Pith. sign in

REVIEW 1 major objections 6 minor 203 references

Adaptive Anomaly Detection for Identifying Attacks in Cyber-Physical Systems: A Systematic Literature Review

T0 review · 1 major / 6 minor · reviewed 2026-08-12 · deepseek-v4-flash

Pith's one-line read This systematic review claims to be the first to map adaptive anomaly detection in cyber-physical systems, and finds that most methods adapt either data processing or the detection model, but rarely both.

desk verdict A useful but flawed SLR: the taxonomy and per-paper tables are valuable, but the headline 'rarely both' finding is not supported by the stated methodology and the reported statistics are internally inconsistent. read the letter →

arxiv 2411.14278 v2 pith:IH4LESPX submitted 2024-11-21 cs.CR cs.LG

classification cs.CRcs.LG
keywords adaptiveanomalydetectioncyber-physicalsystemssystematicliteraturereviewconceptdriftonlinelearningintrusiontaxonomystreamingdata
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper is a systematic literature review of adaptive anomaly detection (AAD) for cyber-physical systems (CPS), and its central claim is that it is the first such review. The authors gathered 397 candidate papers, narrowed them to 65 (47 research and 18 survey papers) from 2013 to 2023, and classified them with a new taxonomy built on attack types, CPS application, learning paradigm, data management, and algorithms. Their headline finding is that most reviewed methods handle only one side of adaptation—either fast data processing or model updating—and that combining both in a single system is rare. If the finding holds, it gives the field a map and identifies a concrete gap: few existing detectors can update themselves online while still making low-latency decisions.

What carries the argument

The review's load-bearing object is its taxonomy, which splits AAD into near real-time data processing versus model adaptation and then cross-classifies each reviewed paper by CPS application, learning paradigm (supervised, unsupervised, reinforcement), data management (offline vs online), and algorithm family. The classification uses the concept-drift and online-learning vocabulary of Gama et al. [34]—learning modes, adaptation methods, ensemble updating—and the data-stream definition from [89]. This machinery is what turns a pile of papers into the 'rarely both' finding, because each paper is tagged on both adaptation dimensions.

What would settle it

Rerun the same review with a broader keyword set and a lower citation threshold, and count the share of included methods that implement both near real-time data processing and model adaptation; if that share is well above what the paper reports, the 'rarely both' finding fails.

Watch

Extended reading notes

Core claim

The paper argues that AAD in CPS requires two components—near real-time data processing and a predefined learning mode for model adaptation—and that the reviewed literature rarely integrates them. Of the 47 research papers, roughly three-quarters use supervised learning, nearly two-thirds train and test offline, and only about a third report online evaluation. The paper's taxonomy organizes the field by application (industrial control, vehicles, power grid, IoT, smart grid), learning paradigm, and algorithm type, and it concludes that an online unsupervised ensemble method is the most suitable AAD configuration for resource-constrained CPS. A direct corollary the authors draw is that future work should target low detection latency, consistent metrics such as the Matthews correlation coefficient, adaptive thresholding, and protection against adversarial manipulation of the detectors themselves.

Load-bearing premise

The findings depend on the manually curated corpus—built from chosen keyword queries, a 99th-percentile citation cutoff for snowballing, and author-side quality screening—being representative of the AAD-in-CPS literature; the paper itself acknowledges this selection bias in Section VI-B.

Editorial extensions

If this is right

  • If the central finding is correct, the most productive design target for AAD in CPS is a detector that couples streaming data processing with online model updates rather than optimizing one side alone.
  • The taxonomy gives new researchers a way to locate any AAD method within a few minutes and see which combinations of application, paradigm, and adaptation strategy are unexplored.
  • Practitioners selecting an AAD method should expect that most published detectors are evaluated offline and may not meet low-latency deployment constraints.
  • The paper's recommendation of online unsupervised ensembles is a concrete candidate architecture for future CPS defenses, one that could detect unseen attacks without expensive labels.
  • Standardizing on metrics such as precision, recall, false positive and negative rates, and the Matthews correlation coefficient would make future AAD comparisons directly head-to-head.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • The review's own numbers imply that the 'rarely both' gap may be an evaluation-infrastructure problem: online evaluation is harder and less standardized, so methods that couple both components are less likely to be reported even if they exist.
  • The 99th-percentile citation threshold for snowballing likely biases the sample toward highly cited, mostly offline academic methods; a lower threshold would probably surface more operational online systems in smaller venues.
  • A testable next step would be to build a shared streaming benchmark from existing CPS datasets and measure detection latency along with accuracy, which would reveal whether the field's bottleneck is algorithmic or evaluative.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

1 major / 6 minor

Summary. This manuscript presents a systematic literature review (SLR) of adaptive anomaly detection (AAD) for cyber-physical systems. The authors retrieved 397 candidate papers from five databases and, after screening and snowballing, analyzed 47 research papers and 18 survey papers published between 2013 and November 2023. They introduce a taxonomy organized by attack type, CPS application, learning paradigm, data management, and algorithm, and summarize each reviewed paper in per-application tables. The paper's central claims are that it is the first SLR on AAD in CPS and that reviewed works focus on either data processing or model adaptation but rarely integrate both.

Significance. If the central finding is supported, the review would provide a useful organizational map of an emerging subfield and a concrete gap statement that could motivate future research. The paper ships a substantial amount of structured information: detailed per-paper tables with datasets, attacks, strengths, and weaknesses; a taxonomy linking applications, learning paradigms, and algorithm families; and a set of future-research directions. The authors also explicitly acknowledge limitations of the search and selection process (Section VI-B), which is a sign of methodological transparency. The review is not built on derived equations or fitted parameters, so the usual circularity concerns do not apply; the taxonomy is used to organize the corpus, which is normal practice for a literature review. However, the value of the contribution depends on whether the corpus is representative and whether the headline claim about the rarity of integrated AAD is actually measured by the presented methodology.

major comments (1)
  1. [Section IV-A.5 and References] The data extraction process is said to be 'inspired by Gama et al. [89]', but reference [89] is Loeffel's PhD thesis on adaptive machine learning algorithms for data streams, not a work by Gama and colleagues. The concept-drift adaptation framework cited elsewhere as [34] is Gama et al.'s survey. This citation error makes it harder to trace the origin of the extraction template. Please verify the intended reference and correct it.
minor comments (6)
  1. [Section II-B] The phrase 'the former' is used twice in the discussion of supervised anomaly detection: 'The former is related to a significantly lower amount of anomalous data versus normal data' and 'The former entails generating a representative proportion of data samples with anomaly labels.' The second 'former' should be 'latter' or the sentence should be rephrased.
  2. [Section IV-A.3] The list of keywords is typeset inconsistently: some terms use semicolons, some use 'AND' in uppercase, and some are capitalized oddly (e.g., 'adaptive cyber security ; dynamic adaption AND cyber security'). Please standardize the formatting of query terms and consider presenting them in a monospaced or quoted style.
  3. [Figure 2] The caption says 'Figure 2(b) displays the application distribution' but the text in Section IV-B says 'Figure 2(b)' while referring to ICS as 41.5%. The percentages 41.5%, 27.7%, 13.8%, 9.2%, and 7.7% do not sum to 100% (they sum to 99.9%, which is fine for rounding), but the ICS value is called out as questionable due to the inconsistency with Section VI-A.
  4. [Tables II-VI] The tables use inconsistent capitalization for algorithms (e.g., 'Hhull' in Table II for one-class scaled convex hull, 'Extra-Threes' in Table VI for Extra-Trees, 'ANFIS' defined only in text). A final proofreading pass for typographical consistency in table entries is needed.
  5. [Section V-B.1] The sentence 'The model is first trained offline where parameters are optimized using a GA' appears to be missing a closing detail about how the GA was applied (e.g., the fitness function and the number of generations). This is a minor clarity issue in the description of Feng et al. [160].
  6. [References] Several references appear truncated or informal, e.g., 'Y . Zhang and H.-L. Lu' is fine, but 'Jiao et al. [40]' is titled 'Cyberattack-resilient load forecasting with adaptive robust regression' in the text while the reference list entry is 'Cyberattack-resilient load forecasting with adaptive robust regression'—please ensure consistency between in-text titles and the reference list. Also check the spelling of 'International Journal of Forecasting' in [166].

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity: the SLR's findings are descriptive classifications of its reviewed corpus, with no equations, fitted parameters, or self-citation chain that forces the reported result.

full rationale

This is a systematic literature review, not a derivation that predicts empirical quantities from fitted parameters. The central claims are that the paper presents the first SLR on adaptive anomaly detection (AAD) in cyber-physical systems and that most reviewed works address only one component of adaptation. These claims are narrative and taxonomic: they summarize the 65 selected papers according to an explicitly presented taxonomy. There are no equations whose inputs equal outputs and no fitted parameter later relabeled as a prediction. The paper defines AAD as requiring both near real-time data processing and a predefined learning mode, and it later observes that few works satisfy both. That observation is a classification of the collected corpus, not a consequence of the definition by construction; it could have turned out otherwise, and the paper's own inclusion criteria are broader than the two-component definition, which if anything weakens the inference rather than making it circular. The authors cite several of their own prior papers, but those citations are used as examples of anomaly-detection research or dataset resources, not as the justification for the review's headline finding. The paper also acknowledges selection bias in Section VI-B, which is a validity limitation, not a circularity mechanism. Because the review is self-contained against external literature and makes no predictions derived from its own inputs, no circular step is present and a score of 0 is appropriate.

