{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T18:02:19Z","timestamp":1784397739115,"version":"3.55.0"},"reference-count":228,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T00:00:00Z","timestamp":1784332800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T00:00:00Z","timestamp":1784332800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int. J. Inf. Secur."],"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>In recent years, cyber threats have become more complex and frequent. These threats compromise the confidentiality of users, the integrity of transactions, and the availability of services offered by organizations in different sectors. To defend against threat actors, organizations employ Red and Blue teams. Red teams conduct offensive security while blue teams commit to defensive efforts. However, the shortage of cybersecurity professionals and the increasing complexity of malicious activities reinforce the need for continuous improvement in threat defense. One possible direction to address these challenges is threat defense automation. This new paradigm empowers analysts to evaluate incidents at scale, enables continuous infrastructure monitoring, accelerates the training of new team members, and establishes standard defense methods that can be shared among multiple organizations. In this regard, Machine Learning (ML) is vital to threat defense automation and leverages organizational resources to generate insights and enable informed decisions. The main goal of this research is to conduct a survey on different solutions for threat defense automation using ML techniques. We focus on the operational functions adopted by red and blue teams in several application areas. We categorize existing efforts into these functions and also review datasets, knowledge graphs, simulation platforms, and Reinforcement Learning (RL) environments for threat defense automation solutions. In total, we analyze 138 research works, of which 35 present resources relevant to automated threat defense, 60 present automated red teaming solutions, and 43 present automated blue teaming solutions. Finally, we highlight critical research gaps and identify future directions in the automation of cyber threat defense.<\/jats:p>","DOI":"10.1007\/s10207-026-01290-6","type":"journal-article","created":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T15:32:09Z","timestamp":1784388729000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Automated threat defense: a comprehensive survey on red and blue team automation using machine learning techniques"],"prefix":"10.1007","volume":"25","author":[{"given":"Euclides Carlos Pinto","family":"Neto","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shahrear","family":"Iqbal","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Scott","family":"Buffett","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Madeena","family":"Sultana","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Adrian","family":"Taylor","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,7,18]]},"reference":[{"key":"1290_CR1","doi-asserted-by":"publisher","first-page":"24","DOI":"10.1016\/S2212-5671(15)01077-1","volume":"28","author":"A Bendovschi","year":"2015","unstructured":"Bendovschi, A.: Cyber-attacks-trends, patterns and security countermeasures. Procedia Economics and Finance 28, 24\u201331 (2015)","journal-title":"Procedia Economics and