GANs generate realistic cyber-attack alerts with feature dependencies.
problem Challenges in creating realistic cyber-attack alert data.
method Used Generative Adversarial Networks (GANs) to learn complex data distributions.
result GANs successfully generate realistic alerts with feature dependencies.
Intrusion detection systems (IDSs) generate valuable knowledge about network security, but an abundance of false alarms and a lack of methods to capture the interdependence among alerts hampers their utility for network defense. Here, we explore a graph-based approach for fusing alerts generated by multiple IDSs (e.g.,…
A system predicts future malicious behavior of network entities.
problem Prioritizing alert data and understanding attack recurrence.
method Machine learning-based network entity reputation database system.
result It is possible to precisely estimate future attack probabilities.
Adversarial neural network improves cyber attack detection across different networks.
problem Detecting cyber attacks across networks with different traffic distributions.
method Adversarial Siamese neural network that learns invariant attack representations.
result The method retrieves sizable proportions of malicious events, even when trained on one dataset and tested on another.
Research shows filtering reduces predictability of cyber-attacks.
problem Predicting cyber-attacks from incomplete data.
method Combining external data with machine learning algorithms to learn indicators of cyber-attacks.
result The process of filtering reduces the predictability of cyber-attacks.
Detects anomalies in product health metrics at eBay for better alerts.
problem Detecting anomalies in unsupervised product health metrics at eBay.
method Developed a Moving Metric Detector (MMD) for anomaly detection and a point-wise ranking model for alert retrieval.
result Improves alert precision and avoids alert spamming in eBay production.
Cyber attacks are growing in frequency and severity. Over the past year alone we have witnessed massive data breaches that stole personal information of millions of people and wide-scale ransomware attacks that paralyzed critical infrastructure of several countries. Combating the rising cyber threat calls for a multi-p…
Paper analyzes electricity price and demand TSs using decomposition to detect cyber-attacks.
problem Detecting cyber-attacks in electricity price and demand time series data.
method Performed time series decomposition using additive and multiplicative methods, tested error term for patterns.
result Found a chance of cyber-attacks in the error term of decomposed TSs.
Study proposes framework for cyber bonds to compensate cyber attack losses.
problem Cyber risk treatment in finance industry.
method Developed a framework, used publicly available data to determine loss distribution parameters, numerically simulated bond price and characteristics, considered two coupon calculation approaches.
result Numerical simulations of cyber bond price, yield, and characteristics.
A tree-based IDS detects cyber-attacks in AV networks.
problem Cyber-attacks in AV and IoV networks.
method Tree-structure machine learning models, ensemble learning, feature selection.
result High detection rate and low computational cost achieved.
Early detection of cyber-attacks is crucial for a safe and reliable operation of the smart grid. In the literature, outlier detection schemes making sample-by-sample decisions and online detection schemes requiring perfect attack models have been proposed. In this paper, we formulate the online attack/anomaly detection…
New approach detects cyber-attacks in real-time.
problem Real-time detection of cyber-attacks for effective mitigation.
method Aggregates unsupervised anomaly detection algorithms and incorporates delayed feedback.
result Improves anomaly detection performance through theoretical guarantees.
Improves cyber attack detection accuracy with GAN-generated balanced data.
problem Difficulty in creating a model due to imbalanced dataset.
method Used GAN to generate balanced data and MLP for classification.
result Improved classification performance with GAN-generated data.
Paper analyzes electricity price and demand data to detect cyber-attacks using time series methods.
problem Detecting cyber-attacks in electricity price and demand data.
method Time series analysis, including moving average, moving standard deviation, and augmented Dickey-Fuller test.
result Identified anomalies in the data using time-series stationary criteria.
The scale of Internet-connected systems has increased considerably, and these systems are being exposed to cyber attacks more than ever. The complexity and dynamics of cyber attacks require protecting mechanisms to be responsive, adaptive, and scalable. Machine learning, or more specifically deep reinforcement learning…
System prioritizes rough sleeper alerts to improve outreach success.
problem Connecting rough sleepers with essential services efficiently.
method Data-driven approach prioritizing alerts based on likelihood of success.
result Increased outreach success rate by at least 15%.
CyPhERS provides real-time event info for CPSs, avoiding downtime.
problem Real-time event identification in CPSs is challenging due to complex interdependencies and rare events.
method CyPhERS integrates cyber and physical components, generating event signatures for known and unknown events.
result Event signatures provide relevant and inferable information on both known and unknown event types.