Assumptions & free parameters 2 free parameters · 4 assumptions · 0 invented entities

No free parameters are fitted to data. The entries are author-chosen scope and selection thresholds that determine the corpus and therefore the review's findings.

free parameters (2)
  • 99th percentile citation threshold = 99th percentile
    Used in Section IV-A.3 to select four core papers for forward and backward snowballing. Chosen by the authors without sensitivity analysis, and it shapes the final corpus.
  • Publication window = 2013 to November 2023
    Inclusion criterion that bounds the corpus. A different window would change all trend findings and the taxonomy distributions.
assumptions (4)
  • domain assumption Adaptive anomaly detection requires both near real-time data processing and a predefined learning mode.
    Used to scope inclusion in Section I. The definition drives the central finding that most methods cover only one of these components.
  • domain assumption Methods trained exclusively on benign data are classified as unsupervised.
    Section V groups one-class classification under unsupervised learning, which affects the counts of learning paradigms across the taxonomy.
  • domain assumption The selected databases and search terms capture the AAD in CPS literature.
    The 'first SLR' claim and the trend findings depend on this coverage assumption, stated in Section IV-A.
  • ad hoc to paper Citation count at the 99th percentile indicates high-impact core papers.
    Author-chosen threshold in Section IV-A.3 with no external justification or sensitivity analysis.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Adaptive Anomaly Detection for Identifying Attacks in Cyber-Physical Systems: A Systematic Literature Review." pith.science (2026). https://pith.science/paper/IH4LESPX

@misc{pith2026241114278,
  author       = {Pith},
  title        = {Pith review of: Adaptive Anomaly Detection for Identifying Attacks in Cyber-Physical Systems: A Systematic Literature Review},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/IH4LESPX}},
  note         = {Machine review of arXiv:2411.14278}
}
read the original abstract

Modern cyberattacks in cyber-physical systems (CPS) rapidly evolve and cannot be deterred effectively with most current methods which focused on characterizing past threats. Adaptive anomaly detection (AAD) is among the most promising techniques to detect evolving cyberattacks focused on fast data processing and model adaptation. AAD has been researched in the literature extensively; however, to the best of our knowledge, our work is the first systematic literature review (SLR) on the current research within this field. We present a comprehensive SLR, gathering 397 relevant papers and systematically analyzing 65 of them (47 research and 18 survey papers) on AAD in CPS studies from 2013 to 2023 (November). We introduce a novel taxonomy considering attack types, CPS application, learning paradigm, data management, and algorithms. Our analysis indicates, among other findings, that reviewed works focused on a single aspect of adaptation (either data processing or model adaptation) but rarely in both at the same time. We aim to help researchers to advance the state of the art and help practitioners to become familiar with recent progress in this field. We identify the limitations of the state of the art and provide recommendations for future research directions.

Figures

Figures reproduced from arXiv: 2411.14278 by the authors.

Figure 1
Figure 1. Flow chart of the search and selection process, highlighting stages from initial identification through screening, eligibility, and final inclusion. This [PITH_FULL_IMAGE:figures/full_fig_p008_1.png] view at source ↗
Figure 2
Figure 2. Distributions across selected papers in the review. (a) Digital libraries distribution, with IEEE Xplore, Springer Link, Science Direct, and ACM Digital [PITH_FULL_IMAGE:figures/full_fig_p009_2.png] view at source ↗
Figure 3
Figure 3. AAD for CPS taxonomy. The numbers indicate the sections that cover each topic in the taxonomy. [PITH_FULL_IMAGE:figures/full_fig_p010_3.png] view at source ↗
Figures from the paper (1 more)
Figure 4
Figure 4. Figure 4: AAD for CPS distribution among application, learning paradigm, data management, and algorithm categories. [PITH_FULL_IMAGE:figures/full_fig_p023_4.png]

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

203 extracted references · 71 canonical work pages

  1. [89]

    Adaptive machine learning algorithms for data streams subject to concept drifts,

    P.-X. Loeffel, “Adaptive machine learning algorithms for data streams subject to concept drifts,” Ph.D. dissertation, Universit´e Pierre et Marie Curie-Paris VI, 2017

  2. [34]

    A survey on concept drift adaptation,

    J. Gama, I. ˇZliobait˙e, A. Bifet, M. Pechenizkiy, and A. Bouchachia, “A survey on concept drift adaptation,” ACM computing surveys (CSUR) , vol. 46, no. 4, pp. 1–37, 2014

  3. [1]

    Big data meet cyber-physical systems: A panoramic survey,

    R. Atat, L. Liu, J. Wu, G. Li, C. Ye, and Y . Yang, “Big data meet cyber-physical systems: A panoramic survey,” IEEE Access, vol. 6, pp. 73 603–73 636, 2018

  4. [2]

    Cps data streams analytics based on machine learning for cloud and fog computing: A survey,

    X. Fei, N. Shah, N. Verba, K.-M. Chao, V . Sanchez-Anguix, J. Lewandowski, A. James, and Z. Usman, “Cps data streams analytics based on machine learning for cloud and fog computing: A survey,” Future generation computer systems , vol. 90, pp. 435–450, 2019

  5. [3]

    Cybersecurity of industrial cyber-physical systems: A review,

    H. Kayan, M. Nunes, O. Rana, P. Burnap, and C. Perera, “Cybersecurity of industrial cyber-physical systems: A review,” ACM Computing Surveys (CSUR), vol. 54, no. 11s, pp. 1–35, 2022

  6. [4]

    On the effectiveness of address-space randomization,

    H. Shacham, M. Page, B. Pfaff, E.-J. Goh, N. Modadugu, and D. Boneh, “On the effectiveness of address-space randomization,” in Proceedings of the 11th ACM conference on Computer and communi- cations security, 2004, pp. 298–307

  7. [5]

    Trackos: A security-aware real-time operating system,

    L. Pike, P. Hickey, T. Elliott, E. Mertens, and A. Tomb, “Trackos: A security-aware real-time operating system,” in Runtime Verification: 16th International Conference, RV 2016, Madrid, Spain, September 23–30, 2016, Proceedings 7 . Springer, 2016, pp. 302–317

  8. [6]

    Protecting bare-metal embedded systems with privilege overlays,

    A. A. Clements, N. S. Almakhdhub, K. S. Saab, P. Srivastava, J. Koo, S. Bagchi, and M. Payer, “Protecting bare-metal embedded systems with privilege overlays,” in 2017 IEEE Symposium on Security and Privacy (SP). San Jose, CA: IEEE, 2017, pp. 289–303

Show all 203 references
  1. [7]

    Spoofers use fake gps signals to knock a yacht off course,

    A. H. Rutkin, “Spoofers use fake gps signals to knock a yacht off course,” MIT Technology Review, 2013

  2. [8]

    Non-invasive spoofing attacks for anti-lock braking systems,

    Y . Shoukry, P. Martin, P. Tabuada, and M. Srivastava, “Non-invasive spoofing attacks for anti-lock braking systems,” in Cryptographic Hardware and Embedded Systems-CHES 2013: 15th International Workshop, Santa Barbara, CA, USA, August 20-23, 2013. 15. Springer, 2013, pp. 55–72

  3. [9]

    Remote attacks on automated vehicles sensors: Experiments on camera and lidar,

    J. Petit, B. Stottelaar, M. Feiri, and F. Kargl, “Remote attacks on automated vehicles sensors: Experiments on camera and lidar,” Black Hat Europe, vol. 11, no. 2015, p. 995, 2015

  4. [10]

    Anomaly detection: A survey,

    V . Chandola, A. Banerjee, and V . Kumar, “Anomaly detection: A survey,” ACM Computing Surveys (CSUR) , vol. 41, no. 3, pp. 1–58, 2009

  5. [11]

    Kitsune: an ensemble of autoencoders for online network intrusion detection,

    Y . Mirsky, T. Doitshman, Y . Elovici, and A. Shabtai, “Kitsune: an ensemble of autoencoders for online network intrusion detection,” arXiv preprint arXiv:1802.09089 , 2018

  6. [12]

    Using bursty announcements for detecting bgp routing anomalies,

    P. Moriano, R. Hill, and L. J. Camp, “Using bursty announcements for detecting bgp routing anomalies,” Computer Networks, vol. 188, p. 107835, 2021

  7. [13]

    Detecting can masquerade attacks with signal clustering similarity,

    P. Moriano, R. A. Bridges, and M. D. Iannacone, “Detecting can masquerade attacks with signal clustering similarity,” in Proceedings Fourth International Workshop on Automotive and Autonomous Vehicle Security, ser. AutoSec 2022. Internet Society, 2022. [Online]. Available: htt...

  8. [14]

    False alarm minimization tech- niques in signature-based intrusion detection systems: A survey,

    N. Hubballi and V . Suryanarayanan, “False alarm minimization tech- niques in signature-based intrusion detection systems: A survey,” Computer Communications, vol. 49, pp. 1–17, 2014

  9. [15]

    A signature-based intrusion detection system for the internet of things,

    P. Ioulianou, V . Vasilakis, I. Moscholios, and M. Logothetis, “A signature-based intrusion detection system for the internet of things,” in Information and Communication Technology Form , AUT, 2018

  10. [16]

    A survey of intrusion detection for in-vehicle networks,

    W. Wu, R. Li, G. Xie, J. An, Y . Bai, J. Zhou, and K. Li, “A survey of intrusion detection for in-vehicle networks,” IEEE Transactions on Intelligent Transportation Systems, vol. 21, no. 3, pp. 919–933, 2019

  11. [17]

    Deep learning- based anomaly detection in cyber-physical systems: Progress and opportunities,

    Y . Luo, Y . Xiao, L. Cheng, G. Peng, and D. Yao, “Deep learning- based anomaly detection in cyber-physical systems: Progress and opportunities,” ACM Computing Surveys (CSUR) , vol. 54, no. 5, pp. 1–36, 2021

  12. [18]

    Canshield: Deep learning-based intrusion detection framework for controller area networks at the signal-level,

    M. H. Shahriar, Y . Xiao, P. Moriano, W. Lou, and Y . T. Hou, “Canshield: Deep learning-based intrusion detection framework for controller area networks at the signal-level,” IEEE Internet of Things Journal, vol. 10, pp. 22 111–22 127, 2023

  13. [19]