Finance"},{"key":"1290_CR2","doi-asserted-by":"crossref","unstructured":"Wang, X., Wang, S., Sun, K., Batcheller, A., Jajodia, S.: A machine learning approach to classify security patches into vulnerability types, in 2020 IEEE Conference on Communications and Network Security (CNS) (IEEE, 2020), pp. 1\u20139","DOI":"10.1109\/CNS48642.2020.9162237"},{"issue":"11","key":"1290_CR3","doi-asserted-by":"publisher","first-page":"460","DOI":"10.3390\/info12110460","volume":"12","author":"N Matsumoto","year":"2021","unstructured":"Matsumoto, N., Fujita, J., Endoh, H., Yamada, T., Sawada, K., Kaneko, O.: Asset management method of industrial iot systems for cyber-security countermeasures. Information 12(11), 460 (2021)","journal-title":"Information"},{"issue":"6","key":"1290_CR4","doi-asserted-by":"publisher","first-page":"1473","DOI":"10.1007\/s40745-022-00444-2","volume":"10","author":"IH Sarker","year":"2023","unstructured":"Sarker, I.H.: Machine learning for intelligent data analysis and automation in cybersecurity: current and future prospects. Annals of Data Science 10(6), 1473\u20131498 (2023)","journal-title":"Annals of Data Science"},{"key":"1290_CR5","unstructured":"Vyas, S., Hannay, J., Bolton, A., Burnap, P.P.: Automated cyber defence: A review, (2023). arXiv preprint arXiv:2303.04926"},{"key":"1290_CR6","doi-asserted-by":"publisher","DOI":"10.3389\/fpsyg.2018.02133","volume":"9","author":"N Buchler","year":"2018","unstructured":"Buchler, N., La Fleur, C.G., Hoffman, B., Rajivan, P., Marusich, L., Lightner, L.: Cyber teaming and role specialization in a cyber security defense competition. Front. Psychol. 9, 333195 (2018)","journal-title":"Front. Psychol."},{"key":"1290_CR7","unstructured":"Sinha, A., Grimes, K., Lucassen, J., Feffer, M., VanHoudnos, N., Wu, Z.S., Heidari, H.: From firewalls to frontiers: Ai red-teaming is a domain-specific evolution of cyber red-teaming. arXiv preprint arXiv:2509.11398 (2025)"},{"key":"1290_CR8","doi-asserted-by":"crossref","unstructured":"Chindrus, C., Caruntu, C.F.: Development and testing of a core system for red and blue scenario in cyber security incidents, in 2022 15th International Conference on Security of Information and Networks (SIN) (IEEE, 2022), pp. 1\u20137","DOI":"10.1109\/SIN56466.2022.9970546"},{"key":"1290_CR9","unstructured":"Liu, X., Yu, F., Li, X., Yan, G., Yang, P., Xi, Z.: Benchmarking llms in an embodied environment for blue team threat hunting. arXiv preprint arXiv:2505.11901 (2025)"},{"key":"1290_CR10","unstructured":"Strom, B.E., Applebaum, A., Miller, D.P., Nickels, K.C., Pennington, A.G., Thomas, C.B.: in Technical report (The MITRE Corporation, 2018)"},{"key":"1290_CR11","doi-asserted-by":"crossref","unstructured":"NIST. Cybersecurity framework (2024). https:\/\/www.nist.gov\/cyberframework","DOI":"10.6028\/NIST.SP.1309.ipd"},{"issue":"1","key":"1290_CR12","first-page":"94","volume":"34","author":"CA Ramezan","year":"2023","unstructured":"Ramezan, C.A.: Examining the cyber skills gap: An analysis of cybersecurity positions by sub-field. J. Inf. Syst. Educ. 34(1), 94\u2013105 (2023)","journal-title":"J. Inf. Syst. Educ."},{"issue":"6245","key":"1290_CR13","doi-asserted-by":"publisher","first-page":"255","DOI":"10.1126\/science.aaa8415","volume":"349","author":"MI Jordan","year":"2015","unstructured":"Jordan, M.I., Mitchell, T.M.: Machine learning: Trends, perspectives, and prospects. Science 349(6245), 255\u2013260 (2015)","journal-title":"Science"},{"key":"1290_CR14","unstructured":"Goodfellow, I., Bengio, Y., Courville, A., Bengio, Y.: Deep learning, vol.