The paper investigates whether machine learning models for IoT intrusion detection truly learn attack patterns or rely on dataset shortcuts. Using the CyberFlowIoT-GICAP benchmark, the authors evaluate four learning paradigms across different feature sets and split strategies, finding that performance is largely driven by feature representation and that tree-based models can exploit temporal artifacts. The study also highlights asymmetric attack detectability and proposes a four-point protocol checklist for realistic evaluation.
By Uday Shankar Roy, Mahbuba Jahan Minu
arXiv:2605.02346v2 Announce Type: replace-cross
Abstract: Operational technology (OT) devices run safety-critical physical processes, yet their security testing remains manual and expert-intensive. A...
By Adel ElZemity, Budi Arief, Shujun Li, George Oikonomou, James Pope
arXiv:2608. 11802v1 Announce Type: cross Abstract: Methods to increase the resilience of systems to cyber-attacks become increasingly important.
By Martin Sachenbacher, Martin Leucker, Alexander Weiss, Aliyu Tanko Ali
arXiv:2608. 05548v1 Announce Type: cross Abstract: Modern vehicles rely on the Controller Area Network (CAN) bus, whose design prioritizes low cost and real-time performance but provides no message authentication or encryption.
By Chandan Hegde, Mukundh R Reddy
arXiv:2606. 14987v1 Announce Type: cross Abstract: Internet of Things (IoT) and Cyber-physical systems (CPS) increasingly rely on continual learning (CL) to adapt to evolving environments, device heterogeneity, and concept drift, thereby improving overall utility.
By Oxana Salish, Kuniyilh S
arXiv:2606. 18599v1 Announce Type: cross Abstract: The Controller Area Network (CAN) protocol is the primary communication standard for Electronic Control Units (ECUs) in modern vehicles, but its lack of encryption and authentication exposes it to a range of security threats.
By Qiqi Liu, Runhan Song, Lei Cui, Heng Zhang, Yuyan Sun, Limin Sun
arXiv:2512. 23849v2 Announce Type: replace-cross Abstract: Sophisticated attackers can evade detection-based security by using encryption, stealth tactics, and low-rate attack patterns.
By Samaresh Kumar Singh, Joyjit Roy, Sriharsha Anand Pushkala
arXiv:2606. 06261v1 Announce Type: cross Abstract: O-RAN enables a disaggregated baseband stack with programmable functions that communicate over standardized open interfaces.
By Francesco Spinelli, Esteban Municio, Pau Baguer, Gines Garcia-Aviles, Xavier Costa-Perez
arXiv:2606. 08173v1 Announce Type: cross Abstract: In sixth-generation (6G) networks, billions of cyber-physical systems (CPSs) - autonomous vehicles, smart grids, industrial robots, and remote-surgical equipment - will run over ultra-reliable low-latency slices, collapsing the gap between a remote breach and physical harm to milliseconds, a budget perimeter firewalls and centralised security operations centres cannot meet.
By Bilal Hussain, Muhammad Bilal, Tan Li, Haris Pervaiz, Xiao Tang, Qinghe Du, Fawad Ahmad, Muhammad Azhar, Jun Zhang
arXiv:2607. 10490v1 Announce Type: cross Abstract: Tool-using large language model (LLM) agents are attractive for network operations, but tickets, alerts, logs, runbooks, and ChatOps messages can carry indirect prompt injections.
By Ruksat Khan Shayoni, Muhammad Faraz Shoaib, S M Asif Hossain, M. F. Mridha
arXiv:2606. 30479v1 Announce Type: cross Abstract: Mitigating an observed adversary in an enterprise network typically takes weeks of expert work: an analyst derives a mitigation tailored to that adversary, validates it without breaking production, and verifies it disrupts the specific attack.
By Chen Frydman, Aviram Zilberman, Rubin Krief, Abed Showgan, Andres Murillo, Sekiya Motoyoshi, Asaf Shabtai, Yuval Elovici, Rami Puzis
The paper introduces ExCYDER, an explainable AI framework for anomaly detection in Distributed Energy Resource (DER) networks. It combines LightGBM with SHAP to self-verify alerts, ensuring that each detection aligns with feature‑attribution evidence. Experiments on a realistic DNP3 dataset show over 98% detection accuracy, 44.6% rule‑SHAP consistency, 14.5 ms SHAP latency per alert, and minimal confidence deviation, while distinguishing coherent from inconsistent alerts without sacrificing accuracy.
By Damilola Popoola, Souradeep Bhattacharya, Manimaran Govindarasu