    Benchmarking unsupervised online ids for masquerade attacks in can,

    P. Moriano, S. C. Hespeler, M. Li, and R. A. Bridges, “Benchmarking unsupervised online ids for masquerade attacks in can,” 2024. [Online]. Available: https://arxiv.org/abs/2406.13778

  14. [20]

    High-performance unsupervised anomaly detection for cyber-physical system networks,

    P. Schneider and K. B ¨ottinger, “High-performance unsupervised anomaly detection for cyber-physical system networks,” in Proceedings of the 2018 Workshop on Cyber-Physical Systems Security and Privacy, Toronto, CA, 2018, pp. 1–12

  15. [21]

    Data-correlation-aware unsupervised deep-learning model for anomaly detection in cyber–physical systems,

    L. Xi, R. Wang, and Z. J. Haas, “Data-correlation-aware unsupervised deep-learning model for anomaly detection in cyber–physical systems,” IEEE Internet of Things Journal , vol. 9, no. 22, pp. 22 410–22 421, 2022

  16. [22]

    Attack-resilient sensor fusion for safety-critical cyber-physical systems,

    R. Ivanov, M. Pajic, and I. Lee, “Attack-resilient sensor fusion for safety-critical cyber-physical systems,” ACM Transactions on Embed- ded Computing Systems (TECS) , vol. 15, no. 1, pp. 1–24, 2016

  17. [23]

    Attack-resilient sensor fusion for cooperative adaptive cruise control,

    P. Lu, L. Zhang, B. B. Park, and L. Feng, “Attack-resilient sensor fusion for cooperative adaptive cruise control,” in 2018 21st International Conference on Intelligent Transportation Systems (ITSC) . Maui, HI: IEEE, 2018, pp. 3955–3960

  18. [24]

    {SA VIOR}: Securing autonomous vehicles with robust physi- cal invariants,

    R. Quinonez, J. Giraldo, L. Salazar, E. Bauman, A. Cardenas, and Z. Lin, “{SA VIOR}: Securing autonomous vehicles with robust physi- cal invariants,” in 29th USENIX security symposium (USENIX Security 20), 2020, pp. 895–912

  19. [25]

    A survey of physics-based attack detection in cyber-physical systems,

    J. Giraldo, D. Urbina, A. Cardenas, J. Valente, M. Faisal, J. Ruths, N. O. Tippenhauer, H. Sandberg, and R. Candell, “A survey of physics-based attack detection in cyber-physical systems,” ACM Computing Surveys (CSUR), vol. 51, no. 4, pp. 1–36, 2018

  20. [26]

    Behaviour-based attack detection and classification in cyber physical systems using machine learning,

    K. N. Junejo and J. Goh, “Behaviour-based attack detection and classification in cyber physical systems using machine learning,” in Proceedings of the 2nd ACM international workshop on cyber-physical system security, Xi’an, CN, 2016, pp. 34–43

  21. [27]

    Intelligent sensor attack detection and identification for automotive cyber-physical systems,

    J. Shin, Y . Baek, Y . Eun, and S. H. Son, “Intelligent sensor attack detection and identification for automotive cyber-physical systems,” in 2017 IEEE Symposium series on computational intelligence (SSCI) . Honolulu, HI: IEEE, 2017, pp. 1–8. 26

  22. [28]

    Cognitive cybersecurity for cps-iot enabled healthcare ecosystems,

    H. Abie, “Cognitive cybersecurity for cps-iot enabled healthcare ecosystems,” in 2019 13th International Symposium on Medical In- formation and Communication Technology (ISMICT) . IEEE, 2019, pp. 1–6

  23. [29]

    Cognitive security: A comprehensive study of cognitive science in cybersecurity,

    R. O. Andrade and S. G. Yoo, “Cognitive security: A comprehensive study of cognitive science in cybersecurity,” Journal of Information Security and Applications , vol. 48, p. 102352, 2019

  24. [30]

    Anomaly detection and its adaptation: Studies on cyber- physical systems,

    M. Raciti, “Anomaly detection and its adaptation: Studies on cyber- physical systems,” Ph.D. dissertation, Link ¨oping University Electronic Press, 2013

  25. [31]

    Protecting cyber physical production systems using anomaly detection to enable self-adaptation,

    G. Settanni, F. Skopik, A. Karaj, M. Wurzenberger, and R. Fiedler, “Protecting cyber physical production systems using anomaly detection to enable self-adaptation,” in 2018 IEEE Industrial Cyber-Physical Systems (ICPS). Saint Petersburg, RU: IEEE, 2018, pp. 173–180

  26. [32]

    Real-time adaptive sensor attack detection in autonomous cyber-physical systems,

    F. Akowuah and F. Kong, “Real-time adaptive sensor attack detection in autonomous cyber-physical systems,” in2021 IEEE 27th Real-Time and Embedded Technology and Applications Symposium (RTAS) . IEEE, 2021, pp. 237–250

  27. [33]

    Machine learning in computer security is difficult to fix,

    B. Biggio, “Machine learning in computer security is difficult to fix,” Communications of the ACM , vol. 67, no. 11, pp. 103–103, 2024

  28. [35]

    Ddoa: A dirichlet-based detection scheme for opportunistic attacks in smart grid cyber-physical system,

    B. Li, R. Lu, W. Wang, and K.-K. R. Choo, “Ddoa: A dirichlet-based detection scheme for opportunistic attacks in smart grid cyber-physical system,” IEEE Transactions on Information Forensics and Security , vol. 11, no. 11, pp. 2415–2425, 2016

  29. [36]

    Applying hoeffding adaptive trees for real-time cyber-power event and intrusion classification,

    U. Adhikari, T. H. Morris, and S. Pan, “Applying hoeffding adaptive trees for real-time cyber-power event and intrusion classification,”IEEE Transactions on Smart Grid , vol. 9, no. 5, pp. 4049–4060, 2017

  30. [37]

    Real-time sensor anomaly detection and identification in automated vehicles,

    F. Van Wyk, Y . Wang, A. Khojandi, and N. Masoud, “Real-time sensor anomaly detection and identification in automated vehicles,” IEEE Transactions on Intelligent Transportation Systems , vol. 21, no. 3, pp. 1264–1276, 2019

  31. [38]

    Iot-cad: Context- aware adaptive anomaly detection in iot systems through sensor as- sociation,

    R. Yasaei, F. Hernandez, and M. A. A. Faruque, “Iot-cad: Context- aware adaptive anomaly detection in iot systems through sensor as- sociation,” in Proceedings of the 39th international conference on computer-aided design, Virtual Event, USA, 2020, pp. 1–9

  32. [39]

    Afrl: Adaptive federated reinforcement learning for intelligent jamming defense in fanet,

    N. I. Mowla, N. H. Tran, I. Doh, and K. Chae, “Afrl: Adaptive federated reinforcement learning for intelligent jamming defense in fanet,” Journal of Communications and Networks , vol. 22, no. 3, pp. 244–258, 2020

  33. [40]

    Cyberattack-resilient load forecasting with adaptive robust regression,

    J. Jiao, Z. Tang, P. Zhang, M. Yue, and J. Yan, “Cyberattack-resilient load forecasting with adaptive robust regression,” International Journal of Forecasting, vol. 38, no. 3, pp. 910–919, 2022

  34. [41]

    A data-driven based security situational awareness framework for power systems,

    J. Ding, C. Lu, and B. Li, “A data-driven based security situational awareness framework for power systems,”Journal of Signal Processing Systems, vol. 94, no. 11, pp. 1159–1168, 2022

  35. [42]

    Novel online network intrusion detection system for industrial iot based on oi-svdd and as-elm,

    E. Gyamfi and A. D. Jurcut, “Novel online network intrusion detection system for industrial iot based on oi-svdd and as-elm,” IEEE Internet of Things Journal , vol. 10, no. 5, pp. 3827–3839, 2022

  36. [43]

    Real-time power system event detection: A novel instance selection approach,

    G. Intriago and Y . Zhang, “Real-time power system event detection: A novel instance selection approach,” IEEE Access, vol. 11, pp. 46 765– 46 781, 2023

  37. [44]

    Adam: an adaptive ddos attack mitigation scheme in software-defined cyber-physical system,

    T. Cai, T. Jia, S. Adepu, Y . Li, and Z. Yang, “Adam: an adaptive ddos attack mitigation scheme in software-defined cyber-physical system,” IEEE Transactions on Industrial Informatics , vol. 19, no. 6, pp. 7802– 7813, 2023

  38. [45]

    A survey of data mining and machine learning methods for cyber security intrusion detection,

    A. L. Buczak and E. Guven, “A survey of data mining and machine learning methods for cyber security intrusion detection,” IEEE Com- munications Surveys & Tutorials, vol. 18, no. 2, pp. 1153–1176, 2015

  39. [46]

    Resilient machine learning for networked cyber physical systems: A survey for machine learning security to securing machine learning for cps,

    F. O. Olowononi, D. B. Rawat, and C. Liu, “Resilient machine learning for networked cyber physical systems: A survey for machine learning security to securing machine learning for cps,” IEEE Communications Surveys & Tutorials, vol. 23, no. 1, pp. 524–552, 2020

  40. [47]

    A survey of cyber attacks on cyber physical systems: Recent advances and challenges,

    W. Duo, M. Zhou, and A. Abusorrah, “A survey of cyber attacks on cyber physical systems: Recent advances and challenges,” IEEE/CAA Journal of Automatica Sinica , vol. 9, no. 5, pp. 784–800, 2022

  41. [48]

    Detection of false data injection attacks in smart grid cyber- physical systems,

    B. Li, “Detection of false data injection attacks in smart grid cyber- physical systems,” Ph.D. dissertation, Springer, 2019

  42. [49]

    The past, present and future of cyber-physical systems: A focus on models,

    E. A. Lee, “The past, present and future of cyber-physical systems: A focus on models,” Sensors, vol. 15, no. 3, pp. 4837–4869, 2015