\u00a01 (MIT press Cambridge, 2016)"},{"key":"1290_CR15","doi-asserted-by":"publisher","first-page":"237","DOI":"10.1613\/jair.301","volume":"4","author":"LP Kaelbling","year":"1996","unstructured":"Kaelbling, L.P., Littman, M.L., Moore, A.W.: Reinforcement learning: A survey. Journal of artificial intelligence research 4, 237\u2013285 (1996)","journal-title":"Journal of artificial intelligence research"},{"issue":"2024","key":"1290_CR16","doi-asserted-by":"publisher","first-page":"347","DOI":"10.1146\/annurev-physchem-083122-125941","volume":"75","author":"S Mehdi","year":"2024","unstructured":"Mehdi, S., Smith, Z., Herron, L., Zou, Z., Tiwary, P.: Enhanced sampling with machine learning. Annu. Rev. Phys. Chem. 75(2024), 347\u2013370 (2024)","journal-title":"Annu. Rev. Phys. Chem."},{"issue":"2","key":"1290_CR17","first-page":"330","volume":"4","author":"AS Acharya","year":"2013","unstructured":"Acharya, A.S., Prakash, A., Saxena, P., Nigam, A.: Sampling: Why and how of it. Indian journal of medical specialties 4(2), 330\u2013333 (2013)","journal-title":"Indian journal of medical specialties"},{"key":"1290_CR18","doi-asserted-by":"crossref","unstructured":"Chen, P., Desmet, L., Huygens, C.: A study on advanced persistent threats, in IFIP international conference on communications and multimedia security (Springer, 2014), pp. 63\u201372","DOI":"10.1007\/978-3-662-44885-4_5"},{"key":"1290_CR19","doi-asserted-by":"crossref","unstructured":"Abdulganiyu, O.H., Ait\u00a0Tchakoucht, T., Saheed, Y.K.: A systematic literature review for network intrusion detection system (ids). International journal of information security 22(5), 1125\u20131162 (2023)","DOI":"10.1007\/s10207-023-00682-2"},{"key":"1290_CR20","doi-asserted-by":"crossref","unstructured":"Saied, M., Adjogble, F., Guirguis, S., Hemmji, M., Warschat, J.: A framework for systematic scientific research management, in 2023 Portland International Conference on Management of Engineering and Technology (PICMET) (IEEE, 2023), pp. 1\u201316","DOI":"10.23919\/PICMET59654.2023.10216819"},{"key":"1290_CR21","doi-asserted-by":"crossref","unstructured":"Kaur, R., Gabrijel\u010di\u010d, D., Klobu\u010dar, T.: Artificial intelligence for cybersecurity: Literature review and future research directions. Information Fusion p. 101804 (2023)","DOI":"10.1016\/j.inffus.2023.101804"},{"key":"1290_CR22","doi-asserted-by":"publisher","first-page":"222310","DOI":"10.1109\/ACCESS.2020.3041951","volume":"8","author":"K Shaukat","year":"2020","unstructured":"Shaukat, K., Luo, S., Varadharajan, V., Hameed, I.A., Xu, M.: A survey on machine learning techniques for cyber security in the last decade. IEEE access 8, 222310\u2013222354 (2020)","journal-title":"IEEE access"},{"key":"1290_CR23","doi-asserted-by":"crossref","unstructured":"Sun, N., Ding, M., Jiang, J., Xu, W., Mo, X., Tai, Y., Zhang, J.: Cyber threat intelligence mining for proactive cybersecurity defense: a survey and new perspectives. IEEE Communications Surveys & Tutorials (2023)","DOI":"10.1109\/COMST.2023.3273282"},{"issue":"1","key":"1290_CR24","doi-asserted-by":"publisher","first-page":"2037254","DOI":"10.1080\/08839514.2022.2037254","volume":"36","author":"B Guembe","year":"2022","unstructured":"Guembe, B., Azeta, A., Misra, S., Osamor, V.C., Fernandez-Sanz, L., Pospelova, V.: The emerging threat of ai-driven cyber attacks: A review. Appl. Artif. Intell. 