Pith paper

  1. [48]

    Christian Gehrmann and Martin Gunnarsson. 2020. A Digital Twin Based Industrial Automation and Control System Security Architecture. IEEE Transactions on Industrial Informatics 16, 1 (2020), 669–680. https://doi.org/10.1109/TII. 2019.2938885

  2. [162]

    Jiawei Su, Danilo Vasconcellos Vargas, and Kouichi Sakurai. 2019. One pixel attack for fooling deep neural networks. IEEE Transactions on Evolutionary Computation 23, 5 (2019), 828–841

  3. [122]

    Aamir Mustafa, Salman H Khan, Munawar Hayat, Jianbing Shen, and Ling Shao. 2019. Image super-resolution as a defense against adversarial attacks. IEEE Transactions on Image Processing 29 (2019), 1711–1724

  4. [1]

    Martin Abadi, Andy Chu, Ian Goodfellow, H Brendan McMahan, Ilya Mironov, Kunal Talwar, and Li Zhang. 2016. Deep learning with differential privacy. In Proceedings of the 2016 ACM SIGSAC conference on computer and communications security. 308–318

  5. [2]

    Gergely Acs, Luca Melis, Claude Castelluccia, and Emiliano De Cristofaro. 2018. Differentially private mixture of generative neural networks. IEEE Transactions on Knowledge and Data Engineering 31, 6 (2018), 1109–1121

  6. [3]

    Toyosi Ademujimi and Vittaldas Prabhu. 2022. Digital twin for training bayesian networks for fault diagnostics of manufacturing systems. Sensors 22, 4 (2022), 1430

  7. [4]

    Marc Antonini, Michel Barlaud, Pierre Mathieu, and Ingrid Daubechies. 1992. Image coding using wavelet transform. IEEE Trans. Image Processing 1 (1992), 20–5

  8. [5]

    Yoshinori Aono, Takuya Hayashi, Lihua Wang, Shiho Moriai, et al . 2017. Privacy-preserving deep learning via additively homomorphic encryption. IEEE transactions on information forensics and security 13, 5 (2017), 1333–1345

Show all 214 references
  1. [6]

    Anish Athalye, Nicholas Carlini, and David Wagner. 2018. Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. In International conference on machine learning . PMLR, 274–283

  2. [7]

    Anish Athalye, Logan Engstrom, Andrew Ilyas, and Kevin Kwok. 2018. Synthesizing robust adversarial examples. In International conference on machine learning . PMLR, 284–293

  3. [8]

    Jinsong Bao, Dongsheng Guo, Jie Li, and Jie Zhang. 2019. The modelling and operations for the digital twin in the context of manufacturing. Enterprise Information Systems 13, 4 (2019), 534–556

  4. [9]

    Ruying Bao, Sihang Liang, and Qingcan Wang. 2018. Featurized bidirectional gan: Adversarial defense via adversarially learned semantic inference. arXiv preprint arXiv:1805.07862 (2018)

  5. [10]

    Wolfgang Birk, Roland Hostettler, Maryam Razi, Khalid Atta, and Rasmus Tammia. 2022. Automatic generation and updating of process industrial digital twins for estimation and control-A review. Frontiers in Control Engineering 3 (2022), 954858

  6. [11]

    Florian Bourse, Michele Minelli, Matthias Minihold, and Pascal Paillier. 2018. Fast homomorphic evaluation of deep discretized neural networks. In Advances in Cryptology–CRYPTO 2018: 38th Annual International Cryptology Conference, Santa Barbara, CA, USA, August 19–23, 2018, P...

  7. [12]

    Wieland Brendel, Jonas Rauber, and Matthias Bethge. 2017. Decision-based adversarial attacks: Reliable attacks against black-box machine learning models. arXiv preprint arXiv:1712.04248 (2017)

  8. [13]

    Bernhard Brenner, Edgar Weippl, and Andreas Ekelhart. 2019. A Versatile Security Layer for AutomationML. In 2019 IEEE 17th International Conference on Industrial Informatics (INDIN) , Vol. 1. 358–364. https://doi.org/10.1109/ INDIN41052.2019.8972288

  9. [14]

    Thomas Brunner, Frederik Diehl, Michael Truong Le, and Alois Knoll. 2019. Guessing smart: Biased sampling for efficient black-box adversarial attacks. In Proceedings of the IEEE/CVF International Conference on Computer Vision . 4958–4966

  10. [15]

    Antoni Buades, Bartomeu Coll, and J-M Morel. 2005. A non-local algorithm for image denoising. In2005 IEEE computer society conference on computer vision and pattern recognition (CVPR’05) , Vol. 2. Ieee, 60–65

  11. [16]

    Peter Buneman, Sanjeev Khanna, and Wang-Chiew Tan. 2000. Data Provenance: Some Basic Issues. In FST TCS 2000: Foundations of Software Technology and Theoretical Computer Science , Sanjiv Kapoor and Sanjiva Prasad (Eds.). Springer Berlin Heidelberg, Berlin, Heidelberg, 87–93

  12. [17]

    Yiyun Cao, Christine Currie, Bhakti Stephan Onggo, and Michael Higgins. 2021. Simulation optimization for a digital twin using a multi-fidelity framework. In 2021 Winter simulation conference (WSC) . IEEE, 1–12

  13. [18]

    Nicholas Carlini and David Wagner. 2017. Towards evaluating the robustness of neural networks. In 2017 ieee symposium on security and privacy (sp) . Ieee, 39–57

  14. [19]

    Glen Cathey, James Benson, Maanak Gupta, and Ravi Sandhu. 2021. Edge Centric Secure Data Sharing with Digital Twins in Smart Ecosystems. 70–79. https://doi.org/10.1109/TPSISA52974.2021.00008

  15. [20]

    Hervé Chabanne, Amaury De Wargny, Jonathan Milgram, Constance Morel, and Emmanuel Prouff. 2017. Privacy- preserving classification on deep neural network. Cryptology ePrint Archive (2017)

  16. [21]

    Ting-Jui Chang, Yukun He, and Peng Li. 2018. Efficient two-step adversarial defense for deep neural networks. arXiv preprint arXiv:1810.03739 (2018). , Vol. 1, No. 1, Article . Publication date: December 2024. 28 Zemskov et al

  17. [22]

    Bryant Chen, Wilka Carvalho, Nathalie Baracaldo, Heiko Ludwig, Benjamin Edwards, Taesung Lee, Ian Molloy, and Biplav Srivastava. 2018. Detecting backdoor attacks on deep neural networks by activation clustering. arXiv preprint arXiv:1811.03728 (2018)

  18. [23]

    Pin-Yu Chen, Huan Zhang, Yash Sharma, Jinfeng Yi, and Cho-Jui Hsieh. 2017. Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models. In Proceedings of the 10th ACM workshop on artificial intelligence and security . 15–26

  19. [24]

    Steven Chen, Nicholas Carlini, and David Wagner. 2020. Stateful detection of black-box adversarial attacks. In Proceedings of the 1st ACM Workshop on Security and Privacy on Artificial Intelligence . 30–39

  20. [25]

    2018.{TVM}: An automated{End-to-End} optimizing compiler for deep learning

    Tianqi Chen, Thierry Moreau, Ziheng Jiang, Lianmin Zheng, Eddie Yan, Haichen Shen, Meghan Cowan, Leyuan Wang, Yuwei Hu, Luis Ceze, et al. 2018.{TVM}: An automated{End-to-End} optimizing compiler for deep learning. In 13th USENIX Symposium on Operating Systems Design and Implem...