Study shows SHAP explanations impact alert processing decisions but not performance.
problem Utility of SHAP explanations in alert processing by human experts.
method Human-grounded evaluation with three groups of participants, qualitative analysis of reflections.
result SHAP explanations impact decision-making but not alert processing performance.
We explain increases in clinical risk predictions over time.
problem Tackling the challenge of explaining dynamic risk increases in clinical settings.
method Developed methods to extend static attribution techniques to dynamic settings, addressing challenges specific to time-series data.
result Identified and addressed challenges specific to dynamic risk estimation, improving clinical alert explanations.
Model quantifies cyber-attacks' impact on firms and insurers.
problem Impact of cyber-attacks on firms' revenues and insurers' portfolios.
method Stochastic SIR model coupled with granular firm growth model.
result Predicts insurer needs to compensate up to two days of revenue in a 100-day incident.
Complex autonomous control systems are subjected to sensor failures, cyber-attacks, sensor noise, communication channel failures, etc. that introduce errors in the measurements. The corrupted information, if used for making decisions, can lead to degraded performance. We develop a framework for using adversarial deep r…
Study cyber-attacks on RL algorithms, focusing on cost signal manipulation.
problem Adversarial manipulation of cost signals in reinforcement learning.
method Quantitative analysis of TD(λ) and Q-learning algorithms under manipulation. result Bound on approximation error for TD(λ) and convergence properties for Q-learning under stealthy attacks. To assure cyber security of an enterprise, typically SIEM (Security Information and Event Management) system is in place to normalize security event from different preventive technologies and flag alerts. Analysts in the security operation center (SOC) investigate the alerts to decide if it is truly malicious or not. H…
Integrates CNN and GRU for precise stock market risk alerts.
problem Predicting future stock market risks and providing early warnings.
method Uses CNN for feature extraction and GRU for time series analysis.
result Effective early warnings of future stock market risks.
Deep learning detects cyber-attacks in smart grid systems.
problem Cyber-attacks on smart grid systems.
method Deep learning-based intrusion detection system trained on industrial dataset.
result Proposed system outperforms Naive Bayes, SVM, and Random Forest.
A CBR approach helps fraud analysts trust machine learning predictions.
problem Understanding the trustworthiness of machine learning predictions for fraud analysts.
method Case-based reasoning (CBR) approach to visualize similar previous instances and their local post-hoc explanations.
result Empirically, the visualization of similar previous instances is useful and easy to use for fraud analysts.
Robust fuzzy clustering for EEG driver alertness with outlier detection.
problem Ambiguous state boundaries in multivariate time series data.
method RFCPCA, a robust fuzzy subspace-clustering method for MTS.
result RFCPCA improves clustering accuracy and characterizes uncertainty and outliers in MTS.
Recent changes to greenhouse gas emission policies are catalyzing the electric vehicle (EV) market making it readily accessible to consumers. While there are challenges that arise with dense deployment of EVs, one of the major future concerns is cyber security threat. In this paper, cyber security threats in the form o…
Paper detects social media influencers affecting financial markets.
problem Impact of social media influencers on financial markets.
method Developed an early warning system for detecting suspicious social network activity.
result Discrepancy in meme and non-meme stocks' reactions to social networks.
Detects potential depegs in Curve's StableSwap pools to protect LPs.
problem Detecting and alerting LPs to potential depegs in Curve's StableSwap pools.
method Constructed metrics based on price and trading data, fine-tuned BOCD algorithm.
result Model detects USDC depeg 5 hours before price dip, with few false alarms.
We present RAPID (Real-time Automated Photometric IDentification), a novel time-series classification tool capable of automatically identifying transients from within a day of the initial alert, to the full lifetime of a light curve. Using a deep recurrent neural network with Gated Recurrent Units (GRUs), we present th…
Simulates patient pathways to detect delayed rare disease diagnoses.
problem Delayed rare disease diagnoses in France, causing health system and patient harm.
method Probabilistic modelling of patient pathways to create an alert system.
result Alert system detects and refers wandering patients to CRMRs.
This paper shows how cyber-attacks can undermine predictive maintenance systems.
problem Cyber-attacks on IoT sensors and DL algorithms in predictive maintenance systems.
method Used LSTM, GRU, and CNN for RUL prediction; modeled false data injection attacks; evaluated impact on accuracy and resilience.
result False data injection attacks can severely impact RUL prediction, but GRU-based models are more resilient.