  43. [50]

    Wiener, Cybernetics or Control and Communication in the Animal and the Machine

    N. Wiener, Cybernetics or Control and Communication in the Animal and the Machine . MIT press, 2019

  44. [51]

    Ai-based intrusion detection systems for in-vehicle networks: A survey,

    S. Rajapaksha, H. Kalutarage, M. O. Al-Kadri, A. Petrovski, G. Madzudzo, and M. Cheah, “Ai-based intrusion detection systems for in-vehicle networks: A survey,” ACM Computing Surveys , vol. 55, no. 11, pp. 1–40, 2023

  45. [52]

    A comprehensive guide to can ids data and introduction of the road dataset,

    M. E. Verma, R. A. Bridges, M. D. Iannacone, S. C. Hollifield, P. Moriano, S. C. Hespeler, B. Kay, and F. L. Combs, “A comprehensive guide to can ids data and introduction of the road dataset,” PLoS one, vol. 19, no. 1, p. e0296879, 2024

  46. [53]

    Secure control against replay attacks,

    Y . Mo and B. Sinopoli, “Secure control against replay attacks,” in 2009 47th annual Allerton conference on communication, control, and computing (Allerton). Monticello, IL: IEEE, 2009, pp. 911–918

  47. [54]

    Man-in-the-middle attacks and defence in a power system cyber-physical testbed,

    P. Wlazlo, A. Sahu, Z. Mao, H. Huang, A. Goulart, K. Davis, and S. Zonouz, “Man-in-the-middle attacks and defence in a power system cyber-physical testbed,” IET Cyber-Physical Systems: Theory & Applications, vol. 6, no. 3, pp. 164–177, 2021

  48. [55]

    Cyber attacks in cyber-physical microgrid systems: A comprehensive review,

    S. Suprabhath Koduru, V . S. P. Machina, and S. Madichetty, “Cyber attacks in cyber-physical microgrid systems: A comprehensive review,” Energies, vol. 16, no. 12, p. 4573, 2023

  49. [56]

    Cyber-physical systems security—a survey,

    A. Humayed, J. Lin, F. Li, and B. Luo, “Cyber-physical systems security—a survey,” IEEE Internet of Things Journal , vol. 4, no. 6, pp. 1802–1831, 2017

  50. [57]

    Unmanned aerial vehicles: Vulnerability to cyber attacks,

    S. Dahiya and M. Garg, “Unmanned aerial vehicles: Vulnerability to cyber attacks,” inProceedings of UASG 2019: Unmanned Aerial System in Geomatics 1 . Roorkee, India: Springer, 2020, pp. 201–211

  51. [58]

    Cy- ber attack vulnerabilities analysis for unmanned aerial vehicles,

    A. Kim, B. Wampler, J. Goppert, I. Hwang, and H. Aldridge, “Cy- ber attack vulnerabilities analysis for unmanned aerial vehicles,” in Infotech@ Aerospace 2012 , 2012, p. 2438

  52. [59]

    Review of unmanned aircraft system (uas),

    S. G. Gupta, D. M. Ghonge, and P. M. Jawandhiya, “Review of unmanned aircraft system (uas),” International Journal of Advanced Research in Computer Engineering & Technology (IJARCET) Volume , vol. 2, pp. 1646–1658, 2013

  53. [60]

    Defense techniques against cyber attacks on unmanned aerial vehicles,

    C. Gudla, M. S. Rana, and A. H. Sung, “Defense techniques against cyber attacks on unmanned aerial vehicles,” inProceedings of the Inter- national Conference on Embedded Systems, Cyber-Physical Systems, and Applications (ESCS) . The Steering Committee of The World Congress in ...

  54. [61]

    Unmanned aerial vehicle systems for disaster relief: Tornado alley,

    W. DeBusk, “Unmanned aerial vehicle systems for disaster relief: Tornado alley,” in AIAA Infotech@ Aerospace 2010 , Atlanta, Georgia, 2010, p. 3506

  55. [62]

    Supporting search and rescue operations with uavs,

    S. Waharte and N. Trigoni, “Supporting search and rescue operations with uavs,” in 2010 international conference on emerging security technologies. Canterbury, UK: IEEE, 2010, pp. 142–147

  56. [63]

    The uses of unmanned aerial vehicles–uav’s-(or drones) in social logistic: Natural disasters response and humanitarian relief aid,

    M. A. R. Estrada and A. Ndoma, “The uses of unmanned aerial vehicles–uav’s-(or drones) in social logistic: Natural disasters response and humanitarian relief aid,” Procedia Computer Science, vol. 149, pp. 375–383, 2019

  57. [64]

    Lightweight digital signature solution to defend micro aerial vehicles against man-in-the-middle attack,

    Y . Li and C. Pu, “Lightweight digital signature solution to defend micro aerial vehicles against man-in-the-middle attack,” in 2020 IEEE 23rd International Conference on Computational Science and Engineering (CSE). Guangzhou, CN: IEEE, 2020, pp. 92–97

  58. [65]

    Robotics cyber security: Vulnerabilities, attacks, countermeasures, and recom- mendations,

    J.-P. A. Yaacoub, H. N. Noura, O. Salman, and A. Chehab, “Robotics cyber security: Vulnerabilities, attacks, countermeasures, and recom- mendations,” International Journal of Information Security , vol. 21, no. 1, pp. 115–158, 2022

  59. [66]

    False data injection attacks in internet of things,

    B. Bostami, M. Ahmed, and S. Choudhury, “False data injection attacks in internet of things,” Performability in internet of things , no. 1, pp. 47–58, 2019

  60. [67]

    D. M. Hawkins, Identification of outliers . Springer, 1980, vol. 11

  61. [68]

    Anomaly-based network intrusion detection: Techniques, systems and challenges,

    P. Garcia-Teodoro, J. Diaz-Verdejo, G. Maci ´a-Fern´andez, and E. V´azquez, “Anomaly-based network intrusion detection: Techniques, systems and challenges,” Computers & Security , vol. 28, no. 1-2, pp. 18–28, 2009

  62. [69]

    The opti- mized anomaly detection models based on an approach of dealing with imbalanced dataset for credit card fraud detection,

    Y .-F. Zhang, H.-L. Lu, H.-F. Lin, X.-C. Qiao, and H. Zheng, “The opti- mized anomaly detection models based on an approach of dealing with imbalanced dataset for credit card fraud detection,” Mobile Information Systems, vol. 2022, no. 1, p. 8027903, 2022

  63. [70]

    Unsupervised profiling methods for fraud detection,

    R. J. Bolton, D. J. Hand et al. , “Unsupervised profiling methods for fraud detection,” Credit scoring and credit control VII , pp. 235–255, 2001

  64. [71]

    Detecting prefix hijackings in the internet with argus,

    X. Shi, Y . Xiang, Z. Wang, X. Yin, and J. Wu, “Detecting prefix hijackings in the internet with argus,” in Proceedings of the 2012 Internet Measurement Conference , Boston, MA, 2012, pp. 15–28

  65. [72]

    Evilseed: A guided approach to finding malicious web pages,

    L. Invernizzi, P. M. Comparetti, S. Benvenuti, C. Kruegel, M. Cova, and G. Vigna, “Evilseed: A guided approach to finding malicious web pages,” in 2012 IEEE Symposium on Security and Privacy . San Francisco, CA: IEEE, 2012, pp. 428–442

  66. [73]

    Learning to predict rare events in event sequences

    G. M. Weiss and H. Hirsh, “Learning to predict rare events in event sequences.” in Proceedings of the 4th International Conference on 27 Knowledge Discovery and Data Mining, vol. 98, New York City, 1998, pp. 359–363

  67. [74]

    Mining needle in a haystack: classifying rare classes via two-phase rule induction,

    M. V . Joshi, R. C. Agarwal, and V . Kumar, “Mining needle in a haystack: classifying rare classes via two-phase rule induction,” in Proceedings of the 2001 ACM SIGMOD International Conference on Management of data , Santa Barbara, CA, 2001, pp. 91–102

  68. [75]

    Predicting rare events in temporal domains,

    R. Vilalta and S. Ma, “Predicting rare events in temporal domains,” in 2002 IEEE International Conference on Data Mining, 2002. Proceed- ings. Maebashi City, JP: IEEE, 2002, pp. 474–481

  69. [76]

    Predicting rare classes: Can boosting make any weak learner strong?

    M. V . Joshi, R. C. Agarwal, and V . Kumar, “Predicting rare classes: Can boosting make any weak learner strong?” in Proceedings of the eighth ACM SIGKDD international conference on Knowledge Discovery and Data Mining, Edmonton, Alberta, CA, 2002, pp. 297–306

  70. [77]

    Special issue on learning from imbalanced data sets,

    N. V . Chawla, N. Japkowicz, and A. Kotcz, “Special issue on learning from imbalanced data sets,” ACM SIGKDD Explorations Newsletter , vol. 6, no. 1, pp. 1–6, 2004

  71. [78]

    Minority report in fraud detection: classification of skewed data,

    C. Phua, D. Alahakoon, and V . Lee, “Minority report in fraud detection: classification of skewed data,” Acm Sigkdd Explorations Newsletter , vol. 6, no. 1, pp. 50–59, 2004

  72. [79]

    Resampling approach for anomaly detection in multispectral images,

    J. P. Theiler and D. M. Cai, “Resampling approach for anomaly detection in multispectral images,” in Algorithms and Technologies for Multispectral, Hyperspectral, and Ultraspectral Imagery IX, vol. 5093. SPIE, 2003, pp. 230–240

  73. [80]

    Outlier detection by active learning,

    N. Abe, B. Zadrozny, and J. Langford, “Outlier detection by active learning,” in Proceedings of the 12th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, 2006, pp. 504– 509

  74. [81]