  21. [26]

    Xinyun Chen, Chang Liu, Bo Li, Kimberly Lu, and Dawn Song. 2017. Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526 (2017)

  22. [27]

    Ilaria Chillotti, Nicolas Gama, Mariya Georgieva, and Malika Izabachene. 2016. Faster fully homomorphic encryption: Bootstrapping in less than 0.1 seconds. In Advances in Cryptology–ASIACRYPT 2016: 22nd International Conference on the Theory and Application of Cryptology and I...

  23. [28]

    Biswarup Choudhury, Robin Swanson, Felix Heide, Gordon Wetzstein, and Wolfgang Heidrich. 2017. Consensus convolutional sparse coding. In Proceedings of the IEEE International Conference on Computer Vision . 4280–4288

  24. [29]

    R Dennis Cook and Sanford Weisberg. 1980. Characterizations of an empirical influence function for detecting influential cases in regression. Technometrics 22, 4 (1980), 495–508

  25. [30]

    Nilaksh Das, Madhuri Shanbhogue, Shang-Tse Chen, Fred Hohman, Li Chen, Michael E Kounavis, and Duen Horng Chau. 2017. Keeping the bad guys out: Protecting and vaccinating deep learning with jpeg compression. arXiv preprint arXiv:1705.02900 (2017)

  26. [31]

    Li Deng. 2012. The mnist database of handwritten digit images for machine learning research [best of the web]. IEEE signal processing magazine 29, 6 (2012), 141–142

  27. [32]

    Aarya Sheetal Desai, N Navaneeth, Sondipon Adhikari, and Souvik Chakraborty. 2023. Enhanced multi-fidelity modeling for digital twin and uncertainty quantification. Probabilistic Engineering Mechanics 74 (2023), 103525

  28. [33]

    Y. Du, Y. Huang, G. Wan, and P. He. 2023. Deep Learning-Based Cyber–Physical Feature Fusion for Anomaly Detection in Industrial Control Systems. IEEE Transactions on Industrial Informatics (2023)

  29. [34]

    Gintare Karolina Dziugaite, Zoubin Ghahramani, and Daniel M Roy. 2016. A study of the effect of jpg compression on adversarial images. arXiv preprint arXiv:1608.00853 (2016)

  30. [35]

    Matthias Eckhart and Andreas Ekelhart. 2018. A Specification-based State Replication Approach for Digital Twins. In Proceedings of the 2018 Workshop on Cyber-Physical Systems Security and PrivaCy (Toronto, Canada) (CPS-SPC ’18). Association for Computing Machinery, New York, N...

  31. [36]

    Alexei A Efros and William T Freeman. 2023. Image quilting for texture synthesis and transfer. In Seminal Graphics Papers: Pushing the Boundaries, Volume 2 . 571–576

  32. [37]

    Henrik Ejersbo, Kenneth Lausdahl, Mirgita Frasheri, and Lukas Esterle. 2023. Dynamic Runtime Integration of New Models in Digital Twins. In 2023 IEEE/ACM 18th Symposium on Software Engineering for Adaptive and Self-Managing Systems (SEAMS). IEEE, 44–55

  33. [38]

    Erba and N

    A. Erba and N. Tippenhauer. 2023. Assessing Model-free Anomaly Detection in Industrial Control Systems Against Generic Concealment Attacks. IEEE Transactions on Industrial Informatics (2023)

  34. [39]

    Andre Esteva, Katherine Chou, Serena Yeung, Nikhil Naik, Ali Madani, Ali Mottaghi, Yun Liu, Eric Topol, Jeff Dean, and Richard Socher. 2021. Deep learning-enabled medical computer vision. NPJ digital medicine 4, 1 (2021), 5

  35. [40]

    Marco Evangelos Biancolini and Ubaldo Cella. 2019. Radial basis functions update of digital models on actual manufactured shapes. Journal of Computational and Nonlinear Dynamics 14, 2 (2019), 021013

  36. [41]

    Sina Faezi, Sujit Rokka Chhetri, Arnav Vaibhav Malawade, John Charles Chaput, William Grover, Philip Brisk, and Mohammad Abdullah Al Faruque. 2019. Oligo-snoop: a non-invasive side channel attack against DNA synthesis machines. In Network and Distributed Systems Security (NDSS...

  37. [42]

    Alexander Fell, Hung Thinh Pham, and Siew-Kei Lam. 2019. TAD: time side-channel attack defense of obfuscated source code. In Proceedings of the 24th Asia and South Pacific Design Automation Conference . 58–63

  38. [43]

    Fend and D

    A. Fend and D. Bork. 2022. CPSAML: a language and code generation framework for digital twin based monitoring of mobile cyber-physical systems. In Proceedings of the ACM Conference on Computer and Communications Security

  39. [44]

    H. Feng, C. Gomes, and P. G. Larsen. 2023. Model-Based Monitoring and State Estimation for Digital Twins: The Kalman Filter. Applied Sciences 13, 2 (2023), 1021

  40. [45]

    Rusins Freivalds. 1977. Probabilistic Machines Can Use Less Running Time.. In IFIP congress, Vol. 839. 842. , Vol. 1, No. 1, Article . Publication date: December 2024. Security and Privacy of Digital Twins for Advanced Manufacturing: A Survey 29

  41. [46]

    Qian Ge, Yuval Yarom, David Cock, and Gernot Heiser. 2018. A survey of microarchitectural timing attacks and countermeasures on contemporary hardware. Journal of Cryptographic Engineering 8 (2018), 1–27

  42. [49]

    Ran Gilad-Bachrach, Nathan Dowlin, Kim Laine, Kristin Lauter, Michael Naehrig, and John Wernsing. 2016. Cryptonets: Applying neural networks to encrypted data with high throughput and accuracy. InInternational conference on machine learning. PMLR, 201–210

  43. [50]

    Ian Goodfellow, Jean Pouget-Abadie, Mehdi Mirza, Bing Xu, David Warde-Farley, Sherjil Ozair, Aaron Courville, and Yoshua Bengio. 2014. Generative adversarial nets. Advances in neural information processing systems 27 (2014)

  44. [51]

    Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)

  45. [52]

    Tianyu Gu, Brendan Dolan-Gavitt, and Siddharth Garg. 2017. Badnets: Identifying vulnerabilities in the machine learning model supply chain. arXiv preprint arXiv:1708.06733 (2017)

  46. [53]

    Zhongshu Gu, Heqing Huang, Jialong Zhang, Dong Su, Ankita Lamba, Dimitrios Pendarakis, and Ian Molloy

