Adversarial machine learning
Attacks on how models learn and decide: adversarial examples, evasion, data poisoning and backdoors in trained models.
- All items
- 85
- Last 90 days
- 23
- Change
- 0%vs 23 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 0 |
| Jun 2025 | 0 |
| Jul 2025 | 0 |
| Aug 2025 | 1 |
| Sep 2025 | 1 |
| Oct 2025 | 1 |
| Nov 2025 | 1 |
| Dec 2025 | 6 |
| Jan 2026 | 4 |
| Feb 2026 | 8 |
| Mar 2026 | 10 |
| Apr 2026 | 10 |
| May 2026 | 9 |
| Jun 2026 | 8 |
| Jul 2026 | 8 |
| Aug 2026 | 2 |
| Sep 2026 | 13 |
| Oct 2026 | 0 |
85 items
Hard-label black-box model extraction attacks against network intrusion detection systems via generative adversarial networks
Sep 30, 2026InfoResearchPeer-reviewedSecurityResearchThe paper asks whether a network intrusion detection system's model can be extracted using only hard-label black-box queries. The source text provided gives only the title, publication date (December 2026), journal (Journal of Information Security and Applications, Volume 103), and authors (Donguk Min, Seungsoo Nam, Daeseon Choi), with no method description or findings.
Elsevier Security JournalsEfficient model stealing in data-free scenarios: An attack method via elite sample distillation
Sep 29, 2026InfoResearchPeer-reviewedSecurityResearchLiu, Wen and Yu published an article in the Journal of Information Security and Applications, Volume 103, dated December 2026. The source text provided contains only the publication metadata and author list, with no abstract, method or findings.
Elsevier Security JournalsIndirectAD: Practical Data Poisoning Attacks Against Recommender Systems for Item Promotion
Sep 28, 2026LowResearchPeer-reviewedSecurityResearchResearchers introduce IndirectAD, a data poisoning attack against recommender systems inspired by Trojan attacks on machine learning. The attack first promotes a trigger item, then transfers that advantage to a target item by creating co-occurrence data between them, which reduces the number of controlled accounts needed. Experiments on multiple datasets and recommender systems show noticeable impact with only 0.05% of a platform's user base.
IEEE Xplore (Security & AI Journals)Stealthy Physical Adversarial Attacks on Speaker Recognition via Near-Ultrasonic Perturbations
Sep 28, 2026LowResearchPeer-reviewedSecurityResearchAdvNup is a physical adversarial attack that spoofs deep neural network speaker recognition systems using near-ultrasonic perturbations played through commercial off-the-shelf speakers, avoiding the specialized hardware that earlier ultrasound attacks required. The authors use single-sideband modulation with low-pass filtering, a nonlinear frequency response model, and time-frequency masking to keep the adversarial signal intact through physical transmission. In simulated and physical experiments, it reached a 100% attack success rate for closed-set identification and over 90% for open-set identification in targeted attacks.
IEEE Xplore (Security & AI Journals)Benchmarking post-processing methods in local differential privacy for utility and adversarial robustness
Sep 26, 2026InfoResearchPeer-reviewedResearchPrivacyElsevier Security JournalsAdaptive Defense Optimization Under Intelligent Data Poisoning Attacks in Industrial Control System
Sep 25, 2026InfoResearchPeer-reviewedSecurityResearchThis paper proposes a detection-aware stochastic optimization framework for industrial control systems facing asynchronous, unreliable feedback and adversarial data poisoning. It uses the SWaT dataset to model poisoning behavior and an adaptive acknowledgment (ACK) bundling mechanism, driven by a multi-objective stochastic gradient descent (SGD) algorithm with a residual-based anomaly indicator, to adjust feedback timing. Numerical experiments on an autonomous surface vehicle (ASV) benchmark show closed-loop recovery under AI-driven data poisoning attacks.
Fix: The source describes an adaptive ACK bundling mechanism that regulates feedback timing and adjusts the ACK bundling window online when anomalous behavior is detected, with Lyapunov–Krasovskii (LK)-based conditions established to ensure closed-loop stability. It does not describe a patch, fixed version or configuration fix for a specific product.