    A classification framework for anomaly detection

    I. Steinwart, D. Hush, and C. Scovel, “A classification framework for anomaly detection.” Journal of Machine Learning Research , vol. 6, no. 2, pp. 211–232, 2005

  75. [82]

    Detecting known and unknown faults in automotive systems using ensemble-based anomaly detection,

    A. Theissler, “Detecting known and unknown faults in automotive systems using ensemble-based anomaly detection,” Knowledge-Based Systems, vol. 123, pp. 163–173, 2017

  76. [83]

    Detecting intrusions using system calls: Alternative data models,

    C. Warrender, S. Forrest, and B. Pearlmutter, “Detecting intrusions using system calls: Alternative data models,” in Proceedings of the 1999 IEEE symposium on security and privacy . Oakland, CA: IEEE, 1999, pp. 133–145

  77. [84]

    A comparison of negative and positive selec- tion algorithms in novel pattern detection,

    D. Dasgupta and F. Nino, “A comparison of negative and positive selec- tion algorithms in novel pattern detection,” in 2000 IEEE International Conference on Systems, Man and Cybernetics , vol. 1. Nashville, TN: IEEE, 2000, pp. 125–130

  78. [85]

    Anomaly detection in multidi- mensional data using negative selection algorithm,

    D. Dasgupta and N. S. Majumdar, “Anomaly detection in multidi- mensional data using negative selection algorithm,” in Proceedings of the 2002 Congress on Evolutionary Computation. CEC’02 , vol. 2. Honolulu, Hawaii: IEEE, 2002, pp. 1039–1044

  79. [86]

    A comparative evaluation of unsupervised anomaly detection algorithms for multivariate data,

    M. Goldstein and S. Uchida, “A comparative evaluation of unsupervised anomaly detection algorithms for multivariate data,” PloS one, vol. 11, no. 4, p. e0152173, 2016

  80. [87]

    Deep autoencoding gaussian mixture model for unsu- pervised anomaly detection,

    B. Zong, Q. Song, M. R. Min, W. Cheng, C. Lumezanu, D. Cho, and H. Chen, “Deep autoencoding gaussian mixture model for unsu- pervised anomaly detection,” in International conference on learning representations, Vancouver, CA, 2018, pp. 1–19

  81. [88]

    Canet: An unsupervised intrusion detection system for high dimensional can bus data,

    M. Hanselmann, T. Strauss, K. Dormann, and H. Ulmer, “Canet: An unsupervised intrusion detection system for high dimensional can bus data,” IEEE Access, vol. 8, pp. 58 194–58 205, 2020

  82. [90]

    Deltagrad: Rapid retraining of machine learning models,

    Y . Wu, E. Dobriban, and S. Davidson, “Deltagrad: Rapid retraining of machine learning models,” in International Conference on Machine Learning, Virtual Only, 2020, pp. 10 355–10 366

  83. [91]

    Cost-aware retraining for ma- chine learning,

    A. Mahadevan and M. Mathioudakis, “Cost-aware retraining for ma- chine learning,” Knowledge-Based Systems, vol. 293, p. 111610, 2024

  84. [92]

    Large scale incremental learning,

    Y . Wu, Y . Chen, L. Wang, Y . Ye, Z. Liu, Y . Guo, and Y . Fu, “Large scale incremental learning,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , Nashville, TN, 2019, pp. 374–382

  85. [93]

    Three types of incremental learning,

    G. M. Van de Ven, T. Tuytelaars, and A. S. Tolias, “Three types of incremental learning,” Nature Machine Intelligence, vol. 4, no. 12, pp. 1185–1197, 2022

  86. [94]

    Adaptive information filtering: Learning in the presence of concept drifts,

    R. Klinkenberg and I. Renz, “Adaptive information filtering: Learning in the presence of concept drifts,” Learning for Text Categorization , pp. 33–40, 1998

  87. [95]

    Enhancing text classification to improve information filtering,

    C. Lanquillon, “Enhancing text classification to improve information filtering,” Ph.D. dissertation, Otto-von-Guericke-Universit ¨at Magde- burg, Universit¨atsbibliothek, 2001

  88. [96]

    Kalman filters and adaptive windows for learning in data streams,

    A. Bifet and R. Gavalda, “Kalman filters and adaptive windows for learning in data streams,” in International conference on discovery science. Barcelona, Spain: Springer, 2006, pp. 29–40

  89. [97]

    Decision trees for mining data streams,

    J. Gama, R. Fernandes, and R. Rocha, “Decision trees for mining data streams,” Intelligent Data Analysis , vol. 10, no. 1, pp. 23–45, 2006

  90. [98]

    Learning in the presence of concept drift and hidden contexts,

    G. Widmer and M. Kubat, “Learning in the presence of concept drift and hidden contexts,” Machine learning, vol. 23, pp. 69–101, 1996

  91. [99]

    Classifier ensembles for changing environments,

    L. I. Kuncheva, “Classifier ensembles for changing environments,” in Multiple Classifier Systems: 5th International Workshop, MCS 2004, Cagliari, Italy, June 9-11, 2004. Proceedings 5 . Springer, 2004, pp. 1–15

  92. [100]

    Handling local concept drift with dynamic integration of classifiers: Domain of antibiotic resistance in nosocomial infections,

    A. Tsymbal, M. Pechenizkiy, P. Cunningham, and S. Puuronen, “Handling local concept drift with dynamic integration of classifiers: Domain of antibiotic resistance in nosocomial infections,” in 19th IEEE Symposium on Computer-Based Medical Systems (CBMS’06) . Salt Lake City, UT...

  93. [101]

    Online ensemble learning: An empirical study,

    A. Fern and R. Givan, “Online ensemble learning: An empirical study,” Machine Learning, vol. 53, pp. 71–109, 2003

  94. [102]

    Combining online classification approaches for changing environments,

    J. J. Rodr ´ıguez and L. I. Kuncheva, “Combining online classification approaches for changing environments,” in Structural, Syntactic, and Statistical Pattern Recognition: Joint IAPR International Workshop, SSPR & SPR 2008, Orlando, USA, December 4-6, 2008. Proceedings . Spri...

  95. [103]

    A streaming ensemble algorithm (sea) for large-scale classification,

    W. N. Street and Y . Kim, “A streaming ensemble algorithm (sea) for large-scale classification,” in Proceedings of the Seventh ACM SIGKDD International Conference on Knowledge Discovery and Data Mining , San Francisco, CA, 2001, pp. 377–382

  96. [104]

    Incremental learning with multi-level adaptation,

    A. Bouchachia, “Incremental learning with multi-level adaptation,” Neurocomputing, vol. 74, no. 11, pp. 1785–1799, 2011

  97. [105]

    Issues in data stream management,

    L. Golab and M. T. ¨Ozsu, “Issues in data stream management,” ACM Sigmod Record, vol. 32, no. 2, pp. 5–14, 2003

  98. [106]

    Data stream analysis: Foundations, major tasks and tools,

    M. Bahri, A. Bifet, J. Gama, H. M. Gomes, and S. Maniu, “Data stream analysis: Foundations, major tasks and tools,” Wiley Interdisciplinary Reviews: Data Mining and Knowledge Discovery , vol. 11, no. 3, p. e1405, 2021

  99. [107]

    Data stream processing on embedded devices,

    R. M ¨uller, “Data stream processing on embedded devices,” Ph.D. dissertation, ETH Zurich, 2010

  100. [108]

    Mining data streams: a review,

    M. M. Gaber, A. Zaslavsky, and S. Krishnaswamy, “Mining data streams: a review,” ACM Sigmod Record , vol. 34, no. 2, pp. 18–26, 2005

  101. [109]

    Issues in evaluation of stream learning algorithms,

    J. Gama, R. Sebastiao, and P. P. Rodrigues, “Issues in evaluation of stream learning algorithms,” in Proceedings of the 15th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining , Paris, FR, 2009, pp. 329–338

  102. [110]

    Evaluating time series forecast- ing models: An empirical study on performance estimation methods,

    V . Cerqueira, L. Torgo, and I. Mozetiˇc, “Evaluating time series forecast- ing models: An empirical study on performance estimation methods,” Machine Learning, vol. 109, no. 11, pp. 1997–2028, 2020

  103. [111]

    A review of various modern strategies for mitigation of cyber attacks in smart grids,

    M. Saad, S. B. A. Bukhari, and C. H. Kim, “A review of various modern strategies for mitigation of cyber attacks in smart grids,” in 2019 IEEE Transportation Electrification Conference and Expo, Asia- Pacific (ITEC Asia-Pacific). Seogwipo-si, KR: IEEE, 2019, pp. 1–7

  104. [112]

    False data injection attacks against smart gird state estimation: Construction, detection and defense,

    M. Zhang, C. Shen, N. He, S. Han, Q. Li, Q. Wang, and X. Guan, “False data injection attacks against smart gird state estimation: Construction, detection and defense,” Science China Technological Sciences, vol. 62, no. 12, pp. 2077–2087, 2019

  105. [113]

    Classifying resilience approaches for protecting smart grids against cyber threats,

    A. D. Syrmakesis, C. Alcaraz, and N. D. Hatziargyriou, “Classifying resilience approaches for protecting smart grids against cyber threats,” International Journal of Information Security, vol. 21, no. 5, pp. 1189– 1210, 2022

  106. [114]

    From a literature review to a conceptual framework of enablers for smart manufacturing control,

    R. A. Rojas and E. Rauch, “From a literature review to a conceptual framework of enablers for smart manufacturing control,” The Interna- tional Journal of Advanced Manufacturing Technology , vol. 104, pp. 517–533, 2019

  107. [115]

    Self-adaptation techniques in cyber-physical systems (cpss),

    S. Zeadally, T. Sanislav, and G. D. Mois, “Self-adaptation techniques in cyber-physical systems (cpss),” IEEE Access , vol. 7, pp. 171 126– 171 139, 2019

  108. [116]

    Adversarial machine learning attacks and defense methods in the cyber security domain,