  47. [54]

    Chuan Guo, Mayank Rana, Moustapha Cisse, and Laurens Van Der Maaten. 2017. Countering adversarial images using input transformations. arXiv preprint arXiv:1711.00117 (2017)

  48. [55]

    Lucjan Hanzlik, Yang Zhang, Kathrin Grosse, Ahmed Salem, Maximilian Augustin, Michael Backes, and Mario Fritz

  49. [56]

    Hasan, Khaled Salah, Raja Jayaraman, Mohammed Omar, Ibrar Yaqoob, Saša Pesic, Todd Taylor, and Dragan Boscovic

    Haya R. Hasan, Khaled Salah, Raja Jayaraman, Mohammed Omar, Ibrar Yaqoob, Saša Pesic, Todd Taylor, and Dragan Boscovic. 2020. A Blockchain-Based Approach for the Creation of Digital Twins. IEEE Access 8 (2020), 34113–34126. https://doi.org/10.1109/ACCESS.2020.2974810

  50. [57]

    Jamie Hayes, Luca Melis, George Danezis, and Emiliano De Cristofaro. 2017. Logan: Membership inference attacks against generative models. arXiv preprint arXiv:1705.07663 (2017)

  51. [58]

    Chao He, Tom Hao Luan, Rongxing Lu, Zhou Su, and Mianxiong Dong. 2022. Security and Privacy in Vehicular Digital Twin Networks: Challenges and Solutions. IEEE Wireless Communications PP (01 2022), 1–8. https://doi.org/ 10.1109/MWC.002.2200015

  52. [59]

    Felix Heide, Wolfgang Heidrich, and Gordon Wetzstein. 2015. Fast and flexible convolutional sparse coding. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition . 5135–5143

  53. [60]

    Joanna Helman. 2022. Digital Twin-driven approach towards manufacturing processes support. In Journal of Physics: Conference Series, Vol. 2198. IOP Publishing, 012007

  54. [61]

    Ehsan Hesamifard, Hassan Takabi, and Mehdi Ghasemi. 2017. Cryptodl: Deep neural networks over encrypted data. arXiv preprint arXiv:1711.05189 (2017)

  55. [62]

    Briland Hitaj, Giuseppe Ateniese, and Fernando Perez-Cruz. 2017. Deep models under the GAN: information leakage from collaborative deep learning. In Proceedings of the 2017 ACM SIGSAC conference on computer and communications security. 603–618

  56. [63]

    Dorjan Hitaj and Luigi V Mancini. 2018. Have you stolen my model? evasion attacks against deep neural network watermarking techniques. arXiv preprint arXiv:1809.00615 (2018)

  57. [64]

    Hossein Hosseini, Yize Chen, Sreeram Kannan, Baosen Zhang, and Radha Poovendran. 2017. Blocking transferability of adversarial examples in black-box learning systems. arXiv preprint arXiv:1703.04318 (2017)

  58. [65]

    Ruitong Huang, Bing Xu, Dale Schuurmans, and Csaba Szepesvári. 2015. Learning with a strong adversary. arXiv preprint arXiv:1511.03034 (2015)

  59. [66]

    Sihan Huang, Guoxin Wang, Yan Yan, and Xiongbing Fang. 2020. Blockchain-based data management for digital twin of product. Journal of Manufacturing Systems 54 (2020), 361–371. https://doi.org/10.1016/j.jmsy.2020.01.009

  60. [67]

    Thomas Huang, GJTGY Yang, and Greory Tang. 1979. A fast two-dimensional median filtering algorithm. IEEE transactions on acoustics, speech, and signal processing 27, 1 (1979), 13–18

  61. [68]

    Tyler Hunt, Congzheng Song, Reza Shokri, Vitaly Shmatikov, and Emmett Witchel. 2018. Chiron: Privacy-preserving machine learning as a service. arXiv preprint arXiv:1803.05961 (2018)

  62. [69]

    Nick Hynes, Raymond Cheng, and Dawn Song. 2018. Efficient deep learning on multi-source private data. arXiv preprint arXiv:1807.06689 (2018). , Vol. 1, No. 1, Article . Publication date: December 2024. 30 Zemskov et al

  63. [70]

    Sergey Ioffe and Christian Szegedy. 2015. Batch normalization: Accelerating deep network training by reducing internal covariate shift. In International conference on machine learning . pmlr, 448–456

  64. [71]

    Yongkuk Jeong, Erik Flores-García, and Magnus Wiktorsson. 2020. A design of digital twins for supporting decision- making in production logistics. In 2020 Winter Simulation Conference (WSC) . IEEE, 2683–2694

  65. [72]

    Deepu Jha, Vispi Nevile Karkaria, PB Karandikar, and RS Desai. 2022. Statistical modeling of hybrid supercapacitor. Journal of Energy storage 46 (2022), 103869

  66. [73]

    2018.{GAZELLE}: A low latency framework for secure neural network inference

    Chiraag Juvekar, Vinod Vaikuntanathan, and Anantha Chandrakasan. 2018.{GAZELLE}: A low latency framework for secure neural network inference. In 27th USENIX Security Symposium (USENIX Security 18) . 1651–1669

  67. [74]

    Uday Kamath, John Liu, and James Whitaker. 2019. Deep learning for NLP and speech recognition . Vol. 84. Springer

  68. [75]

    Harini Kannan, Alexey Kurakin, and Ian Goodfellow. 2018. Adversarial logit pairing. arXiv preprint arXiv:1803.06373 (2018)

  69. [76]

    Michael G Kapteyn, David J Knezevic, and Karen Willcox. 2020. Toward predictive digital twins via component-based reduced-order models and interpretable machine learning. In AIAA scitech 2020 forum . 0418

  70. [77]

    Vispi Karkaria, Jie Chen, Chase Siuta, Damien Lim, Robert Radulescu, and Wei Chen. 2024. A Machine Learning–Based Tire Life Prediction Framework for Increasing Life of Commercial Vehicle Tires. Journal of Mechanical Design 146, 2 (2024)

  71. [78]

    Vispi Karkaria, Anthony Goeckner, Rujing Zha, Jie Chen, Jianjing Zhang, Qi Zhu, Jian Cao, Robert X Gao, and Wei Chen. 2024. Towards a digital twin framework in additive manufacturing: Machine learning and bayesian optimization for time series process optimization. Journal of M...