36(1), 2037254 (2022)","journal-title":"Appl. Artif. Intell."},{"issue":"11","key":"1290_CR25","doi-asserted-by":"publisher","first-page":"340","DOI":"10.1007\/s10462-025-11346-z","volume":"58","author":"ECP Neto","year":"2025","unstructured":"Neto, E.C.P., Iqbal, S., Buffett, S., Sultana, M., Taylor, A.: Deep learning for intrusion detection in emerging technologies: a comprehensive survey and new perspectives. Artif. Intell. Rev. 58(11), 340 (2025)","journal-title":"Artif. Intell. Rev."},{"key":"1290_CR26","doi-asserted-by":"crossref","unstructured":"Galinec, D., Steingartner, W.: Combining cybersecurity and cyber defense to achieve cyber resilience, in 2017 IEEE 14th International Scientific Conference on Informatics (IEEE, 2017), pp. 87\u201393","DOI":"10.1109\/INFORMATICS.2017.8327227"},{"key":"1290_CR27","doi-asserted-by":"crossref","unstructured":"Craigen, D., Diakun-Thibault, N., Purse, R.: Defining cybersecurity. Technol. Innov. Manag. Rev. 4(10), (2014)","DOI":"10.22215\/timreview\/835"},{"key":"1290_CR28","unstructured":"Diogenes, Y., Ozkaya, E.: Cybersecurity-attack and defense strategies: Infrastructure security with red team and blue team tactics, Packt Publishing Ltd (2018)"},{"issue":"6","key":"1290_CR29","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3538704","volume":"55","author":"S Roy","year":"2022","unstructured":"Roy, S., Sharmin, N., Acosta, J.C., Kiekintveld, C., Laszka, A.: Survey and taxonomy of adversarial reconnaissance techniques. ACM Comput. Surv. 55(6), 1\u201338 (2022)","journal-title":"ACM Comput. Surv."},{"key":"1290_CR30","doi-asserted-by":"crossref","unstructured":"King, S.T., Chen, P.M.: SubVirt: Implementing malware with virtual machines, in 2006 IEEE Symposium on Security and Privacy (S&P\u201906) (IEEE, 2006), pp. 14\u2013pp","DOI":"10.1109\/SP.2006.38"},{"key":"1290_CR31","doi-asserted-by":"publisher","first-page":"40281","DOI":"10.1109\/ACCESS.2022.3165809","volume":"10","author":"MA Ferrag","year":"2022","unstructured":"Ferrag, M.A., Friha, O., Hamouda, D., Maglaras, L., Janicke, H.: Edge-iiotset: A new comprehensive realistic cyber security dataset of iot and iiot applications for centralized and federated learning. IEEE Access 10, 40281\u201340306 (2022)","journal-title":"IEEE Access"},{"issue":"16","key":"1290_CR32","doi-asserted-by":"publisher","first-page":"7738","DOI":"10.3390\/app11167738","volume":"11","author":"K Kim","year":"2021","unstructured":"Kim, K., Alfouzan, F.A., Kim, H.: Cyber-attack scoring model based on the offensive cybersecurity framework. Appl. Sci. 11(16), 7738 (2021)","journal-title":"Appl. Sci."},{"key":"1290_CR33","doi-asserted-by":"crossref","unstructured":"Lee, S., Tsai, M., Shieh, S.W.: The game of spear and shield in next era of cybersecurity. IEEE Trans. Reliab. , (2023)","DOI":"10.1109\/TR.2023.3342874"},{"issue":"5","key":"1290_CR34","first-page":"390","volume":"15","author":"M Uma","year":"2013","unstructured":"Uma, M., Padmavathi, G.: A survey on various cyber attacks and their classification. Int. J. Netw. Secur. 15(5), 390\u2013396 (2013)","journal-title":"Int. J. Netw. Secur."