arXiv Machine Learning

Self-Verifying Anomaly Detection using Explainable AI for Cybersecurity of DER Networks

The paper introduces ExCYDER, an explainable AI framework for anomaly detection in Distributed Energy Resource (DER) networks. It combines LightGBM with SHAP to self-verify alerts, ensuring that each detection aligns with feature‑attribution evidence. Experiments on a realistic DNP3 dataset show over 98% detection accuracy, 44.6% rule‑SHAP consistency, 14.5 ms SHAP latency per alert, and minimal confidence deviation, while distinguishing coherent from inconsistent alerts without sacrificing accuracy.

arXiv AI
Jun 6

Explainable AI-Driven Cyber Risk Analytics and Model Reliability Assessment for Intelligent Governance of U.S. Critical Infrastructure: An XGBoost and SHAP-Based Intrusion Detection Framework

arXiv:2606. 05710v1 Announce Type: cross Abstract: The increasing penetrations of the critical infrastructure sector in the United States with intelligent digital technologies have greatly increased exposure to advanced cyber adversaries and operational vulnerabilities.

By B. M. Taslimul Haque, Md. Arifur Rahman, Md. Serajul Kabir Chowdhury Rubel, Md. Iqbal Hossan
arXiv AI
Jun 6

Cognitive Threat Intelligence and Explainable Federated Security Analytics for distributed Infrastructure Systems

arXiv:2606. 05701v1 Announce Type: cross Abstract: The increasing adoption of distributed infrastructure systems, cloud computing, Internet of Things (IoT) technologies, and edge-based architectures has significantly expanded the cybersecurity attack surface and introduced increasingly sophisticated cyber threats.

By Md. Arifur Rahman, B. M. Taslimul Haque, Md. Iqbal Hossan, Md. Serajul Kabir Chowdhury Rubel
arXiv AI
Jul 9

Large Language Models (LLMs) and Generative AI in Cybersecurity and Privacy: A Survey of Dual-Use Risks, AI-Generated Malware, Explainability, and Defensive Strategies

arXiv:2607. 06963v1 Announce Type: cross Abstract: Large Language Models (LLMs) and generative AI (GenAI) systems, such as ChatGPT, Claude, Gemini, LLaMA, Copilot, Stable Diffusion by OpenAI, Anthropic, Google, Meta, Microsoft, Stability AI, respectively, are revolutionizing cybersecurity, enabling both automated defense and sophisticated attacks.

By Kiarash Ahi, Saeed Valizadeh
Hugging Face Trending Papers
Jul 8

Large Language Models (LLMs) and Generative AI in Cybersecurity and Privacy: A Survey of Dual-Use Risks, AI-Generated Malware, Explainability, and Defensive Strategies

Large Language Models (LLMs) and generative AI (GenAI) systems, such as ChatGPT, Claude, Gemini, LLaMA, Copilot, Stable Diffusion by OpenAI, Anthropic, Google, Meta, Microsoft, Stability AI, respectively, are revolutionizing cybersecurity, enabling both automated defense and sophisticated attacks. These technologies power real-time threat detection, phishing defense, secure code generation, and vulnerability exploitation at unprecedented scales.

Hugging Face Trending Papers
Jul 2

Beyond Gradient-Based Attacks: Adversarial Robustness and Explainability Stability in Cybersecurity Classifiers

Adversarial attacks on cybersecurity classifiers pose a dual threat: degrading predictions and destabilising the SHAP-based explanations that security analysts rely on to understand and triage alerts. We extend our prior MLP conference study to Random Forest and XGBoost across four tabular security datasets (phishing URLs, UNSW-NB15, NF-ToN-IoT, HIKARI-2021), evaluating five attacks including three black-box methods applicable to non-differentiable tree models.

arXiv AI
Sep 10

Towards a Resilience-Theoretic Foundation for Adversarial Robustness in Industrial Control System Anomaly Detection

The paper argues that adversarial robustness of anomaly detectors in industrial control systems (ICS) is a specific form of system resilience. It maps resilience concepts—disturbance class, absorption capacity, recovery trajectory, and degradation function—to adversarial machine learning, deriving a compositional resilience bound that identifies the coupling‑adjusted absorption capacity of nodes along an attack path as the key constraint. Empirical tests on the BATADAL water distribution benchmark reveal operationally significant effects, such as absorption‑degradation divergence under adversarial training and a paradox where hardening the most vulnerable node alone can reduce overall resilience.

By Branka Stojanovi\'c, Andreas Flatscher, Michael Somma
arXiv AI
Jun 3

FlowGuard: Flow Matching for Identity-Independent Detection of Data-Free Model Stealing Attacks on Energy System Intrusion Detection Systems

arXiv:2606. 03430v1 Announce Type: cross Abstract: Artificial Intelligence (AI)-based Intrusion Detection Systems (IDS) deployed in energy infrastructure are vulnerable to model theft attacks, which allow adversaries to create evasive traffic offline.

By Maxime Schwarzer, Laurin Holz, Tobias Huerten, Johannes Loevenich, Thies Moehlenhof, Roberto Rigolin F. Lopes, Veit Hagenmeyer