  72. [79]

    Hakan Kayan, Matthew Nunes, Omer Rana, Pete Burnap, and Charith Perera. 2022. Cybersecurity of industrial cyber-physical systems: a review. ACM Computing Surveys (CSUR) 54, 11s (2022), 1–35

  73. [80]

    Paul C Kocher. 1996. Timing attacks on implementations of Diffie-Hellman, RSA, DSS, and other systems. InAdvances in Cryptology—CRYPTO’96: 16th Annual International Cryptology Conference Santa Barbara, California, USA August 18–22, 1996 Proceedings 16 . Springer, 104–113

  74. [81]

    Pang Wei Koh and Percy Liang. 2017. Understanding black-box predictions via influence functions. In International conference on machine learning . PMLR, 1885–1894

  75. [82]

    Petteri Kokkonen, Björn Hemming, Eeva Mikkola, Linus Teir, Ville Lämsä, and Jukka Junttila. 2022. Robust lightweight design and digital twins considering manufacturing quality variation and sustainability requirements. Rakenteiden Mekaniikka 55, 3 (2022), 66–80

  76. [83]

    Alex Krizhevsky, Geoffrey Hinton, et al. 2009. Learning multiple layers of features from tiny images. (2009)

  77. [84]

    Alex Krizhevsky, Ilya Sutskever, and Geoffrey E Hinton. 2012. Imagenet classification with deep convolutional neural networks. Advances in neural information processing systems 25 (2012)

  78. [85]

    Wolfgang Kuehn. 2018. Digital twins for decision making in complex production and logistic enterprises.International Journal of Design & Nature and Ecodynamics 13, 3 (2018), 260–271

  79. [86]

    Martin Kunath and Herwig Winkler. 2018. Integrating the Digital Twin of the manufacturing system into a decision support system for improving the order management process. Procedia Cirp 72 (2018), 225–231

  80. [87]

    Alexey Kurakin, Ian Goodfellow, and Samy Bengio. 2016. Adversarial machine learning at scale. arXiv preprint arXiv:1611.01236 (2016)

  81. [88]

    Heikki Laaki, Yoan Miche, and Kari Tammi. 2019. Prototyping a digital twin for real time remote control over mobile networks: Application of remote surgery. Ieee Access 7 (2019), 20325–20336

  82. [89]

    Hasan Latif, Guodong Shao, and Binil Starly. 2020. A case study of digital twin for a manufacturing process involving human interactions. In 2020 Winter Simulation Conference (WSC) . IEEE, 2659–2670

  83. [90]

    Krishnan, and Victor C

    Dongmin Lee, Sang Hyun Lee, Neda Masoud, M.S. Krishnan, and Victor C. Li. 2021. Integrated digital twin and blockchain framework to support accountable information sharing in construction projects.Automation in Construction 127 (2021), 103688. https://doi.org/10.1016/j.autcon....

  84. [91]

    Chunquan Li, Yaqiong Chen, and Yuling Shang. 2022. A review of industrial big data for decision making in intelligent manufacturing. Engineering Science and Technology, an International Journal 29 (2022), 101021

  85. [92]

    Luan, Xinghao Li, Jinkai Zheng, Chengzhe Lai, Zhou Su, and Kuan Zhang

    Guanjie Li, Tom H. Luan, Xinghao Li, Jinkai Zheng, Chengzhe Lai, Zhou Su, and Kuan Zhang. 2023. Breaking Down Data Sharing Barrier of Smart City: A Digital Twin Approach. IEEE Network (2023), 1–9. https://doi.org/10.1109/ MNET.140.2200512

  86. [93]

    Shaofeng Li, Minhui Xue, Benjamin Zi Hao Zhao, Haojin Zhu, and Xinpeng Zhang. 2020. Invisible backdoor attacks on deep neural networks via steganography and regularization. IEEE Transactions on Dependable and Secure Computing 18, 5 (2020), 2088–2105

  87. [94]

    W. Li, M. Yang, B. Xi, and Q. Huang. 2023. Framework of Virtual Plantation Forest Modeling and Data Analysis for Digital Twin. Forests 14, 4 (2023), 683

  88. [95]

    Bin Liang, Hongcheng Li, Miaoqiang Su, Xirong Li, Wenchang Shi, and Xiaofeng Wang. 2018. Detecting adversarial image examples in deep neural networks with adaptive noise reduction. IEEE Transactions on Dependable and Secure , Vol. 1, No. 1, Article . Publication date: December...

  89. [96]

    Fangzhou Liao, Ming Liang, Yinpeng Dong, Tianyu Pang, Xiaolin Hu, and Jun Zhu. 2018. Defense against adversarial attacks using high-level representation guided denoiser. In Proceedings of the IEEE conference on computer vision and pattern recognition. 1778–1787

  90. [97]

    Chihuang Liu and Joseph JaJa. 2018. Feature prioritization and regularization improve standard accuracy and adversarial robustness. arXiv preprint arXiv:1810.02424 (2018)

  91. [98]

    Jian Liu, Mika Juuti, Yao Lu, and Nadarajah Asokan. 2017. Oblivious neural network predictions via minionn transformations. In Proceedings of the 2017 ACM SIGSAC conference on computer and communications security . 619– 631

  92. [99]

    Kang Liu, Brendan Dolan-Gavitt, and Siddharth Garg. 2018. Fine-pruning: Defending against backdooring attacks on deep neural networks. In International symposium on research in attacks, intrusions, and defenses . Springer, 273–294

  93. [100]

    Weibo Liu, Zidong Wang, Xiaohui Liu, Nianyin Zeng, Yurong Liu, and Fuad E Alsaadi. 2017. A survey of deep neural network architectures and their applications. Neurocomputing 234 (2017), 11–26

  94. [101]

    Ximeng Liu, Robert H Deng, Pengfei Wu, and Yang Yang. 2020. Lightning-fast and privacy-preserving outsourced computation in the cloud. Cybersecurity 3 (2020), 1–21

  95. [102]

    X. Liu, H. Gan, Y. Luo, Y. Chen, and L. Gao. 2023. Digital-Twin-Based Real-Time Optimization for A Fractional Order Controller for Industrial Robots. Fractal and Fractional 7, 2 (2023), 167

  96. [103]

    Vasilakos

    Ximeng Liu, Lehui Xie, Yaopeng Wang, Jian Zou, Jinbo Xiong, Zuobin Ying, and Athanasios V. Vasilakos. 2021. Privacy and Security Issues in Deep Learning: A Survey. IEEE Access 9 (2021), 4566–4593. https://doi.org/10.1109/ACCESS. 2020.3045078

  97. [104]

    Yingqi Liu, Shiqing Ma, Yousra Aafer, Wen-Chuan Lee, Juan Zhai, Weihang Wang, and Xiangyu Zhang. 2018. Trojaning attack on neural networks. In 25th Annual Network And Distributed System Security Symposium (NDSS 2018) . Internet Soc

  98. [105]

    Yunhui Long, Vincent Bindschaedler, Lei Wang, Diyue Bu, Xiaofeng Wang, Haixu Tang, Carl A Gunter, and Kai Chen

  99. [106]

    Jiajun Lu, Hussein Sibai, Evan Fabry, and David Forsyth. 2017. No need to worry about adversarial examples in object detection in autonomous vehicles. arXiv preprint arXiv:1707.03501 (2017)

  100. [107]

    Giovanni Lugaresi and Andrea Matta. 2021. Automated manufacturing system discovery and digital twin generation. Journal of Manufacturing Systems 59 (2021), 51–66

  101. [108]

    arXiv preprint arXiv:1802.04889 (2018)