},{"issue":"2","key":"1290_CR35","doi-asserted-by":"publisher","first-page":"1851","DOI":"10.1109\/COMST.2019.2891891","volume":"21","author":"A Alshamrani","year":"2019","unstructured":"Alshamrani, A., Myneni, S., Chowdhary, A., Huang, D.: A survey on advanced persistent threats: Techniques, solutions, challenges, and research opportunities. IEEE Communications Surveys & Tutorials 21(2), 1851\u20131877 (2019)","journal-title":"IEEE Communications Surveys & Tutorials"},{"issue":"4","key":"1290_CR36","first-page":"5054","volume":"4","author":"I Ghafir","year":"2014","unstructured":"Ghafir, I., Prenosil, V., et al.: Advanced persistent threat attack detection: an overview. Int J Adv Comput Netw Secur 4(4), 5054 (2014)","journal-title":"Int J Adv Comput Netw Secur"},{"key":"1290_CR37","doi-asserted-by":"crossref","unstructured":"Jaafar, F., Nicolescu, G., Richard, C.: A systematic approach for privilege escalation prevention, in 2016 IEEE International Conference on Software Quality, Reliability and Security Companion (QRS-C) (IEEE, 2016), pp. 101\u2013108","DOI":"10.1109\/QRS-C.2016.17"},{"key":"1290_CR38","doi-asserted-by":"publisher","first-page":"20111","DOI":"10.1109\/ACCESS.2017.2757944","volume":"5","author":"LX Yang","year":"2017","unstructured":"Yang, L.X., Li, P., Yang, X., Tang, Y.Y.: Security evaluation of the cyber networks under advanced persistent threats. IEEE access 5, 20111\u201320123 (2017)","journal-title":"IEEE access"},{"issue":"1","key":"1290_CR39","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1186\/s42400-019-0038-7","volume":"2","author":"A Khraisat","year":"2019","unstructured":"Khraisat, A., Gondal, I., Vamplew, P., Kamruzzaman, J.: Survey of intrusion detection systems: techniques, datasets and challenges. Cybersecurity 2(1), 1\u201322 (2019)","journal-title":"Cybersecurity"},{"key":"1290_CR40","doi-asserted-by":"publisher","first-page":"148","DOI":"10.1016\/j.future.2020.04.013","volume":"110","author":"M Pawlicki","year":"2020","unstructured":"Pawlicki, M., Chora\u015b, M., Kozik, R.: Defending network intrusion detection systems against adversarial evasion attacks. Futur. Gener. Comput. Syst. 110, 148\u2013154 (2020)","journal-title":"Futur. Gener. Comput. Syst."},{"key":"1290_CR41","doi-asserted-by":"crossref","unstructured":"Liu, Q., Bao, K., Hagenmeyer, V.: Aviator: A MITRE Emulation Plan-Derived Living Dataset for Advanced Persistent Threat Detection and Investigation, in 2024 IEEE International Conference on Big Data (BigData) (IEEE, 2024), pp. 5610\u20135619","DOI":"10.1109\/BigData62323.2024.10826006"},{"issue":"4","key":"1290_CR42","doi-asserted-by":"publisher","first-page":"653","DOI":"10.3390\/sym12040653","volume":"12","author":"G Apruzzese","year":"2020","unstructured":"Apruzzese, G., Andreolini, M., Marchetti, M., Colacino, V.G., Russo, G.: Appcon: Mitigating evasion attacks to ml cyber detectors. Symmetry 12(4), 653 (2020)","journal-title":"Symmetry"},{"key":"1290_CR43","doi-asserted-by":"crossref","unstructured":"Rajesh, P., Alam, M., Tahernezhadi, M., Monika, A., Chanakya, G.: Analysis of cyber threat detection and emulation using mitre attack framework, in 2022 International Conference on Intelligent Data Science Technologies and Applications (IDSTA) (IEEE, 2022), pp. 4\u201312","DOI":"10.1109\/IDSTA55301.2022.9923170"},{"issue":"1","key":"1290_CR44","doi-asserted-by":"publisher","first-page":"157","DOI":"10.1007\/s10270-021-00898-7","volume":"21","author":"W Xiong","year":"2022","unstructured":"Xiong, W., Legrand, E., \u00c5berg, O., Lagerstr\u00f6m, R.: Cyber security threat modeling based on the mitre enterprise att&ck matrix. Softw. Syst. Model. 21(1), 157\u2013177 (2022)","journal-title":"Softw. Syst. Model."