arXiv AI

Robust Conformal Intrusion Detection via Traffic-Aware Calibration and Attack-Orbit Invariance

The paper addresses the lack of statistical validity in language‑model‑based network intrusion detection. It introduces traffic‑aware conformal prediction, which calibrates on attacker‑expected traffic to restore coverage guarantees, and further mitigates adaptive attacks by removing attacker‑controllable features, achieving exact pathwise coverage. Experiments on three benchmarks show that this approach maintains coverage while incurring a modest accuracy cost.

arXiv Machine Learning
5d ago

Probabilistic Robustness-driven Universal Adversarial Perturbations with Explainability against Deep Reinforcement Learning-based Intrusion Detection System

The paper introduces a new method for generating universal adversarial perturbations (UAPs) against deep reinforcement learning (DRL)-based intrusion detection systems (IDS). It leverages Probabilistic Robustness (PR) as a post‑hoc metric to guide UAP creation, integrating PR directly into the optimization objective. The authors further develop PX‑UAP, which incorporates explainable AI (XAI) to shape perturbations within realistic domain constraints, and provide a theoretical analysis of its design. Experiments show PX‑UAP outperforms existing UAP techniques in attack effectiveness.

By Hongsen Zhang, Lu Zhang, Mingjing Xu, Yi Zhang, Gregory Epiphaniou, Carsten Maple
arXiv Machine Learning
Sep 7

Conformal Prediction for Offensive Security

The paper examines the underexplored use of Conformal Prediction (CP) in offensive security, noting that while CP has been applied defensively, its role in attacks is rarely documented. The authors present preliminary results in two offensive domains: Privacy‑Preserving Machine Learning and network traffic analysis. They aim to bridge the gap between CP’s defensive successes and its potential for facilitating attacks.

By Giovanni Cherubin
arXiv Machine Learning
Aug 7

Enhancing Anomaly Resilience in Research Networks: A Large-Scale Forecasting Benchmark for Dynamic Security Baselining

arXiv:2608. 05605v1 Announce Type: cross Abstract: Research and Education Networks (RENs) serve as critical infrastructure for scientific discovery, yet they face a unique security paradox: their normal traffic patterns which are characterized by massive, bursty "elephant flows" are statistically indistinguishable from volumetric attacks such as DDoS to conventional monitoring systems.

By Mohammad Arafath Uddin Shariff, Byrav Ramamurthy
arXiv AI
Jun 9

SHIELD-IDS: Structurally Heterogeneous Ensemble with Integrated Layered Defense for Intrusion Detection Systems

arXiv:2606. 07716v1 Announce Type: cross Abstract: Adversarial attacks pose a serious and growing threat to Machine Learning (ML)-based Intrusion Detection Systems (IDS), where imperceptible perturbations to network flow features can systematically mislead classifiers into accepting malicious traffic as benign.

By Maryam Zaman, Muhammad Khuram Shahzad
arXiv AI
Jun 3

AI Model Extraction Attacks: Bypassing Single-Client Assumptions in Defenses

arXiv:2606. 03381v1 Announce Type: cross Abstract: Ensuring the protection of Artificial Intelligence (AI) models deployed in military Command and Control (C2) systems and critical infrastructure is essential for maintaining information superiority.

By Maxime Schwarzer, Johannes F. Loevenich, Gustavo S\'anchez, Laurin Holz, Thies M\"ohlenhof, Tobias H\"urten, Roberto Rigolin F. Lopes, Veit Hagenmeyer
arXiv Machine Learning
Aug 27

Adversarial Training of Linear Models under Stealthy Attacks

The paper introduces a detector‑based switched model to defend linear predictive models against stealthy false data injection attacks. It derives a convex formulation of the adversarial risk that incorporates protected features and a hyperparameter for attack probability, allowing an explicit trade‑off between clean and attacked data performance. Numerical experiments on real and synthetic datasets demonstrate improved performance on partially attacked data, even when the attack probability is misspecified.

By Lovisa Eriksson, Dave Zachariah, Andr\'e M. H. Teixeira