arXiv Machine Learning By Rahil Aftab, Anyash Prasad, Soumya Mazumdar, Vineet Kumar Rakesh, Tapas Samanta

RES-DARE: Failure-Aware Expert Adaptation and Rollback-Safe Self-Repair for Intrusion Detection

Read the original on arXiv Machine Learning →

arXiv:2607. 02687v1 Announce Type: cross Abstract: Intrusion detection systems are often trained under static benchmark conditions, although deployed network environments are affected by traffic drift, sensor noise, changing workloads, and evolving attack behaviour.

Machine-generated by The Flow from the publisher's headline and feed description — not written or checked by a human. The full article lives at arXiv Machine Learning.

arXiv AI
Sep 10

Towards a Resilience-Theoretic Foundation for Adversarial Robustness in Industrial Control System Anomaly Detection

The paper argues that adversarial robustness of anomaly detectors in industrial control systems (ICS) is a specific form of system resilience. It maps resilience concepts—disturbance class, absorption capacity, recovery trajectory, and degradation function—to adversarial machine learning, deriving a compositional resilience bound that identifies the coupling‑adjusted absorption capacity of nodes along an attack path as the key constraint. Empirical tests on the BATADAL water distribution benchmark reveal operationally significant effects, such as absorption‑degradation divergence under adversarial training and a paradox where hardening the most vulnerable node alone can reduce overall resilience.

By Branka Stojanovi\'c, Andreas Flatscher, Michael Somma
arXiv Machine Learning
Sep 7

Candidate Comparability Before Promotion: Conditional Validation in Adaptive Network Intrusion Detection

The paper investigates how to properly validate candidate models before promoting them to replace incumbent classifiers in adaptive network intrusion detection systems. It demonstrates that promotion decisions can be biased by how challengers are constructed and the amount of evidence they receive, and that using self‑contained challenger pipelines and sufficient candidate evidence reduces apparent promotion harm. The study also shows that policy rankings shift with candidate comparability and that no single update policy dominates across benchmarks.

By Roberto Fern\'andez-Barrios, Iker Pastor-L\'opez, Amaia Pikatza-Huerga, Pablo Garc\'ia Bringas
arXiv Machine Learning
Sep 14

Self-Verifying Anomaly Detection using Explainable AI for Cybersecurity of DER Networks

The paper introduces ExCYDER, an explainable AI framework for anomaly detection in Distributed Energy Resource (DER) networks. It combines LightGBM with SHAP to self-verify alerts, ensuring that each detection aligns with feature‑attribution evidence. Experiments on a realistic DNP3 dataset show over 98% detection accuracy, 44.6% rule‑SHAP consistency, 14.5 ms SHAP latency per alert, and minimal confidence deviation, while distinguishing coherent from inconsistent alerts without sacrificing accuracy.

By Damilola Popoola, Souradeep Bhattacharya, Manimaran Govindarasu