    I. Rosenberg, A. Shabtai, Y . Elovici, and L. Rokach, “Adversarial machine learning attacks and defense methods in the cyber security domain,” ACM Computing Surveys (CSUR) , vol. 54, no. 5, pp. 1–36, 2021

  109. [117]

    A review on security analysis of cyber physical systems using machine learning,

    A. A. Jamal, A.-A. M. Majid, A. Konev, T. Kosachenko, and A. Shelu- panov, “A review on security analysis of cyber physical systems using machine learning,” Materials today: proceedings , vol. 80, pp. 2302– 2306, 2023

  110. [118]

    A systematic review on security and safety of self- 28 adaptive systems,

    I. Pekaric, R. Groner, T. Witte, J. G. Adigun, A. Raschke, M. Felderer, and M. Tichy, “A systematic review on security and safety of self- 28 adaptive systems,” Journal of Systems and Software, vol. 203, pp. 1–25, 2023

  111. [119]

    Machine learning in industrial control system (ics) security: current landscape, opportuni- ties and challenges,

    A. M. Koay, R. K. L. Ko, H. Hettema, and K. Radke, “Machine learning in industrial control system (ics) security: current landscape, opportuni- ties and challenges,” Journal of Intelligent Information Systems, vol. 60, no. 2, pp. 377–405, 2023

  112. [120]

    A survey on secure transmission in internet of things: taxonomy, recent techniques, re- search requirements, and challenges,

    S. N. Mahapatra, B. K. Singh, and V . Kumar, “A survey on secure transmission in internet of things: taxonomy, recent techniques, re- search requirements, and challenges,” Arabian Journal for Science and Engineering, vol. 45, no. 8, pp. 6211–6240, 2020

  113. [121]

    A survey on the internet of things (iot) forensics: chal- lenges, approaches, and open issues,

    M. Stoyanova, Y . Nikoloudakis, S. Panagiotakis, E. Pallis, and E. K. Markakis, “A survey on the internet of things (iot) forensics: chal- lenges, approaches, and open issues,” IEEE Communications Surveys & Tutorials, vol. 22, no. 2, pp. 1191–1221, 2020

  114. [122]

    A review of artificial intelligence to enhance the security of big data systems: state-of-art, methodologies, applications, and challenges,

    D. Dai and S. Boroomand, “A review of artificial intelligence to enhance the security of big data systems: state-of-art, methodologies, applications, and challenges,” Archives of Computational Methods in Engineering, vol. 29, no. 2, pp. 1291–1309, 2022

  115. [123]

    Reinforcement learning for feedback-enabled cyber resilience,

    Y . Huang, L. Huang, and Q. Zhu, “Reinforcement learning for feedback-enabled cyber resilience,” Annual Reviews in Control, vol. 53, pp. 273–295, 2022

  116. [124]

    Com- plex event processing for physical and cyber security in datacentres- recent progress, challenges and recommendations,

    K. A. Alaghbari, M. H. M. Saad, A. Hussain, and M. R. Alam, “Com- plex event processing for physical and cyber security in datacentres- recent progress, challenges and recommendations,” Journal of Cloud Computing, vol. 11, no. 1, p. 65, 2022

  117. [125]

    Security and privacy in 5g-iiot smart factories: Novel approaches, trends, and challenges,

    C.-C. Lin, C.-T. Tsai, Y .-L. Liu, T.-T. Chang, and Y .-S. Chang, “Security and privacy in 5g-iiot smart factories: Novel approaches, trends, and challenges,” Mobile Networks and Applications , vol. 28, pp. 1043–1058, 2023

  118. [126]

    Context-aware security for vehicles and fleets: A survey,

    D. Grimm, M. Stang, and E. Sax, “Context-aware security for vehicles and fleets: A survey,” IEEE Access, vol. 9, pp. 101 809–101 846, 2021

  119. [127]

    A systematic literature review on automotive digital forensics: Challenges, technical solutions and data collection,

    K. Strandberg, N. Nowdehi, and T. Olovsson, “A systematic literature review on automotive digital forensics: Challenges, technical solutions and data collection,” IEEE Transactions on Intelligent Vehicles, vol. 8, no. 2, pp. 1350–1367, 2022

  120. [128]

    Anomaly detection in power system state estimation: Review and new directions,

    A. Cooper, A. Bretas, and S. Meyn, “Anomaly detection in power system state estimation: Review and new directions,” Energies, vol. 16, no. 18, p. 6678, 2023

  121. [129]

    A guide to conducting a standalone systematic literature review,

    C. Okoli, “A guide to conducting a standalone systematic literature review,” Communications of the Association for Information Systems , vol. 37, pp. 879–910, 2015

  122. [130]

    Guidelines for snowballing in systematic literature studies and a replication in software engineering,

    C. Wohlin, “Guidelines for snowballing in systematic literature studies and a replication in software engineering,” in Proceedings of the 18th International Conference on Evaluation and Assessment in Software Engineering, London England, UK, 2014, pp. 1–10

  123. [131]

    A hybrid online offline system for network anomaly detection,

    M. Odiathevar, W. K. Seah, and M. Frean, “A hybrid online offline system for network anomaly detection,” in 2019 28th International Conference on Computer Communication and Networks (ICCCN) . Valencia, ES: IEEE, 2019, pp. 1–9

  124. [132]

    Adaptive anomaly de- tection in performance metric streams,

    O. Ibidunmoye, A.-R. Rezaie, and E. Elmroth, “Adaptive anomaly de- tection in performance metric streams,” IEEE Transactions on Network and Service Management , vol. 15, no. 1, pp. 217–231, 2017

  125. [133]

    Multi-agent based attack-resilient system integrity protection for smart grid,

    P. Wang and M. Govindarasu, “Multi-agent based attack-resilient system integrity protection for smart grid,”IEEE Transactions on Smart Grid, vol. 11, no. 4, pp. 3447–3456, 2020

  126. [134]

    Security strategy for autonomous vehicle cyber-physical systems using transfer learning,

    A. A. Alsulami, Q. A. Al-Haija, B. Alturki, A. Alqahtani, and R. Alsini, “Security strategy for autonomous vehicle cyber-physical systems using transfer learning,” Journal of Cloud Computing, vol. 12, no. 1, pp. 181– 199, 2023

  127. [135]

    Taxonomy for description of cross-domain attacks on cps,

    M. Yampolskiy, P. Horvath, X. D. Koutsoukos, Y . Xue, and J. Szti- panovits, “Taxonomy for description of cross-domain attacks on cps,” in Proceedings of the 2nd ACM international conference on High confidence networked systems , Philadelphia, PA, 2013, pp. 135–142

  128. [136]

    A survey on network security for cyber–physical systems: From threats to resilient design,

    S. Kim, K.-J. Park, and C. Lu, “A survey on network security for cyber–physical systems: From threats to resilient design,” IEEE Communications Surveys & Tutorials , vol. 24, no. 3, pp. 1534–1573, 2022

  129. [137]

    Unsupervised real-time anomaly detection for streaming data,

    S. Ahmad, A. Lavin, S. Purdy, and Z. Agha, “Unsupervised real-time anomaly detection for streaming data,” Neurocomputing, vol. 262, pp. 134–147, 2017

  130. [138]

    Deepant: A deep learning approach for unsupervised anomaly detection in time series,

    M. Munir, S. A. Siddiqui, A. Dengel, and S. Ahmed, “Deepant: A deep learning approach for unsupervised anomaly detection in time series,” IEEE Access, vol. 7, pp. 1991–2005, 2018

  131. [139]

    Deep reinforcement learning for anomaly detection: A systematic review,

    K. Arshad, R. F. Ali, A. Muneer, I. A. Aziz, S. Naseer, N. S. Khan, and S. M. Taib, “Deep reinforcement learning for anomaly detection: A systematic review,” IEEE Access, vol. 10, pp. 124 017–124 035, 2022

  132. [140]

    Detection of false data injection attacks in cyber-physical systems using dynamic invariants,

    K. Nakayama, N. Muralidhar, C. Jin, and R. Sharma, “Detection of false data injection attacks in cyber-physical systems using dynamic invariants,” in 2019 18th IEEE International Conference On Machine Learning And Applications (ICMLA) . Boca Raton, FL: IEEE, 2019, pp. 1023–1030

  133. [141]

    Threshold-free physical layer authentication based on ma- chine learning for industrial wireless cps,

    F. Pan, Z. Pang, H. Wen, M. Luvisotto, M. Xiao, R.-F. Liao, and J. Chen, “Threshold-free physical layer authentication based on ma- chine learning for industrial wireless cps,” IEEE Transactions on Industrial Informatics, vol. 15, no. 12, pp. 6481–6491, 2019

  134. [142]

    Context- sensitive modeling and analysis of cyber-physical manufacturing sys- tems for anomaly detection and diagnosis,

    M. A. Saez, F. P. Maturana, K. Barton, and D. M. Tilbury, “Context- sensitive modeling and analysis of cyber-physical manufacturing sys- tems for anomaly detection and diagnosis,” IEEE Transactions on Automation Science and Engineering , vol. 17, no. 1, pp. 29–40, 2019

  135. [143]

    A dynamic games approach to proactive defense strategies against advanced persistent threats in cyber-physical systems,

    L. Huang and Q. Zhu, “A dynamic games approach to proactive defense strategies against advanced persistent threats in cyber-physical systems,” Computers & Security , vol. 89, p. 101660, 2020

  136. [144]

    Dennes: deep embedded neural network expert system for detecting cyber attacks,

    S. Mahdavifar and A. A. Ghorbani, “Dennes: deep embedded neural network expert system for detecting cyber attacks,” Neural Computing and Applications, vol. 32, no. 18, pp. 14 753–14 780, 2020

  137. [145]