Bitcoin reacts positively to USDT minting but not burning, showing state-dependence.
problem Understanding Bitcoin's response to Tether's supply changes.
method Analyzing Bitcoin's intraday price movements in response to USDT minting and burning events.
result Bitcoin's response to USDT minting events declines after 60 minutes and is influenced by investor sentiment and public announcements.
Machine Learning improves cybersecurity by detecting cyber attacks.
problem Growing sophistication and complexity of cybersecurity threats.
method Examined five machine learning algorithms on NetFlow datasets to classify malicious traffic.
result Random Forest Classifier detects over 95% of botnets in 8 out of 13 scenarios.
Social media services such as Twitter are a valuable source of information for decision support systems. Many studies have shown that this also holds for the medical domain, where Twitter is considered a viable tool for public health officials to sift through relevant information for the early detection, management, an…
Paper tackles cyber threats to PHM systems using adversarial examples.
problem Vulnerability of IoT sensors and DL algorithms to cyber attacks.
method Adopted adversarial example crafting techniques from computer vision to PHM domain.
result PHM models are vulnerable to adversarial attacks, leading to inaccurate remaining useful life estimation.
Machine learning-based IDSs in ICS are vulnerable to adversarial attacks that can bypass them.
problem Adversarial attacks on machine learning-based IDSs in ICS can lead to undetected cyber attacks.
method Used Jacobian-based Saliency Map attack to generate adversarial samples and explored adversarial training to improve model robustness.
result Classification performance of supervised models decreased by 16-20 percentage points with adversarial samples, but improved with adversarial training.
Silence on suspicious stock market patterns persists despite lack of plausible explanations.
problem Suspicious patterns in stock market returns not explained or warned about.
method Analysis of correspondence and market data over five years.
result People aware of suspicious patterns chose not to alert the public.
Deployment of machine learning (ML) algorithms in production for extended periods of time has uncovered new challenges such as monitoring and management of real-time prediction quality of a model in the absence of labels. However, such tracking is imperative to prevent catastrophic business outcomes resulting from inco…
To reap the benefits of the Internet of Things (IoT), it is imperative to secure the system against cyber attacks in order to enable mission critical and real-time applications. To this end, intrusion detection systems (IDSs) have been widely used to detect anomalies caused by a cyber attacker in IoT systems. However, …
Paper forecasts extreme Bitcoin volatility spikes using whale transactions and CryptoQuant data.
problem Forecasting extreme volatility spikes in Bitcoin market.
method Proposes Synthesizer Transformer model for forecasting.
result Model outperforms state-of-the-art models in forecasting extreme volatility spikes.
CovidSens uses social media to track COVID-19 spread.
problem Accurate and timely dissemination of COVID-19 information.
method Social sensing to analyze online user data.
result Real-time COVID-19 spread tracking system.
The paper proposes a method to detect relevant model degradations without over-alerting.
problem Detecting meaningful changes in machine learning model performance over time.
method Sequential monitoring scheme accounting for temporal dependence and multiple testing issues.
result The proposed method outperforms benchmark methods in detecting relevant changes in model quality.
A new algorithm uses bandits to diversify database activity monitoring.
problem Limitation of current DAM systems in collecting diverse data.
method Redefined DAM sampling as a bandit problem and developed a novel algorithm combining expert knowledge and random exploration.
result Adding diversity to sampling using the bandit-based approach improves coverage without decreasing alert quality.
We propose a general model explanation system (MES) for "explaining" the output of black box classifiers. This paper describes extensions to Turner (2015), which is referred to frequently in the text. We use the motivating example of a classifier trained to detect fraud in a credit card transaction history. The key asp…
Benchmarking recursive collapse claims with a new framework under false-positive control.
problem Evaluating recursive systems for failure patterns and warning claims.
method Developed Loopzero framework for testing recursive failures, specified claim boundaries in Lean, evaluated under FP constraint, and compared with standard detectors.
result No standard detectors or Loopzero's pre-registered quantile detector achieved the required operating point under the false-positive contract.
We adopted an approach based on an LSTM neural network to monitor and detect faults in industrial multivariate time series data. To validate the approach we created a Modelica model of part of a real gasoil plant. By introducing hacks into the logic of the Modelica model, we were able to generate both the roots and cau…