    Understanding membership inferences on well-generalized learning models. arXiv preprint arXiv:1802.04889 (2018)

  102. [109]

    Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2017. Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083 (2017)

  103. [110]

    Makansi and K

    F. Makansi and K. Schmitz. 2022. Data-Driven Condition Monitoring of a Hydraulic Press Using Supervised Learning and Neural Networks. Energies 15, 17 (2022), 6217

  104. [111]

    Yan Luo, Xavier Boix, Gemma Roig, Tomaso Poggio, and Qi Zhao. 2015. Foveation-based mechanisms alleviate adversarial examples. arXiv preprint arXiv:1511.06292 (2015)

  105. [112]

    F. C. Mehlan, A. Nejad, and Z. Gao. 2022. Digital twin based virtual sensor for online fatigue damage monitoring in offshore wind turbine drivetrains. Journal of Offshore Mechanics and Arctic Engineering 144, 6 (2022)

  106. [113]

    Luca Melis, Congzheng Song, Emiliano De Cristofaro, and Vitaly Shmatikov. 2019. Exploiting unintended feature leakage in collaborative learning. In 2019 IEEE symposium on security and privacy (SP) . IEEE, 691–706

  107. [114]

    Frank McKeen, Ilya Alexandrovich, Alex Berenzon, Carlos V Rozas, Hisham Shafi, Vedvyas Shanbhogue, and Uday R Savagaonkar. 2013. Innovative instructions and software model for isolated execution. Hasp@ isca 10, 1 (2013)

  108. [115]

    Payman Mohassel and Yupeng Zhang. 2017. Secureml: A system for scalable privacy-preserving machine learning. In 2017 IEEE symposium on security and privacy (SP) . IEEE, 19–38

  109. [116]

    Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, Omar Fawzi, and Pascal Frossard. 2017. Universal adversarial perturbations. In Proceedings of the IEEE conference on computer vision and pattern recognition . 1765–1773

  110. [117]

    Qingfei Min, Yangguang Lu, Zhiyong Liu, Chao Su, and Bo Wang. 2019. Machine learning based digital twin framework for production optimization in petrochemical industry. International Journal of Information Management 49 (2019), 502–519

  111. [118]

    Luis Muñoz-González, Battista Biggio, Ambra Demontis, Andrea Paudice, Vasin Wongrassamee, Emil C Lupu, and Fabio Roli. 2017. Towards poisoning of deep learning algorithms with back-gradient optimization. In Proceedings of the 10th ACM workshop on artificial intelligence and se...

  112. [119]

    Luis Muñoz-González, Bjarne Pfitzner, Matteo Russo, Javier Carnerero-Cano, and Emil C Lupu. 2019. Poisoning attacks with generative adversarial nets. arXiv preprint arXiv:1906.07773 (2019). , Vol. 1, No. 1, Article . Publication date: December 2024. 32 Zemskov et al

  113. [120]

    Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, and Pascal Frossard. 2016. Deepfool: a simple and accurate method to fool deep neural networks. In Proceedings of the IEEE conference on computer vision and pattern recognition . 2574–2582

  114. [121]

    Jack Murray, Brandon Chamberlain, Nicholas Hemleben, Daniel Ospina-Acero, Indranil Nayak, Andrew VanFossen, Frank Zahiri, and Mrinal Kumar. 2023. Reconceptualizing the Prognostics Digital Twin for Smart Manufacturing with Data-Driven Evolutionary Models and Adaptive Uncertaint...

  115. [123]

    Andres Murillo, Riccardo Taormina, Nils Tippenhauer, and Stefano Galelli. 2021. Co-Simulating Physical Processes and Network Data for High-Fidelity Cyber-Security Experiments. In Sixth Annual Industrial Control System Security (ICSS) Workshop (Austin, TX, USA) (ICSS 2020). Ass...

  116. [124]

    Paromita Nath and Sankaran Mahadevan. 2022. Probabilistic digital twin for additive manufacturing process design and control. Journal of Mechanical Design 144, 9 (2022), 091704

  117. [125]

    Engineering National Academies of Sciences, Medicine, et al. 2023. Foundational research gaps and future directions for digital twins

  118. [126]

    Milad Nasr, Reza Shokri, and Amir Houmansadr. 2019. Comprehensive privacy analysis of deep learning: Passive and active white-box inference attacks against centralized and federated learning. In 2019 IEEE symposium on security and privacy (SP). IEEE, 739–753

  119. [127]

    Olga Ohrimenko, Felix Schuster, Cédric Fournet, Aastha Mehta, Sebastian Nowozin, Kapil Vaswani, and Manuel Costa. 2016. Oblivious{Multi-Party} machine learning on trusted processors. In 25th USENIX Security Symposium (USENIX Security 16). 619–636

  120. [128]

    Nicolas Papernot, Martín Abadi, Ulfar Erlingsson, Ian Goodfellow, and Kunal Talwar. 2016. Semi-supervised knowledge transfer for deep learning from private training data. arXiv preprint arXiv:1610.05755 (2016)

  121. [129]

    Robert Norvill, Cyril Cassanges, Wazen Shbair, Jean Hilger, Andrea Cullen, and Radu State. 2020. A Security and Privacy Focused KYC Data Sharing Platform. In Proceedings of the 2nd ACM International Symposium on Blockchain and Secure Critical Infrastructure (Taipei, Taiwan) (B...

  122. [130]

    Nicolas Papernot, Shuang Song, Ilya Mironov, Ananth Raghunathan, Kunal Talwar, and Úlfar Erlingsson. 2018. Scalable private learning with pate. arXiv preprint arXiv:1802.08908 (2018)

  123. [131]

    Andrea Paudice, Luis Muñoz-González, Andras Gyorgy, and Emil C Lupu. 2018. Detection of adversarial training examples in poisoning attacks through anomaly detection. arXiv preprint arXiv:1802.03041 (2018)

  124. [132]

    Nicolas Papernot, Patrick McDaniel, Somesh Jha, Matt Fredrikson, Z Berkay Celik, and Ananthram Swami. 2016. The limitations of deep learning in adversarial settings. In 2016 IEEE European symposium on security and privacy (EuroS&P). IEEE, 372–387

  125. [133]

    NhatHai Phan, Yue Wang, Xintao Wu, and Dejing Dou. 2016. Differential privacy preservation for deep auto-encoders: an application of human behavior prediction. In Proceedings of the AAAI Conference on Artificial Intelligence , Vol. 30

  126. [134]

    NhatHai Phan, Xintao Wu, and Dejing Dou. 2017. Preserving differential privacy in convolutional deep belief networks. Machine learning 106, 9-10 (2017), 1681–1704

  127. [135]

    2016.{DRAMA}: Exploiting {DRAM} Addressing for{Cross-CPU} Attacks

    Peter Pessl, Daniel Gruss, Clémentine Maurice, Michael Schwarz, and Stefan Mangard. 2016.{DRAMA}: Exploiting {DRAM} Addressing for{Cross-CPU} Attacks. In 25th USENIX security symposium (USENIX security 16) . 565–581