    On the performance of grasp-based feature selection for cps intrusion detection,

    S. E. Quincozes, D. Moss ´e, D. Passos, C. Albuquerque, L. S. Ochi, and V . F. dos Santos, “On the performance of grasp-based feature selection for cps intrusion detection,” IEEE Transactions on Network and Service Management, vol. 19, no. 1, pp. 614–626, 2021

  138. [146]

    Root-cause analysis for time-series anomalies via spatiotemporal graphical modeling in distributed complex systems,

    C. Liu, K. G. Lore, Z. Jiang, and S. Sarkar, “Root-cause analysis for time-series anomalies via spatiotemporal graphical modeling in distributed complex systems,” Knowledge-Based Systems, vol. 211, p. 106527, 2021

  139. [147]

    An intelligent cognitive computing based intrusion detection for industrial cyber-physical systems,

    M. M. Althobaiti, K. P. M. Kumar, D. Gupta, S. Kumar, and R. F. Mansour, “An intelligent cognitive computing based intrusion detection for industrial cyber-physical systems,” Measurement, vol. 186, p. 110145, 2021

  140. [148]

    Adaptive anomaly detection system based on machine learning algorithms in an industrial control environment,

    J. V ´avra, M. Hromada, L. Luk´aˇs, and J. Dworzecki, “Adaptive anomaly detection system based on machine learning algorithms in an industrial control environment,” International Journal of Critical Infrastructure Protection, vol. 34, pp. 1–11, 2021

  141. [149]

    Artificial intelligence enabled intrusion detection systems for cognitive cyber-physical systems in industry 4.0 environment,

    M. A. Alohali, F. N. Al-Wesabi, A. M. Hilal, S. Goel, D. Gupta, and A. Khanna, “Artificial intelligence enabled intrusion detection systems for cognitive cyber-physical systems in industry 4.0 environment,” Cognitive Neurodynamics, vol. 16, no. 5, pp. 1045–1057, 2022

  142. [150]

    Novel hybrid model for intrusion prediction on cyber physical sys- tems’ communication networks based on bio-inspired deep neural network structure,

    A. E. Ibor, O. B. Okunoye, F. A. Oladeji, and K. A. Abdulsalam, “Novel hybrid model for intrusion prediction on cyber physical sys- tems’ communication networks based on bio-inspired deep neural network structure,” Journal of Information Security and Applications , vol. 65, p....

  143. [151]

    Intrusion detection for maritime transportation systems with batch federated aggregation,

    W. Liu, X. Xu, L. Wu, L. Qi, A. Jolfaei, W. Ding, and M. R. Khosravi, “Intrusion detection for maritime transportation systems with batch federated aggregation,” IEEE Transactions on Intelligent Transportation Systems, vol. 24, no. 2, pp. 2503–2514, 2022

  144. [152]

    Asset crit- icality and risk prediction for an effective cybersecurity risk manage- ment of cyber-physical system,

    H. I. Kure, S. Islam, M. Ghazanfar, A. Raza, and M. Pasha, “Asset crit- icality and risk prediction for an effective cybersecurity risk manage- ment of cyber-physical system,” Neural Computing and Applications , vol. 34, no. 1, pp. 493–514, 2022

  145. [153]

    An lstm- autoencoder based online side channel monitoring approach for cyber- physical attack detection in additive manufacturing,

    Z. Shi, A. A. Mamun, C. Kan, W. Tian, and C. Liu, “An lstm- autoencoder based online side channel monitoring approach for cyber- physical attack detection in additive manufacturing,” Journal of Intel- ligent Manufacturing, vol. 34, pp. 1815–1831, 2023

  146. [154]

    Design of capability maturity model integration with cybersecurity risk severity complex prediction using bayesian- based machine learning models,

    F. H. Alshammari, “Design of capability maturity model integration with cybersecurity risk severity complex prediction using bayesian- based machine learning models,” Service Oriented Computing and Applications, vol. 17, no. 1, pp. 59–72, 2023

  147. [155]

    Real-time cyber-physical security solution leveraging an integrated learning-based approach: An integrated learning-based cyber-physical security solution,

    D. Wang, F. Li, K. Liu, and X. Zhang, “Real-time cyber-physical security solution leveraging an integrated learning-based approach: An integrated learning-based cyber-physical security solution,” ACM Transactions on Sensor Networks , vol. 20, no. 2, pp. 1–22, 2023

  148. [156]

    On survivability of mobile cyber physical systems with intrusion detection,

    R. Mitchell and I.-R. Chen, “On survivability of mobile cyber physical systems with intrusion detection,” Wireless personal communications , vol. 68, pp. 1377–1391, 2013

  149. [157]

    Performance evaluation of unsupervised techniques in cyber-attack anomaly detection,

    J. Meira, R. Andrade, I. Prac ¸a, J. Carneiro, V . Bol ´on-Canedo, A. Alonso-Betanzos, and G. Marreiros, “Performance evaluation of unsupervised techniques in cyber-attack anomaly detection,” Journal of Ambient Intelligence and Humanized Computing , vol. 11, no. 11, pp. 4477–4...

  150. [158]

    Adaptive- correlation-aware unsupervised deep learning for anomaly detection in cyber-physical systems,

    L. Xi, D. Miao, M. Li, R. Wang, H. Liu, and X. Huang, “Adaptive- correlation-aware unsupervised deep learning for anomaly detection in cyber-physical systems,” IEEE Transactions on Dependable and Secure Computing, 2023. 29

  151. [159]

    Safety pilot model deployment: Test con- ductor team report,

    D. Bezzina and J. Sayer, “Safety pilot model deployment: Test con- ductor team report,” Report No. DOT HS , vol. 812, no. 171, p. 18, 2014

  152. [160]

    Effi- cient drone hijacking detection using two-step ga-xgboost,

    Z. Feng, N. Guan, M. Lv, W. Liu, Q. Deng, X. Liu, and W. Yi, “Effi- cient drone hijacking detection using two-step ga-xgboost,” Journal of Systems Architecture, vol. 103, p. 101694, 2020

  153. [161]

    Source authenti- cation of distribution synchrophasors for cybersecurity of microgrids,

    Y . Cui, F. Bai, R. Yan, T. Saha, R. K. Ko, and Y . Liu, “Source authenti- cation of distribution synchrophasors for cybersecurity of microgrids,” IEEE Transactions on Smart Grid, vol. 12, no. 5, pp. 4577–4580, 2021

  154. [162]

    A privacy-conserving framework based intrusion detection method for detecting and recognizing malicious behaviours in cyber- physical power networks,

    I. A. Khan, D. Pi, N. Khan, Z. U. Khan, Y . Hussain, A. Nawaz, and F. Ali, “A privacy-conserving framework based intrusion detection method for detecting and recognizing malicious behaviours in cyber- physical power networks,” Applied Intelligence , vol. 51, pp. 7306– 7321, 2021

  155. [163]

    Industrial control system (ics) cyber attack datasets,

    T. Morris, “Industrial control system (ics) cyber attack datasets,” https: //sites.google.com/a/uah.edu/tommy-morris-uah/ics-data-sets, 2013

  156. [164]

    Unsw-nb15: a comprehensive data set for network intrusion detection systems (unsw-nb15 network data set),

    N. Moustafa and J. Slay, “Unsw-nb15: a comprehensive data set for network intrusion detection systems (unsw-nb15 network data set),” in 2015 military communications and information systems conference (MilCIS). Canberra, AU: IEEE, 2015, pp. 1–6

  157. [165]

    An adaptive robust regres- sion method: Application to galaxy spectrum baseline estimation,

    R. Bacher, F. Chatelain, and O. Michel, “An adaptive robust regres- sion method: Application to galaxy spectrum baseline estimation,” in 2016 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP). IEEE, 2016, pp. 4423–4427

  158. [166]

    Global energy forecasting competition 2012,

    T. Hong, P. Pinson, and S. Fan, “Global energy forecasting competition 2012,” International Journal of Forecasting , vol. 30, no. 2, pp. 357– 363, 2014

  159. [167]

    Robust estimation of a location parameter,

    P. J. Huber, “Robust estimation of a location parameter,” in Break- throughs in statistics: Methodology and distribution . Springer, 1992, pp. 492–518

  160. [168]

    Efficient estimation of word representations in vector space,

    T. Mikolov, K. Chen, G. Corrado, and J. Dean, “Efficient estimation of word representations in vector space,” arXiv preprint arXiv:1301.3781, 2013

  161. [169]

    System statistics learning-based iot security: Feasibility and suitability,

    F. Li, A. Shinde, Y . Shi, J. Ye, X.-Y . Li, and W. Song, “System statistics learning-based iot security: Feasibility and suitability,” IEEE Internet of Things Journal , vol. 6, no. 4, pp. 6396–6403, 2019

  162. [170]

    Deep learning enabled data of- floading with cyber attack detection model in mobile edge computing systems,

    T. Gopalakrishnan, D. Ruby, F. Al-Turjman, D. Gupta, I. V . Pustokhina, D. A. Pustokhin, and K. Shankar, “Deep learning enabled data of- floading with cyber attack detection model in mobile edge computing systems,” IEEE Access, vol. 8, pp. 185 938–185 949, 2020

  163. [171]

    Deep ai-powered cyber threat analysis in iiot,

    I. Bibi, A. Akhunzada, and N. Kumar, “Deep ai-powered cyber threat analysis in iiot,” IEEE Internet of Things Journal , vol. 10, no. 9, pp. 7749–7760, 2022

  164. [172]

    Secure intelligent fuzzy blockchain framework: Ef- fective threat detection in iot networks,

    A. Yazdinejad, A. Dehghantanha, R. M. Parizi, G. Srivastava, and H. Karimipour, “Secure intelligent fuzzy blockchain framework: Ef- fective threat detection in iot networks,” Computers in Industry , vol. 144, p. 103801, 2023

  165. [173]

    Data mining-based ethereum fraud detection,

    E. Jung, M. Le Tilly, A. Gehani, and Y . Ge, “Data mining-based ethereum fraud detection,” in 2019 IEEE International Conference on Blockchain (Blockchain). Atlanta, GA: IEEE, 2019, pp. 266–273

