The paper argues that adversarial robustness of anomaly detectors in industrial control systems (ICS) is a specific form of system resilience. It maps resilience concepts—disturbance class, absorption capacity, recovery trajectory, and degradation function—to adversarial machine learning, deriving a compositional resilience bound that identifies the coupling‑adjusted absorption capacity of nodes along an attack path as the key constraint. Empirical tests on the BATADAL water distribution benchmark reveal operationally significant effects, such as absorption‑degradation divergence under adversarial training and a paradox where hardening the most vulnerable node alone can reduce overall resilience.
By Branka Stojanovi\'c, Andreas Flatscher, Michael Somma
arXiv:2608. 12444v1 Announce Type: cross Abstract: An unconditional risk bound on automated decisions can be satisfied without automating anything, since a selector that never acts drives the bound to zero.
By Zhenpeng Li
arXiv:2606. 20502v1 Announce Type: cross Abstract: Whether LLMs scoring well on vulnerability benchmarks genuinely reason about security or merely pattern-match on contaminated data remains unresolved.
By Arastoo Zibaeirad, Marco Vieira
The paper investigates how to properly validate candidate models before promoting them to replace incumbent classifiers in adaptive network intrusion detection systems. It demonstrates that promotion decisions can be biased by how challengers are constructed and the amount of evidence they receive, and that using self‑contained challenger pipelines and sufficient candidate evidence reduces apparent promotion harm. The study also shows that policy rankings shift with candidate comparability and that no single update policy dominates across benchmarks.
By Roberto Fern\'andez-Barrios, Iker Pastor-L\'opez, Amaia Pikatza-Huerga, Pablo Garc\'ia Bringas
arXiv:2607. 13801v1 Announce Type: cross Abstract: Large language model (LLM)-based intrusion detection systems (IDS) are increasingly studied for security monitoring, yet their robustness against feasible traffic manipulation remains largely empirical.
By Zhenpeng Li
The paper introduces ExCYDER, an explainable AI framework for anomaly detection in Distributed Energy Resource (DER) networks. It combines LightGBM with SHAP to self-verify alerts, ensuring that each detection aligns with feature‑attribution evidence. Experiments on a realistic DNP3 dataset show over 98% detection accuracy, 44.6% rule‑SHAP consistency, 14.5 ms SHAP latency per alert, and minimal confidence deviation, while distinguishing coherent from inconsistent alerts without sacrificing accuracy.
By Damilola Popoola, Souradeep Bhattacharya, Manimaran Govindarasu
arXiv:2510.09619v2 Announce Type: replace-cross
Abstract: [Corrected v2: an audit found that the score, threshold, and latency descriptions below are not what the shared codebase implements, and that...
By Michel A. Youssef (Independent Researcher)
arXiv:2605. 24696v2 Announce Type: replace-cross Abstract: Streaming intrusion detection systems must process flows continuously under bounded memory, yet most leave alerting-threshold selection as a post-hoc tuning problem incompatible with production, where operators commit in advance to alert budgets, misclassification costs, and Service Level Objectives.
By Michel A. Youssef
arXiv:2605. 30837v2 Announce Type: replace-cross Abstract: Prompt-injection detectors are heterogeneous: each is strong on a different slice of attacks, and none is always reliable.
By Shuhao Zhang, Jiarui Li, Qi Cao, Ruiyi Zhang, Pengtao Xie
arXiv:2608. 14089v1 Announce Type: new Abstract: Safety classifiers deployed with large language models often fail for two reasons: their decisions reflect the policy learned during training rather than the deployer's desired policy, and their performance degrades as deployment traffic evolves.
By Thiago Sandoval, Ufuk Topcu
arXiv:2606. 05710v1 Announce Type: cross Abstract: The increasing penetrations of the critical infrastructure sector in the United States with intelligent digital technologies have greatly increased exposure to advanced cyber adversaries and operational vulnerabilities.
By B. M. Taslimul Haque, Md. Arifur Rahman, Md. Serajul Kabir Chowdhury Rubel, Md. Iqbal Hossan
arXiv:2608. 08100v1 Announce Type: cross Abstract: Retrieval-Augmented Generation (RAG) enables large language models to classify network flows and generate human-readable incident reports by retrieving semantically similar historical traffic from a vector knowledge base.
By Kaysarul Anas Apurba, Md. Hasibul Hasan, Mahedee Zaman Moon, Sk. Md. Mizanur Rahman, Atsuo Inomata