Research shows filtering reduces predictability of cyber-attacks.
problem Predicting cyber-attacks from incomplete data.
method Combining external data with machine learning algorithms to learn indicators of cyber-attacks.
result The process of filtering reduces the predictability of cyber-attacks.
Paper proposes RL for real-time smart grid cyber attack detection.
problem Real-time detection of cyber-attacks in smart grids.
method Formulated as POMDP, uses model-free reinforcement learning.
result Effective in timely and accurate detection of cyber-attacks.
Cyber attacks are growing in frequency and severity. Over the past year alone we have witnessed massive data breaches that stole personal information of millions of people and wide-scale ransomware attacks that paralyzed critical infrastructure of several countries. Combating the rising cyber threat calls for a multi-p…
Paper analyzes electricity price and demand TSs using decomposition to detect cyber-attacks.
problem Detecting cyber-attacks in electricity price and demand time series data.
method Performed time series decomposition using additive and multiplicative methods, tested error term for patterns.
result Found a chance of cyber-attacks in the error term of decomposed TSs.
Framework uses RL to design robust observers for cyber-attacks.
problem Robustness of autonomous systems under cyber-attacks and sensor failures.
method Adversarial deep reinforcement learning for observer design.
result Learned observer strategies perform well under bounded adversarial errors.
Study proposes framework for cyber bonds to compensate cyber attack losses.
problem Cyber risk treatment in finance industry.
method Developed a framework, used publicly available data to determine loss distribution parameters, numerically simulated bond price and characteristics, considered two coupon calculation approaches.
result Numerical simulations of cyber bond price, yield, and characteristics.
A tree-based IDS detects cyber-attacks in AV networks.
problem Cyber-attacks in AV and IoV networks.
method Tree-structure machine learning models, ensemble learning, feature selection.
result High detection rate and low computational cost achieved.
Deep RL enhances cyber security through adaptive, responsive, and scalable defenses.
problem Complex, dynamic cyber attacks require adaptive and scalable security solutions.
method Incorporates deep learning into traditional RL for cyber defense.
result Demonstrates the potential of DRL in solving high-dimensional cyber defense problems.
New approach detects cyber-attacks in real-time.
problem Real-time detection of cyber-attacks for effective mitigation.
method Aggregates unsupervised anomaly detection algorithms and incorporates delayed feedback.
result Improves anomaly detection performance through theoretical guarantees.
Improves cyber attack detection accuracy with GAN-generated balanced data.
problem Difficulty in creating a model due to imbalanced dataset.
method Used GAN to generate balanced data and MLP for classification.
result Improved classification performance with GAN-generated data.
Paper analyzes electricity price and demand data to detect cyber-attacks using time series methods.
problem Detecting cyber-attacks in electricity price and demand data.
method Time series analysis, including moving average, moving standard deviation, and augmented Dickey-Fuller test.
result Identified anomalies in the data using time-series stationary criteria.
GANs generate realistic cyber-attack alerts with feature dependencies.
problem Challenges in creating realistic cyber-attack alert data.
method Used Generative Adversarial Networks (GANs) to learn complex data distributions.
result GANs successfully generate realistic alerts with feature dependencies.
CyPhERS provides real-time event info for CPSs, avoiding downtime.
problem Real-time event identification in CPSs is challenging due to complex interdependencies and rare events.
method CyPhERS integrates cyber and physical components, generating event signatures for known and unknown events.
result Event signatures provide relevant and inferable information on both known and unknown event types.
Model quantifies cyber-attacks' impact on firms and insurers.
problem Impact of cyber-attacks on firms' revenues and insurers' portfolios.
method Stochastic SIR model coupled with granular firm growth model.
result Predicts insurer needs to compensate up to two days of revenue in a 100-day incident.
Study cyber-attacks on RL algorithms, focusing on cost signal manipulation.
problem Adversarial manipulation of cost signals in reinforcement learning.
method Quantitative analysis of TD(λ) and Q-learning algorithms under manipulation. result Bound on approximation error for TD(λ) and convergence properties for Q-learning under stealthy attacks. Deep learning detects cyber-attacks in smart grid systems.
problem Cyber-attacks on smart grid systems.
method Deep learning-based intrusion detection system trained on industrial dataset.
result Proposed system outperforms Naive Bayes, SVM, and Random Forest.
Recent changes to greenhouse gas emission policies are catalyzing the electric vehicle (EV) market making it readily accessible to consumers. While there are challenges that arise with dense deployment of EVs, one of the major future concerns is cyber security threat. In this paper, cyber security threats in the form o…
This paper shows how cyber-attacks can undermine predictive maintenance systems.
problem Cyber-attacks on IoT sensors and DL algorithms in predictive maintenance systems.
method Used LSTM, GRU, and CNN for RUL prediction; modeled false data injection attacks; evaluated impact on accuracy and resilience.
result False data injection attacks can severely impact RUL prediction, but GRU-based models are more resilient.
Machine Learning improves cybersecurity by detecting cyber attacks.
problem Growing sophistication and complexity of cybersecurity threats.
method Examined five machine learning algorithms on NetFlow datasets to classify malicious traffic.
result Random Forest Classifier detects over 95% of botnets in 8 out of 13 scenarios.
Paper tackles cyber threats to PHM systems using adversarial examples.
problem Vulnerability of IoT sensors and DL algorithms to cyber attacks.
method Adopted adversarial example crafting techniques from computer vision to PHM domain.
result PHM models are vulnerable to adversarial attacks, leading to inaccurate remaining useful life estimation.