  166. [174]

    A labeled transactions-based dataset on the ethereum network,

    S. Al-E’mari, M. Anbar, Y . Sanjalawe, and S. Manickam, “A labeled transactions-based dataset on the ethereum network,” in International Conference on Advances in Cyber Security . Penang, Malaysia: Springer, 2020, pp. 61–79

  167. [175]

    A review on kdd cup9 and nsl-kdd dataset

    R. Bala and R. Nagpal, “A review on kdd cup9 and nsl-kdd dataset.” International Journal of Advanced Research in Computer Science , vol. 10, no. 2, 2019

  168. [176]

    Hybrid meta-heuristic based feature selection mechanism for cyber-attack detection in iot-enabled networks,

    A. K. Dey, G. P. Gupta, and S. P. Sahu, “Hybrid meta-heuristic based feature selection mechanism for cyber-attack detection in iot-enabled networks,” Procedia Computer Science , vol. 218, pp. 318–327, 2023

  169. [177]

    Ton iot: The role of heterogeneity and the need for standardization of features and attack types in iot network intrusion data sets,

    T. M. Booij, I. Chiscop, E. Meeuwissen, N. Moustafa, and F. T. Den Hartog, “Ton iot: The role of heterogeneity and the need for standardization of features and attack types in iot network intrusion data sets,” IEEE Internet of Things Journal , vol. 9, no. 1, pp. 485–496, 2021

  170. [178]

    An ensemble deep learning model for cyber threat hunting in industrial internet of things,

    A. Yazdinejad, M. Kazemi, R. M. Parizi, A. Dehghantanha, and H. Karimipour, “An ensemble deep learning model for cyber threat hunting in industrial internet of things,” Digital Communications and Networks, vol. 9, no. 1, pp. 101–110, 2023

  171. [179]

    Deep-learning based detection for cyber-attacks in iot net- works: A distributed attack detection framework,

    O. Jullian, B. Otero, E. Rodriguez, N. Gutierrez, H. Antona, and R. Canal, “Deep-learning based detection for cyber-attacks in iot net- works: A distributed attack detection framework,” Journal of Network and Systems Management , vol. 31, no. 2, p. 33, 2023

  172. [180]

    Apae: an iot intrusion detection sys- tem using asymmetric parallel auto-encoder,

    A. Basati and M. M. Faghih, “Apae: an iot intrusion detection sys- tem using asymmetric parallel auto-encoder,” Neural Computing and Applications, vol. 35, no. 7, pp. 4813–4833, 2023

  173. [181]

    Multi-scale context aggregation by dilated convolutions,

    F. Yu and V . Koltun, “Multi-scale context aggregation by dilated convolutions,” arXiv preprint arXiv:1511.07122 , 2015

  174. [182]

    Attention is all you need,

    A. Vaswani, N. Shazeer, N. Parmar, J. Uszkoreit, L. Jones, A. N. Gomez, Ł. Kaiser, and I. Polosukhin, “Attention is all you need,” Advances in neural information processing systems , vol. 30, pp. 1–11, 2017

  175. [183]

    Integration of digital twin and federated learning for securing vehicular internet of things,

    D. Gupta, S. S. Moni, and A. S. Tosun, “Integration of digital twin and federated learning for securing vehicular internet of things,” in Proceedings of the 2023 International Conference on Research in Adaptive and Convergent Systems , Gdansk, Poland, 2023, pp. 1–8

  176. [184]

    Anomaly detection models for iot time series data,

    F. Giannoni, M. Mancini, and F. Marinelli, “Anomaly detection models for iot time series data,” arXiv preprint arXiv:1812.00890 , 2018

  177. [185]

    Few-shot iot attack detection based on rfp-cnn and adversarial unsupervised domain- adaptive regularization,

    K. Li, W. Ma, H. Duan, H. Xie, and Z. Juanxiu, “Few-shot iot attack detection based on rfp-cnn and adversarial unsupervised domain- adaptive regularization,” Computers & Security , vol. 121, p. 102856, 2022

  178. [186]

    Behavioral mod- eling intrusion detection system (bmids) using internet of things (iot) behavior-based anomaly detection via immunity-inspired algorithms,

    B. Arrington, L. Barnett, R. Rufus, and A. Esterline, “Behavioral mod- eling intrusion detection system (bmids) using internet of things (iot) behavior-based anomaly detection via immunity-inspired algorithms,” in 2016 25th International Conference on Computer Communication an...

  179. [187]

    Extremely randomized trees-based scheme for stealthy cyber-attack detection in smart grid networks,

    M. R. C. Acosta, S. Ahmed, C. E. Garcia, and I. Koo, “Extremely randomized trees-based scheme for stealthy cyber-attack detection in smart grid networks,” IEEE Access, vol. 8, pp. 19 921–19 933, 2020

  180. [188]

    Divergence-based transferability analysis for self-adaptive smart grid intrusion detection with transfer learning,

    P. Liao, J. Yan, J. M. Sellier, and Y . Zhang, “Divergence-based transferability analysis for self-adaptive smart grid intrusion detection with transfer learning,” IEEE Access, vol. 10, pp. 68 807–68 818, 2022

  181. [189]

    The 2017 iso new england system operational analysis and renewable energy integration study (soares),

    A. Muzhikyan, S. O. Muhanji, G. D. Moynihan, D. J. Thompson, Z. M. Berzolla, and A. M. Farid, “The 2017 iso new england system operational analysis and renewable energy integration study (soares),” Energy Reports, vol. 5, pp. 747–792, 2019

  182. [190]

    Reinforcement learning-based adaptive feature boosting for smart grid intrusion detection,

    C. Hu, J. Yan, and X. Liu, “Reinforcement learning-based adaptive feature boosting for smart grid intrusion detection,” IEEE Transactions on Smart Grid , vol. 14, no. 4, pp. 3150–3163, 2022

  183. [191]

    Trustworthy anomaly detection: A survey,

    S. Yuan and X. Wu, “Trustworthy anomaly detection: A survey,” arXiv preprint arXiv:2202.07787, 2022

  184. [192]

    Deep reinforcement learning for cyber security,

    T. T. Nguyen and V . J. Reddi, “Deep reinforcement learning for cyber security,” IEEE Transactions on Neural Networks and Learning Systems, vol. 34, no. 8, pp. 3779–3795, 2021

  185. [193]

    The advantages of the matthews correlation coefficient (mcc) over f1 score and accuracy in binary classification evaluation,

    D. Chicco and G. Jurman, “The advantages of the matthews correlation coefficient (mcc) over f1 score and accuracy in binary classification evaluation,” BMC genomics, vol. 21, pp. 1–13, 2020

  186. [194]

    A survey on transfer learning,

    S. J. Pan and Q. Yang, “A survey on transfer learning,” IEEE Transac- tions on Knowledge and Data Engineering , vol. 22, no. 10, pp. 1345– 1359, 2009

  187. [195]

    Matching networks for one shot learning,

    O. Vinyals, C. Blundell, T. Lillicrap, D. Wierstra et al. , “Matching networks for one shot learning,” in 30th Conference on Neural Infor- mation Processing Systems (NIPS 2016), vol. 29, Barcelona, ES, 2016, pp. 1–9

  188. [196]

    Zero-shot learning-the good, the bad and the ugly,

    Y . Xian, B. Schiele, and Z. Akata, “Zero-shot learning-the good, the bad and the ugly,” in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition , San Francisco, CA, 2017, pp. 4582– 4591

  189. [197]

    A survey on adversarial attacks and defences,

    A. Chakraborty, M. Alam, V . Dey, A. Chattopadhyay, and D. Mukhopadhyay, “A survey on adversarial attacks and defences,” CAAI Transactions on Intelligence Technology , vol. 6, no. 1, pp. 25– 45, 2021

  190. [198]

    Adversarial attacks in intrusion detection systems: Triggering false alarms in connected and autonomous vehi- cles,

    F. Aloraini and A. Javed, “Adversarial attacks in intrusion detection systems: Triggering false alarms in connected and autonomous vehi- cles,” in 2024 IEEE International Conference on Cyber Security and Resilience (CSR). IEEE, 2024, pp. 714–719

  191. [199]

    Adversarial robustness in unsupervised ma- chine learning: A systematic review,

    M. L. Mohus and J. Li, “Adversarial robustness in unsupervised ma- chine learning: A systematic review,”arXiv preprint arXiv:2306.00687, 2023

  192. [200]

    Robustness of autoen- coders for anomaly detection under adversarial impact,

    A. Goodge, B. Hooi, S. K. Ng, and W. S. Ng, “Robustness of autoen- coders for anomaly detection under adversarial impact,” in Proceedings of the twenty-ninth international conference on international joint conferences on artificial intelligence , 2021, pp. 1244–1250

  193. [201]

    Adversarially robust one-class nov- elty detection,

    S.-Y . Lo, P. Oza, and V . M. Patel, “Adversarially robust one-class nov- elty detection,” IEEE Transactions on Pattern Analysis and Machine Intelligence, vol. 45, no. 4, pp. 4167–4179, 2022

  194. [202]

    Stakeholders in explainable ai,

    A. Preece, D. Harborne, D. Braines, R. Tomsett, and S. Chakraborty, “Stakeholders in explainable ai,” arXiv preprint arXiv:1810.00184 , 2018

  195. [203]

    A survey on explainable anomaly detection,

    Z. Li, Y . Zhu, and M. Van Leeuwen, “A survey on explainable anomaly detection,” ACM Transactions on Knowledge Discovery from Data , vol. 18, no. 1, pp. 1–54, 2023. 30 Pablo Moriano (Senior Member, IEEE) received B.S. and M.S. degrees in electrical engineering from Pontificia ...

Pith tools

Reviewed August 12, 2026 · model on record in the stance chip above.