Jul 2026· European Conference on Artificial Intelligence· pp. 1-7· 0 citations· 16 references
Abstract
Cyber-physical energy systems rely on digital measurements, state estimation, and learning-assisted monitoring, yet these layers are vulnerable to stealthy false data injection attacks that can distort operator awareness without triggering residual alarms. This paper presents a physics-constrained deep generative framework for attack synthesis in power-system state estimation. Conditional generative adversarial networks, autoencoders, and variational autoencoders are compared under a unified physics-aware setting that embeds the nonlinear measurement function, local state-estimation sensitivity, residual preservation, and reconstruction consistency. The framework evaluates generated attacks on IEEE 14-bus, 57-bus, and 118-bus systems using convergence behavior, bad data detection bypass rate, and Jensen-Shannon divergence. Results show that the variational autoencoder and autoencoder achieve stronger residual evasion, whereas the conditional generative adversarial network yields more realistic measurement distributions. Confidential computing and zero-trust tokenization are incorporated as interpretive security layers for protected measurement handling, tokenized provenance, and joint residual distributional trust assessment within state-estimation security decision workflows.
UA-EAD is proposed, an uncertainty-aware evidential adversarial defense that equips the detector with an evidential head yielding calibrated predictive uncertainty in a single forward pass, trains it with an uncertainty-weighted adversarial objective plus a consistency regularizer that concentrates robustness on the most uncertain, near-boundary flows, and uses the resulting uncertainty for selective prediction.
Jiawen Luo, Samuel Price· International Journal of Adv...· 0 citations
As artificial intelligence becomes woven into critical applications such as healthcare, finance, autonomous systems, and cybersecurity, adversarial threats to machine learning models have grown into one of the most pressing concerns in the field. Adversarial machine learning studies how attackers exploit weaknesses in model architectures and data pipelines, manipulating inputs to trigger misclassification, extract sensitive information, or quietly degrade system performance. This article offers a detailed overview of the security risks associated with adversarial attacks, including evasion attacks carried out at inference time, data poisoning that corrupts the training process, backdoor insertion that hides dormant triggers inside a model, and model inversion that leaks private information back out of a trained system. In response to these threats, the discussion evaluates a wide range of defense strategies designed to strengthen the robustness and reliability of AI systems, including adversarial training, robust optimization, defensive distillation, anomaly detection, and privacy-preserving techniques such as differential privacy and federated learning. Particular emphasis is placed on weaving these defenses into every stage of the AI development lifecycle and on cultivating a threat-aware mindset before models are ever deployed into real-world environments. By drawing together current research, mathematical foundations, and practical implementation experience, this article traces the evolving landscape of adversarial machine learning and offers actionable guidance for developers, researchers, and policymakers who are working to secure AI-driven applications against increasingly sophisticated attacks.
Harsh Verma· International Journal of Sci...· 0 citations
As semiconductor manufacturing becomes increasingly outsourced to untrusted entities, Hardware Trojan (HT) attacks pose a critical threat to the security and reliability of modern integrated circuits. Machine learning models have improved the effectiveness of HT detection using Ring Oscillator Network (RON) side-channel data, yet recent work shows that these models are highly vulnerable to adversarial attacks. This paper evaluates the robustness of the Support Vector Machine (SVM) classifier, a leading algorithm in state-of-the-art HT detection frameworks, under gradient-based adversarial attacks. The proposed work demonstrates that high nominal accuracy does not ensure security against these attacks, which can reduce recall to zero. To strengthen resilience, three data-augmentation methods are investigated: SMOTE, Conditional Tabular Generative Adversarial Network (CTGAN), and Tabular Variational Autoencoder (TVAE). TVAE produces high-fidelity synthetic samples and substantially improves robustness, maintaining over 91% accuracy for nominal performance and over 88% accuracy under strong adversarial perturbations that cause a 100% attack success rate for the surrogate model. The results highlight the need to reframe hardware security evaluations beyond nominal accuracy toward adversarial robustness.
Ashutosh Ghimire, Lingwei Chen, Cole Castronova et al.· Journal of electronic testin...· 0 citations
In the era of collaborative cybersecurity, the sharing of threat intelligence models across organizations has become critical for proactive defence. However, such sharing raises significant privacy concerns, as machine learning models trained on proprietary or sensitive security data can inadvertently leak information through model inversion or membership inference attacks. This paper introduces a novel framework for adversarial machine unlearning to enable privacy-preserving threat intelligence sharing. Our approach integrates unlearning mechanisms with adversarial training to ensure that specific data—such as organization-specific attack traces or internal system logs—can be selectively forgotten from threat detection models without requiring full retraining. We define a robust threat model to evaluate potential privacy leakage post-unlearning and introduce novel metrics for quantifying forgetting efficacy and utility retention. Experiments on benchmark cybersecurity datasets, including network traffic, malware behaviour, and intrusion detection logs, demonstrate that our method effectively mitigates data leakage risks while maintaining high detection performance. This work lays the foundation for secure and compliant knowledge transfer in federated security operations and collaborative defence ecosystems.
R. Polishetty, Arfi Siddik Mollashaik, Naveen Jagadam et al.· Journal of Intelligent Decis...· 0 citations
The proposed Diff-DDoS framework, a three-phase framework for realistic attack synthesis and robust detection using tabular diffusion models, supports tabular diffusion models for stress-testing and hardening intrusion detectors in data-scarce 5G cyber-physical deployments.
Bilal Hussain, Xiao Tang, Qinghe Du et al.· 0 citations
A Self-Adaptive Quantum-Capsule Cognitive Security Architecture (SA-QCCSA) is introduced for zero-trust adversarial defense in 6G wireless networks, integrating Quantum-optimized Capsule Networks (Q-CapsNet) with cognitive threat orchestration for real-time cyber-attack mitigation. Multidimensional 6G network traffic is modeled as temporal–spectral feature tensors and processed using a lightweight CNN encoder followed by primary and higher-order capsules that preserve hierarchical attack patterns. A quantum-enhanced dynamic routing mechanism, implemented using a Variational Quantum Optimization layer, adaptively tunes capsule coupling coefficients to minimize adversarial uncertainty and maximize class separability under strong evasion attacks. The framework is trained using a hybrid adversarial learning strategy that combines margin-based capsule loss with contrastive regularization, enabling robustness against FGSM, BIM, PGD, and CW attacks. Experiments conducted on CIC-IDS2017, NSL-KDD, and AWID Wi-Fi intrusion datasets demonstrate that SA-QCCSA achieves 98.7% detection accuracy, 0.986 F1-score, and 0.993 AUC, significantly outperforming conventional CNN (94.1% accuracy) and LSTM (91.6% accuracy) models. Under high-strength PGD attacks, the proposed model maintains 94.8% accuracy, while CNN performance degrades below 78%, confirming superior adversarial resilience. A cognitive zero-trust control plane dynamically adjusts quantum routing depth based on real-time threat entropy, enabling self-learning, self-healing, and proactive attack containment for future 6G and beyond wireless networks.
Sneha George, R. Joy, K. Karuppasamy· 2026 International Conferenc...· 0 citations