arXiv Machine Learning

Conformal Prediction for Offensive Security

The paper examines the underexplored use of Conformal Prediction (CP) in offensive security, noting that while CP has been applied defensively, its role in attacks is rarely documented. The authors present preliminary results in two offensive domains: Privacy‑Preserving Machine Learning and network traffic analysis. They aim to bridge the gap between CP’s defensive successes and its potential for facilitating attacks.

arXiv AI
Sep 18

Robust Conformal Intrusion Detection via Traffic-Aware Calibration and Attack-Orbit Invariance

The paper addresses the lack of statistical validity in language‑model‑based network intrusion detection. It introduces traffic‑aware conformal prediction, which calibrates on attacker‑expected traffic to restore coverage guarantees, and further mitigates adaptive attacks by removing attacker‑controllable features, achieving exact pathwise coverage. Experiments on three benchmarks show that this approach maintains coverage while incurring a modest accuracy cost.

By Zhenpeng Li
arXiv Machine Learning
Jun 29

CO-DEFEND: Continuous Decentralized Federated Learning for Secure DoH-Based Threat Detection

arXiv:2504. 01882v2 Announce Type: replace Abstract: The use of DNS over HTTPS (DoH) tunneling by an attacker to hide malicious activity within encrypted DNS traffic poses a serious threat to network security, as it allows malicious actors to bypass traditional monitoring and intrusion detection systems while evading detection by conventional traffic analysis techniques.

By Diego Cajaraville-Aboy, Marta Moure-Garrido, Carlos Beis-Penedo, Carlos Garcia-Rubio, Rebeca P. D\'iaz-Redondo, Celeste Campo, Ana Fern\'andez-Vilas, Manuel Fern\'andez-Veiga
arXiv AI
3d ago

AI Security Research Should Better Incentivize Defense Research

The article discusses a notable imbalance in AI security research, where studies on attacking AI systems outnumber those on defending them. It highlights that this skew is evident across various subfields such as federated learning, speech recognition, membership inference, and large language models. The authors argue that attack papers often benefit from favorable evaluation conditions, whereas defense papers face stricter standards, resulting in a literature rich in vulnerabilities but lacking robust, deployable protections.

By Youqian Zhang
arXiv Machine Learning
Sep 14

Correlation-Guided Fast Machine Unlearning via Hessian Analysis

The paper presents a fast machine unlearning method that uses Hessian analysis to identify correlated training data and applies a closed‑form update rule. This approach achieves an 82× speedup over traditional influence‑function unlearning while maintaining or slightly improving model accuracy. Experiments on seven dataset‑architecture pairs, including CIFAR‑100 with ResNet‑50, show strong forgetting performance and low vulnerability to membership inference attacks.

By Ayushi Thakur, Ruchir Gupta, Amit Kumar Jaiswal, Prayag Tiwari
arXiv Machine Learning
2d ago

ModSec-Learn: Boosting ModSecurity with Machine Learning

arXiv:2406.13547v2 Announce Type: replace Abstract: ModSecurity is widely recognized as the standard open-source Web Application Firewall (WAF), maintained by the OWASP Foundation. It detects malicio...

By Christian Scano, Giuseppe Floris, Biagio Montaruli, Luca Demetrio, Andrea Valenza, Luca Compagna, Davide Ariu, Luca Piras, Davide Balzarotti, Battista Biggio
arXiv AI
Jun 3

AI Model Extraction Attacks: Bypassing Single-Client Assumptions in Defenses

arXiv:2606. 03381v1 Announce Type: cross Abstract: Ensuring the protection of Artificial Intelligence (AI) models deployed in military Command and Control (C2) systems and critical infrastructure is essential for maintaining information superiority.

By Maxime Schwarzer, Johannes F. Loevenich, Gustavo S\'anchez, Laurin Holz, Thies M\"ohlenhof, Tobias H\"urten, Roberto Rigolin F. Lopes, Veit Hagenmeyer
arXiv Computer Vision
Sep 21

Privacy Leakage on DNNs: A Survey of Model Inversion Attacks and Defenses

The paper "Privacy Leakage on DNNs: A Survey of Model Inversion Attacks and Defenses" provides a comprehensive review of model inversion (MI) attacks that exploit trained deep neural networks to reconstruct private training data. It traces the evolution of MI from early machine‑learning contexts to recent DNN‑based attacks across various modalities and learning tasks, offering a detailed taxonomy and comparative analysis of both attacks and defenses. The authors also present an open‑source toolbox on GitHub to support further research in this area.

By Hao Fang, Yixiang Qiu, Hongyao Yu, Wenbo Yu, Jiawei Kong, Baoli Chong, Bin Chen, Xuan Wang, Shu-Tao Xia, Ke Xu
arXiv AI
Aug 19

Future-Back Threat Modeling: A Foresight-Driven Security Framework

Future-Back Threat Modeling (FBTM) is a predictive security framework that starts with envisioned future threat states and works backward to uncover assumptions, gaps, blind spots, and vulnerabilities in current defense architectures. It aims to reveal both known unknowns and unknown unknowns, including emerging tactics, techniques, and procedures, thereby improving the predictability of adversary behavior under future uncertainty. By anticipating future threats such as AI, information warfare, and supply chain attacks, FBTM helps security leaders make informed decisions today to build more resilient security postures for the future.

By Vu Van Than