IEEE Xplore (Security & AI Journals)EXE-Bench: Ranking the Tradeoffs of AI-Based Windows Malware Detectors for Real-World Usability
Sep 17, 2026InfoResearchPeer-reviewedSecurityResearchExisting evaluations of AI-based Windows malware detectors differ in training and test data, lack temporal analysis, skip adversarial content-injection tests, and ignore deployment compute costs, so they cannot show which detector to deploy. The authors introduce EXE-Bench, which assesses performance, temporal and adversarial robustness, and computational overhead, combining them into one score for direct comparison. Their analysis finds that feature-engineered domain knowledge remains highly useful, resisting both time and adversarial attacks, while most deep networks excel only right after deployment.
IEEE Xplore (Security & AI Journals)Advanced Cross-Attack Backdoor Detector Based on Disturbance Immunity Learned From Classic Backdoor Attacks
Sep 17, 2026InfoResearchPeer-reviewedSecurityResearchThe paper presents the Advanced Cross-attack Backdoor Detector (ACBD), which detects trigger-injected samples by solving a labeled binary classification task based on disturbance immunity, rather than unlabeled feature clustering. ACBD is trained on one class of a poisoned dataset (1/100 of CIFAR-100) with two classic attacks, using a small LSTM with 53 K parameters and at most 10 clean images for perturbation. The authors report state-of-the-art detection with cross-attack generalization, including on unseen triggers and different target labels.
IEEE Xplore (Security & AI Journals)CAFBA: Context-aware adaptive fusion backdoor attack for polyp segmentation
Sep 9, 2026InfoResearchPeer-reviewedSecurityResearchElsevier Security JournalsAction-Level Backdoor Attacks Against Deep Reinforcement Learning Systems via Adaptive Reward Exploration
Sep 2, 2026InfoResearchPeer-reviewedSecurityResearchAdapdoor is an attack framework that injects action-level backdoors into deep reinforcement learning models during training, so that adversaries can manipulate action outputs at deployment. It initializes the backdoor reward from benign reward statistics and iteratively fine-tunes it using performance feedback from benign and backdoor tasks. Across 3 DRL algorithms, 11 environments and 53 backdoor tasks, it outperforms existing baselines by 42.0% to 144.2%.
Fix: The source says the authors evaluate three potential defenses to explore pathways for mitigating this threat, but it does not name them or state a fix.
IEEE Xplore (Security & AI Journals)Generative Textual Adversarial Attack Through Extensible Compositional Perturbation via Reinforcement Learning for Policy Optimization
Sep 1, 2026InfoResearchPeer-reviewedSecurityResearchGECOMP is a generative textual adversarial attack that uses reinforcement learning for policy optimization. An LLM-based generator rewrites input sequences using an extensible library of compositional perturbations, constrained by semantic similarity and edit magnitude. Across four public datasets and five victim models, it achieved higher attack success rates than ten baseline methods while using fewer queries and less edit magnitude.
IEEE Xplore (Security & AI Journals)WPEBA: A Novel Ensemble Black-Box Adversarial Attack for Visual Recognition Systems via Wavelet Packet Decomposition
Sep 1, 2026InfoResearchPeer-reviewedSecurityResearchWPEBA is a frequency-driven ensemble black-box adversarial attack for visual recognition systems that uses wavelet packet decomposition to split images into frequency sub-bands. It adjusts sub-band weights from internal gradient feedback and updates surrogate-model weights from target-model query feedback, reaching an average attack success rate of nearly 99% with one or two queries across six standard architectures. The authors report it also remains effective against defended models and the Google Cloud Vision API.
IEEE Xplore (Security & AI Journals)3DGAA: Realistic and Robust 3D Gaussian-Based Adversarial Attack for Autonomous Driving
Sep 1, 2026InfoResearchPeer-reviewedSecurityResearchResearchers present 3DGAA, a framework for physical adversarial attacks on camera-based perception in autonomous vehicles. It uses 3D multi-view optimization with a 3D Gaussian splatting surrogate to produce print-only vehicle wraps that keep geometry unchanged. In CARLA simulations and miniature-vehicle tests, the wraps substantially reduced detection confidence and average precision across multiple modern detectors.