  128. [136]

    Kanthakumar Pongaliur, Zubin Abraham, Alex X Liu, Li Xiao, and Leo Kempel. 2008. Securing sensor nodes against side channel attacks. In 2008 11th IEEE High Assurance Systems Engineering Symposium . IEEE, 353–361

  129. [137]

    Aaditya Prakash, Nick Moran, Solomon Garber, Antonella DiLillo, and James Storer. 2018. Deflecting adversarial attacks with pixel deflection. In Proceedings of the IEEE conference on computer vision and pattern recognition . 8571– 8580

  130. [138]

    NhatHai Phan, Xintao Wu, Han Hu, and Dejing Dou. 2017. Adaptive laplace mechanism: Differential privacy preservation in deep learning. In 2017 IEEE international conference on data mining (ICDM) . IEEE, 385–394

  131. [139]

    Balta, Bin-Chou Kao, Sibin Mohan, James Moyne, Dawn Tilbury, and Kira Barton

    Yassine Qamsane, Chien-Ying Chen, Efe C. Balta, Bin-Chou Kao, Sibin Mohan, James Moyne, Dawn Tilbury, and Kira Barton. 2019. A Unified Digital Twin Framework for Real-time Monitoring and Evaluation of Smart Manufacturing Systems. In 2019 IEEE 15th International Conference on A...

  132. [140]

    Edward Raff, Jared Sylvester, Steven Forsyth, and Mark McLean. 2019. Barrage of random transforms for adversarially robust defense. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition . 6528–6537

  133. [141]

    Benedikt Putz, Marietheres Dietz, Philip Empl, and Günther Pernul. 2021. EtherTwin: Blockchain-based Secure Digital Twin Information Management. Information Processing & Management 58, 1 (2021), 102425. https://doi.org/10.1016/j. ipm.2020.102425

  134. [142]

    M Mazhar Rathore, Syed Attique Shah, Dhirendra Shukla, Elmahdi Bentafat, and Spiridon Bakiras. 2021. The role of ai, machine learning, and big data in digital twinning: A systematic literature review, challenges, and opportunities. IEEE Access 9 (2021), 32030–32052

  135. [143]

    Olaf Ronneberger, Philipp Fischer, and Thomas Brox. 2015. U-net: Convolutional networks for biomedical image segmentation. In Medical Image Computing and Computer-Assisted Intervention–MICCAI 2015: 18th International Conference, Munich, Germany, October 5-9, 2015, Proceedings,...

  136. [144]

    M Rahman, Abid Khan, Sayeed Anowar, Md Al-Imran, Richa Verma, Dinesh Kumar, Kazuma Kobayashi, and Syed Alam. 2022. Leveraging Industry 4.0: Deep Learning, Surrogate Model, and Transfer Learning with Uncertainty , Vol. 1, No. 1, Article . Publication date: December 2024. Securi...

  137. [145]

    Jože M Rožanec, Jinzhi Lu, Jan Rupnik, Maja Škrjanc, Dunja Mladenić, Blaž Fortuna, Xiaochen Zheng, and Dimitris Kiritsis. 2022. Actionable cognitive twins for decision making in manufacturing. International Journal of Production Research 60, 2 (2022), 452–478

  138. [146]

    Juan Enrique Rubio, Cristina Alcaraz, Rodrigo Roman, and Javier Lopez. 2019. Current cyber-defense trends in industrial control systems. Computers & Security 87 (2019), 101561. https://doi.org/10.1016/j.cose.2019.06.015

  139. [147]

    Bita Darvish Rouhani, M Sadegh Riazi, and Farinaz Koushanfar. 2018. Deepsecure: Scalable provably-secure deep learning. In Proceedings of the 55th annual design automation conference . 1–6

  140. [148]

    Pouya Samangouei, Maya Kabkab, and Rama Chellappa. 2018. Defense-gan: Protecting classifiers against adversarial attacks using generative models. arXiv preprint arXiv:1805.06605 (2018)

  141. [149]

    Amartya Sanyal, Matt Kusner, Adria Gascon, and Varun Kanade. 2018. TAPAS: Tricks to accelerate (encrypted) prediction as a service. In International conference on machine learning . PMLR, 4490–4499

  142. [150]

    Leonid I Rudin, Stanley Osher, and Emad Fatemi. 1992. Nonlinear total variation based noise removal algorithms. Physica D: nonlinear phenomena 60, 1-4 (1992), 259–268

  143. [151]

    Oscar Serrano, Luc Dandurand, and Sarah Brown. 2014. On the Design of a Cyber Security Data Sharing System. In Proceedings of the 2014 ACM Workshop on Information Sharing & Collaborative Security (Scottsdale, Arizona, USA) (WISCS ’14). Association for Computing Machinery, New ...

  144. [152]

    Ali Shafahi, W Ronny Huang, Mahyar Najibi, Octavian Suciu, Christoph Studer, Tudor Dumitras, and Tom Goldstein

  145. [153]

    R. K. Sen. 2023. Detailed Process for Developing an Efficient Anomaly Detection Algorithm for Real-Time Streaming Data in Large-Scale Industrial Systems. Processes 11, 1 (2023), 101

  146. [154]

    Weidong Shen, Tianliang Hu, Chengrui Zhang, and Songhua Ma. 2021. Secure sharing of big digital twin data for smart manufacturing based on blockchain. Journal of Manufacturing Systems 61 (2021), 338–350. https://doi.org/10. 1016/j.jmsy.2021.09.014

  147. [155]

    Sharmin Sultana Sheuly, Mobyen Uddin Ahmed, and Shahina Begum. 2022. Machine-learning-based digital twin in manufacturing: a bibliometric analysis and evolutionary overview. Applied Sciences 12, 13 (2022), 6512

  148. [156]

    Advances in neural information processing systems 31 (2018)

    Poison frogs! targeted clean-label poisoning attacks on neural networks. Advances in neural information processing systems 31 (2018)

  149. [157]

    Uri Shaham, Yutaro Yamada, and Sahand Negahban. 2018. Understanding adversarial training: Increasing local stability of supervised models through robust optimization. Neurocomputing 307 (2018), 195–204

  150. [158]

    Reza Shokri, Marco Stronati, Congzheng Song, and Vitaly Shmatikov. 2017. Membership inference attacks against machine learning models. In 2017 IEEE symposium on security and privacy (SP) . IEEE, 3–18

  151. [159]

    Seunghwan Son, Deokkyu Kwon, Joonyoung Lee, Sungjin Yu, Nam-Su Jho, and Youngho Park. 2022. On the Design of a Privacy-Preserving Communication Scheme for Cloud-Based Digital Twin Environments Using Blockchain. IEEE Access 10 (2022), 75365–75375. https://doi.org/10.1109/ACCESS...