Machine learning-based IDSs in ICS are vulnerable to adversarial attacks that can bypass them.
problem Adversarial attacks on machine learning-based IDSs in ICS can lead to undetected cyber attacks.
method Used Jacobian-based Saliency Map attack to generate adversarial samples and explored adversarial training to improve model robustness.
result Classification performance of supervised models decreased by 16-20 percentage points with adversarial samples, but improved with adversarial training.
Adversarial neural network improves cyber attack detection across different networks.
problem Detecting cyber attacks across networks with different traffic distributions.
method Adversarial Siamese neural network that learns invariant attack representations.
result The method retrieves sizable proportions of malicious events, even when trained on one dataset and tested on another.
Generative adversarial networks enable distributed IoT IDS without central controller.
problem Detecting cyber attacks in IoT systems with privacy preservation.
method Proposes a fully distributed GAN-based IDS for IoT.
result Higher accuracy and lower false positive rate compared to standalone IDS.
Graph-based approach detects anomalies in IDS alerts.
problem False alarms and lack of interdependence among alerts.
method Fused graph of IDS alerts, role-dynamics approach.
result Significant reduction in false positives.
We adopted an approach based on an LSTM neural network to monitor and detect faults in industrial multivariate time series data. To validate the approach we created a Modelica model of part of a real gasoil plant. By introducing hacks into the logic of the Modelica model, we were able to generate both the roots and cau…
Paper offers guidelines for using ML in cyber security, focusing on botnet detection.
problem Lack of public benchmark datasets for evaluating ML-based cyber security systems.
method Provided concrete guidelines and recommendations for using supervised ML in cyber security, focusing on botnet detection.
result Ensemble models are well-suited to handle class imbalance in botnet detection.
Communication networks have evolved from specialized, research and tactical transmission systems to large-scale and highly complex interconnections of intelligent devices, increasingly becoming more commercial, consumer-oriented, and heterogeneous. Propelled by emergent social networking services and high-definition st…
Nowadays more and more data are gathered for detecting and preventing cyber attacks. In cyber security applications, data analytics techniques have to deal with active adversaries that try to deceive the data analytics models and avoid being detected. The existence of such adversarial behavior motivates the development…
This paper uses deep reinforcement learning to detect phishing websites.
problem Detecting and preventing phishing websites to protect user data.
method Introduces a novel deep reinforcement learning model for phishing website detection.
result The model can adapt to the dynamic nature of phishing websites.
While modern day web applications aim to create impact at the civilization level, they have become vulnerable to adversarial activity, where the next cyber-attack can take any shape and can originate from anywhere. The increasing scale and sophistication of attacks, has prompted the need for a data driven solution, wit…
Proposes a probabilistic framework for smart contract risk quantification.
problem Quantifying financial risk of smart contract cyber attacks and failures.
method Probabilistic graph-theoretical framework using bond percolation models.
result Analytical results and numerical examples for aggregate loss distribution.
Paper addresses Byzantine attacks in decentralized optimization over networks.
problem Byzantine attacks in decentralized stochastic optimization over static and time-varying networks.
method Formulate a TV norm-penalized approximation of the problem, solve using stochastic subgradient method.
result Proposed method reaches a neighborhood of the Byzantine-free optimal solution.
A system predicts future malicious behavior of network entities.
problem Prioritizing alert data and understanding attack recurrence.
method Machine learning-based network entity reputation database system.
result It is possible to precisely estimate future attack probabilities.
This paper detects anomalies in cellular network traffic using hybrid methods.
problem Detecting anomalies in network traffic for security and analysis.
method Hybrid method combining GARCH, K-means, and Neural Network.
result Anomaly detection in cellular network traffic successfully achieved.
Adversarial attacks degrade DRL-based EV energy management systems.
problem Adversarial attacks on DRL-based energy management systems of electric vehicles.
method Generated adversarial examples to degrade DRL performance using low-dimensional state representations.
result Adversarial attacks can significantly degrade DRL-based EV energy management systems.
This paper reviews ML and DL for IoT security, highlighting gaps and future directions.
problem Security and privacy issues in IoT networks due to resource constraints and dynamic behavior.
method Systematic review of current security solutions and ML/ DL approaches.
result ML and DL are essential for IoT security due to resource constraints and dynamic behavior.
Paper introduces a new model for cyber insurance pricing.
problem Inaccurate pricing of cyber insurance due to multiple, contagious losses.
method Developed a bivariate compound dynamic contagion process.
result Analytical expressions for the compound process and its moments.
The control and sensing of large-scale systems results in combinatorial problems not only for sensor and actuator placement but also for scheduling or observability/controllability. Such combinatorial constraints in system design and implementation can be captured using a structure known as matroids. In particular, the…
GAN-AD detects anomalies in CPSs using LSTM-RNN and multivariate time series.
problem Detecting anomalies in complex CPSs with networked sensors and actuators.
method Generative Adversarial Networks (GAN) with LSTM-RNN for multivariate time series analysis.
result GAN-AD outperforms existing methods in identifying anomalies with high detection rate and low false positives.
Paper studies autoencoder-based anomaly detectors' robustness to adversarial poisoning attacks.
problem Adversarial poisoning attacks on online-trained autoencoder-based anomaly detectors in ICSs.
method Proposes two algorithms for generating poison samples and evaluates them on synthetic and real-world ICS data.
result Autoencoder detectors are resilient to poisoning in the face of all relevant attacks in the SWaT dataset.