IEEE Xplore (Security & AI Journals)Edge-Only Universal Adversarial Attacks in Distributed Learning
Aug 19, 2026InfoResearchPeer-reviewedSecurityResearchResearchers study whether universal adversarial perturbations (UAPs) can be generated when an attacker controls only the edge portion of a split model, meaning its initial network layers. They introduce edge-only untargeted and targeted UAP formulations that manipulate intermediate features before the split point. On ImageNet, the attacks transfer strongly to the unknown cloud component and compare favorably with classical white-box and black-box techniques.
IEEE Xplore (Security & AI Journals)Text Adversarial Attacks With Dynamic Outputs
Aug 12, 2026InfoResearchPeer-reviewedSecurityResearchResearchers introduce the Textual Dynamic Outputs Attack (TDOA), a text adversarial attack for settings where the number and content of model labels vary, such as LLM outputs and multi-label classification. TDOA trains a clustering-based surrogate model that approximates dynamic fine-grained outputs with static coarse-grained labels, and uses a farthest-label targeted strategy to induce larger output changes. Evaluated on five datasets and ten victim models including GPT-4o and GPT-4.1, it reaches an 80.8% maximum attack success rate with five queries per text.
IEEE Xplore (Security & AI Journals)A comprehensive analysis of adversarial attacks against spam filters
Jul 25, 2026InfoResearchPeer-reviewedSecurityResearchElsevier Security JournalsPREFed: An Effective and Stealthy Static-Anchor Backdoor Attack via Trigger Pre-Optimization in Federated Learning
Jul 23, 2026InfoResearchPeer-reviewedSecurityResearchPREFed is a static-anchor backdoor attack for federated learning that pre-optimizes trigger patterns on clean data before training, removing the need for round-wise adaptation. The authors report that it reaches over 80% backdoor accuracy within five communication rounds while cutting main task accuracy by less than 2%, versus more than 15% degradation in prior methods, across six defenses on image benchmarks and SST-2.
IEEE Xplore (Security & AI Journals)NEO: Navigating Entropy in Optimized Closed-Box Video Adversarial Attacks
Jul 22, 2026InfoResearchPeer-reviewedSecurityResearchNEO is a closed-box adversarial attack on deep learning video recognition systems that uses information-entropy guidance to cut query costs. The authors model query-based attacks as an open-box approximation and find that queries near decision boundaries carry the most information. NEO combines diffusion-based perturbation initialization with mutual-information-driven optimization and reports significantly higher efficiency and stealthiness than existing methods on four benchmark datasets.
IEEE Xplore (Security & AI Journals)Rethinking Fake Adversarial Examples for Single-Step Adversarial Training
Jul 20, 2026InfoResearchPeer-reviewedSecurityResearchResearchers examine why single-step adversarial training, a cheaper alternative to standard adversarial training, often suffers catastrophic overfitting under larger perturbations. They identify "fakers," single-step adversarial examples that are learned and correctly classified yet fail to expose true model vulnerabilities, and that degrade robustness, resist learning and diverge strongly from their clean counterparts. They propose FAST, which adjusts label smoothing by learning difficulty and adds a weak-effect auxiliary sample, reporting superior clean accuracy and robustness across various attacks.
IEEE Xplore (Security & AI Journals)Spa: Stealthy and Persistent Backdoor Attacks in Federated Learning via Feature-Space Alignment
Jul 17, 2026InfoResearchPeer-reviewedSecurityResearchResearchers propose Spa, a backdoor attack framework for federated learning that aims to be both stealthy and persistent. Instead of training a conflicting secondary task, Spa uses feature-space alignment to fold backdoor features into the primary objective, and it uses adversarial dynamic trigger optimization that co-evolves with the global model. Experiments report attack success rates near 100% with minimal utility loss, and the backdoor stays effective around 900 FL rounds after attacks stop.
IEEE Xplore (Security & AI Journals)
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.