  152. [160]

    Lei Shi, Xiao Chen, Sheng Wen, and Yang Xiang. 2019. Main Enabling Technologies in Industry 4.0 and Cybersecurity Threats. In Cyberspace Safety and Security , Jaideep Vaidya, Xiao Zhang, and Jin Li (Eds.). Springer International Publishing, Cham, 588–597

  153. [161]

    Reza Shokri and Vitaly Shmatikov. 2015. Privacy-preserving deep learning. In Proceedings of the 22nd ACM SIGSAC conference on computer and communications security . 1310–1321

  154. [163]

    Bo Sun, Nian-hsuan Tsai, Fangchen Liu, Ronald Yu, and Hao Su. 2019. Adversarial defense by stratified convolutional sparse coding. In Proceedings of the IEEE/CVF conference on computer vision and pattern recognition . 11447–11456. , Vol. 1, No. 1, Article . Publication date: D...

  155. [164]

    Wei-ning Song, Tan Li, Jun-hua Zhou, and Lin Xu. 2021. A Real-Time Digital Twin Model Dynamically Modifying Method Based on Consistency Measurement Model. In2021 IEEE 4th International Conference on Electronics Technology (ICET). IEEE, 406–410

  156. [165]

    Jacob Steinhardt, Pang Wei W Koh, and Percy S Liang. 2017. Certified defenses for data poisoning attacks. Advances in neural information processing systems 30 (2017)

  157. [166]

    Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus

  158. [167]

    Taibi, Y

    I. Taibi, Y. H. Aoul, and C. Barakat. 2022. Leveraging Web browsing performance data for network monitoring: a data-driven approach. In Proceedings of the IEEE Global Communications Conference (GLOBECOM)

  159. [168]

    W. Sun, Z. Zhou, F. Ma, J. Wang, and C. Ji. 2023. Industrial Application of Data-Driven Process Monitoring with an Automatic Selection Strategy for Modeling Data. Processes 11, 2 (2023), 402

  160. [169]

    Christian Szegedy, Vincent Vanhoucke, Sergey Ioffe, Jon Shlens, and Zbigniew Wojna. 2016. Rethinking the inception architecture for computer vision. In Proceedings of the IEEE conference on computer vision and pattern recognition . 2818–2826

  161. [170]

    Amirsina Torfi, Rouzbeh A Shirvani, Yaser Keneshloo, Nader Tavaf, and Edward A Fox. 2020. Natural language processing advancements by deep learning: A survey. arXiv preprint arXiv:2003.01200 (2020)

  162. [171]

    Florian Tramer and Dan Boneh. 2018. Slalom: Fast, verifiable and private execution of neural networks in trusted hardware. arXiv preprint arXiv:1806.03287 (2018)

  163. [172]

    Florian Tramèr, Alexey Kurakin, Nicolas Papernot, Ian Goodfellow, Dan Boneh, and Patrick McDaniel. 2017. Ensemble adversarial training: Attacks and defenses. arXiv preprint arXiv:1705.07204 (2017)

  164. [173]

    Adam Thelen, Xiaoge Zhang, Olga Fink, Yan Lu, Sayan Ghosh, Byeng D Youn, Michael D Todd, Sankaran Mahadevan, Chao Hu, and Zhen Hu. 2023. A comprehensive review of digital twin—part 2: roles of uncertainty quantification and optimization, a battery digital twin, and perspective...

  165. [174]

    Shixin Tian, Guolei Yang, and Ying Cai. 2018. Detecting adversarial examples through image transformation. In Proceedings of the AAAI Conference on Artificial Intelligence , Vol. 32

  166. [175]

    Tapas Tripura, Aarya Sheetal Desai, Sondipon Adhikari, and Souvik Chakraborty. 2023. Probabilistic machine learning based predictive and interpretable digital twin for dynamical systems. Computers & Structures 281 (2023), 107008

  167. [176]

    Chun-Chen Tu, Paishun Ting, Pin-Yu Chen, Sijia Liu, Huan Zhang, Jinfeng Yi, Cho-Jui Hsieh, and Shin-Ming Cheng

  168. [177]

    Yusuke Uchida, Yuki Nagai, Shigeyuki Sakazawa, and Shin’ichi Satoh. 2017. Embedding watermarks into deep neural networks. In Proceedings of the 2017 ACM on international conference on multimedia retrieval . 269–277

  169. [178]

    Florian Tramèr, Fan Zhang, Ari Juels, Michael K Reiter, and Thomas Ristenpart. 2016. Stealing machine learning models via prediction{APIs}. In 25th USENIX security symposium (USENIX Security 16) . 601–618

  170. [179]

    Aleksei Triastcyn and Boi Faltings. 2018. Generating differentially private datasets using gans. (2018)

  171. [180]

    Pascal Vincent, Hugo Larochelle, Yoshua Bengio, and Pierre-Antoine Manzagol. 2008. Extracting and composing robust features with denoising autoencoders. In Proceedings of the 25th international conference on Machine learning . 1096–1103

  172. [181]

    Athanasios Voulodimos, Nikolaos Doulamis, Anastasios Doulamis, Eftychios Protopapadakis, et al . 2018. Deep learning for computer vision: A brief review. Computational intelligence and neuroscience 2018 (2018)

  173. [182]

    Sameer Wagh, Divya Gupta, and Nishanth Chandran. 2018. Securenn: Efficient and private neural network training. Cryptology ePrint Archive (2018)

  174. [183]

    Binghui Wang and Neil Zhenqiang Gong. 2018. Stealing hyperparameters in machine learning. In2018 IEEE symposium on security and privacy (SP) . IEEE, 36–52

  175. [184]

    Anton van Beek, Vispi Nevile Karkaria, and Wei Chen. 2023. Digital twins for the designs of systems: a perspective. Structural and Multidisciplinary Optimization 66, 3 (2023), 49

  176. [185]

    Alberto Villalonga, Elisa Negri, Giacomo Biscardo, Fernando Castano, Rodolfo E Haber, Luca Fumagalli, and Marco Macchi. 2021. A decision-making framework for dynamic scheduling of cyber-physical production systems based on digital twins. Annual Reviews in Control 51 (2021), 357–373

  177. [186]

    Wilfling, B

    S. Wilfling, B. Falay, Q. Alfalouji, and G. Schweiger. 2022. A Dymola-Python framework for data-driven model creation and Co-simulation. In Proceedings of the 13th International Modelica Conference

  178. [187]

    Jim Woodcock, Cláudio Gomes, Hugo Daniel Macedo, and Peter Gorm Larsen. 2021. Uncertainty quantification and runtime monitoring using environment-aware digital twins. In Leveraging Applications of Formal Methods, Verification and Validation: Tools and Trends: 9th International...

  179. [188]

    Christos Xenofontos, Ioannis Zografopoulos, Charalambos Konstantinou, Alireza Jolfaei, Muhammad Khurram Khan, and Kim-Kwang Raymond Choo. 2021. Consumer, commercial, and industrial iot (in) security: Attack taxonomy and , Vol. 1, No. 1, Article . Publication date: December 202...

  180. [189]

    Kaishu Xia, Christopher Sacco, Max Kirkpatrick, Clint Saidy, Lam Nguyen, Anil Kircaliali, and Ramy Harik. 2021. A digital twin to train deep reinforcement learning agent for smart manufacturing plants: Environment, interfaces and intelligence. Journal of Manufacturing Systems ...

  181. [190]

    Qinglong Wang, Wenbo Guo, Kaixuan Zhang, Alexander G Ororbia, Xinyu Xing, Xue Liu, and C Lee Giles. 2017. Adversary resistant deep neural networks with an application to malware detection. In Proceedings of the 23rd ACM sigkdd international conference on knowledge discovery an...

  182. [191]

    Tianhao Wang and Florian Kerschbaum. 2019. Attacks on digital watermarks for deep neural networks. In ICASSP 2019-2019 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP) . IEEE, 2622–2626

  183. [192]

    Pengtao Xie, Misha Bilenko, Tom Finley, Ran Gilad-Bachrach, Kristin Lauter, and Michael Naehrig. 2014. Crypto-nets: Neural networks over encrypted data. arXiv preprint arXiv:1412.6181 (2014)

  184. [193]

    Qinghua Xu, Shaukat Ali, and Tao Yue. 2021. Digital twin-based anomaly detection in cyber-physical systems. In 2021 14th IEEE Conference on Software Testing, Verification and Validation (ICST) . IEEE, 205–216

  185. [194]

    Qinghua Xu, Shaukat Ali, Tao Yue, and Maite Arratibel. 2022. Uncertainty-aware transfer learning to evolve digital twins for industrial elevators. In Proceedings of the 30th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Enginee...

  186. [195]

    Weilin Xu, David Evans, and Yanjun Qi. 2017. Feature squeezing mitigates and detects carlini/wagner adversarial examples. arXiv preprint arXiv:1705.10686 (2017)

  187. [196]

    Cihang Xie, Yuxin Wu, Laurens van der Maaten, Alan L Yuille, and Kaiming He. 2019. Feature denoising for improving adversarial robustness. In Proceedings of the IEEE/CVF conference on computer vision and pattern recognition . 501–509

  188. [197]

    Liyang Xie, Kaixiang Lin, Shu Wang, Fei Wang, and Jiayu Zhou. 2018. Differentially private generative adversarial network. arXiv preprint arXiv:1802.06739 (2018)

  189. [198]

    Matthew D Zeiler and Rob Fergus. 2014. Visualizing and understanding convolutional networks. In Computer Vision–ECCV 2014: 13th European Conference, Zurich, Switzerland, September 6-12, 2014, Proceedings, Part I 13 . Springer, 818–833

  190. [199]

    Chao Zhang, Guanghui Zhou, Junsheng Hu, and Jing Li. 2020. Deep learning-enabled intelligent process planning for digital twin manufacturing cell. Knowledge-Based Systems 191 (2020), 105247

  191. [200]

    Ding Zhang, Qiang Liu, Hong Yan, and Min Xie. 2021. A matrix analytic approach for Bayesian network modeling and inference of a manufacturing system. Journal of Manufacturing Systems 60 (2021), 202–213

  192. [201]

    Jiale Zhang, Bing Chen, Yanchao Zhao, Xiang Cheng, and Feng Hu. 2018. Data Security and Privacy-Preserving in Edge Computing Paradigm: Survey and Open Issues. IEEE Access 6 (2018), 18209–18237. https://doi.org/10.1109/ ACCESS.2018.2820162

  193. [202]

    Chaofei Yang, Qing Wu, Hai Li, and Yiran Chen. 2017. Generative poisoning attack method against neural networks. arXiv preprint arXiv:1703.01340 (2017)

  194. [203]

    Fan Yang, Tao Feng, Fangmin Xu, Huiwen Jiang, and Chenglin Zhao. 2022. Collaborative clustering parallel reinforce- ment learning for edge-cloud digital twins manufacturing system. China Communications 19, 8 (2022), 138–148

  195. [204]

    Yu Zhang, Lili Yang, Wenxi Long, and Jun Han. 2022. Research on Data Sharing Model Based on Multi-Party Secure Computing. In Proceedings of the 6th International Conference on Big Data Research (Harbin, China) (ICBDR ’22). Association for Computing Machinery, New York, NY, USA...

  196. [205]

    Zhao and O

    M. Zhao and O. Fink. 2023. Dynamic Graph Attention for Anomaly Detection in Heterogeneous Sensor Networks. Sensors 23, 1 (2023), 231

  197. [206]

    X. Zhao, L. Zhang, Y. Cao, K. Jin, and Y. Hou. 2023. Anomaly Detection Approach in Industrial Control Systems Based on Measurement Data. IEEE Transactions on Industrial Informatics (2023)

  198. [207]

    Guanghui Zhou, Chao Zhang, Zhi Li, Kai Ding, and Chuang Wang. 2020. Knowledge-driven digital twin manufacturing cell towards intelligent manufacturing. International Journal of Production Research 58, 4 (2020), 1034–1051

  199. [208]

    Jianjing Zhang, Clayton Cooper, and Robert X. Gao. 2023. Federated Learning for Privacy-Preserving Collaboration in Smart Manufacturing. In Proceedings of the GCSM 2022 . Springer, Case Western Reserve University, Cleveland, OH 44106, USA, 845–853. https://doi.org/10.1007/978-...

  200. [209]

    Shunliang Zhang, Yongming Wang, and Weihua Zhou. 2019. Towards secure 5G networks: A Survey. Computer Networks 162 (2019), 106871. https://doi.org/10.1016/j.comnet.2019.106871

  201. [214]

    Chen Zhu, W Ronny Huang, Hengduo Li, Gavin Taylor, Christoph Studer, and Tom Goldstein. 2019. Transferable clean-label poisoning attacks on deep neural nets. InInternational Conference on Machine Learning. PMLR, 7614–7623

  202. [215]

    Xiaoyang Zhu and Yangjian Ji. 2023. A digital twin-based multi-objective optimization method for technical schemes in process industry. International Journal of Computer Integrated Manufacturing 36, 3 (2023), 443–468. , Vol. 1, No. 1, Article . Publication date: December 2024

  203. [2013]

    arXiv preprint arXiv:1312.6199 (2013)

    Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199 (2013)

  204. [2018]

    arXiv preprint arXiv:1807.00969 (2018), 1–14

    Securing input data of deep learning inference systems via partitioned enclave execution. arXiv preprint arXiv:1807.00969 (2018), 1–14

  205. [2019]

    In Proceedings of the AAAI Conference on Artificial Intelligence , Vol

    Autozoom: Autoencoder-based zeroth order optimization method for attacking black-box neural networks. In Proceedings of the AAAI Conference on Artificial Intelligence , Vol. 33. 742–749

  206. [2021]

    In Proceedings of the IEEE/CVF conference on computer vision and pattern recognition

    Mlcapsule: Guarded offline deployment of machine learning as a service. In Proceedings of the IEEE/CVF conference on computer vision and pattern recognition . 3300–3309

Pith tools

Reviewed August 11, 2026 · model on record in the stance chip above.