},{"key":"1290_CR45","doi-asserted-by":"crossref","unstructured":"Liu, Q., Stokes, J.W., Mead, R., Burrell, T., Hellen, I., Lambert, J., Marochko, A., Cui, W.: Latte: Large-scale lateral movement detection, in MILCOM 2018-2018 IEEE Military Communications Conference (MILCOM) (IEEE, 2018), pp. 1\u20136","DOI":"10.1109\/MILCOM.2018.8599748"},{"key":"1290_CR46","doi-asserted-by":"crossref","unstructured":"Mundt, M., Baier, H.: Towards mitigation of data exfiltration techniques using the MITRE ATT&CK framework, in International Conference on Digital Forensics and Cyber Crime (Springer, 2021), pp. 139\u2013158","DOI":"10.1007\/978-3-031-06365-7_9"},{"key":"1290_CR47","unstructured":"Datta, P., Lodinger, N., Namin, A.S., Jones, K.S.: Cyber-attack consequence prediction, (2020). arXiv preprint arXiv:2012.00648"},{"issue":"2","key":"1290_CR48","first-page":"109","volume":"1","author":"C Ashley","year":"2022","unstructured":"Ashley, C., Preiksaitis, M.: Strategic cybersecurity risk management practices for information in small and medium enterprises. Business Management Research and Applications: A Cross-Disciplinary Journal 1(2), 109\u2013157 (2022)","journal-title":"Business Management Research and Applications: A Cross-Disciplinary Journal"},{"key":"1290_CR49","doi-asserted-by":"crossref","unstructured":"Belalc\u00e1zar, A., Ron, M., D\u00edaz, J., Molinari, L.: Towards a strategic resilience of applications through the NIST cybersecurity framework and the strategic alignment model (SAM), in 2017 International Conference on Information Systems and Computer Science (INCISCOS) (IEEE, 2017), pp. 181\u2013187","DOI":"10.1109\/INCISCOS.2017.29"},{"key":"1290_CR50","doi-asserted-by":"crossref","unstructured":"Bokan, B., Santos, J.: Managing cybersecurity risk using threat based methodology for evaluation of cybersecurity architectures, in 2021 Systems and Information Engineering Design Symposium (SIEDS) (IEEE, 2021), pp. 1\u20136","DOI":"10.1109\/SIEDS52267.2021.9483736"},{"key":"1290_CR51","doi-asserted-by":"crossref","unstructured":"Brown, G.G., Carlyle, W.M., Salmeron, J., Wood, K.: in Emerging Theory, Methods, and Applications (Informs, 2005), pp. 102\u2013123","DOI":"10.1287\/educ.1053.0018"},{"issue":"8","key":"1290_CR52","doi-asserted-by":"publisher","first-page":"597","DOI":"10.1016\/j.ijmedinf.2005.08.010","volume":"75","author":"B Blobel","year":"2006","unstructured":"Blobel, B., Nordberg, R., Davis, J.M., Pharow, P.: Modelling privilege management and access control. Int. J. Med. Informatics 75(8), 597\u2013623 (2006)","journal-title":"Int. J. Med. Informatics"},{"key":"1290_CR53","doi-asserted-by":"crossref","unstructured":"Agrafiotis, I., Nurse, J.R., Goldsmith, M., Creese, S., Upton, D.: A taxonomy of cyber-harms: Defining the impacts of cyber-attacks and understanding how they propagate. Journal of Cybersecurity 4(1), tyy006 (2018)","DOI":"10.1093\/cybsec\/tyy006"},{"issue":"4","key":"1290_CR54","doi-asserted-by":"publisher","first-page":"2525","DOI":"10.1109\/COMST.2021.3117338","volume":"23","author":"D Schlette","year":"2021","unstructured":"Schlette, D., Caselli, M., Pernul, G.: A comparative study on cyber threat intelligence: The security incident response perspective. IEEE Communications Surveys & Tutorials 23(4), 2525\u20132556 (2021)","journal-title":"IEEE Communications Surveys & Tutorials"},{"key":"1290_CR55","doi-asserted-by":"crossref","unstructured":"Ioannou, M., Stavrou, E., Bada, M.: Cybersecurity culture in computer security incident response teams: Investigating difficulties in communication and coordination, in 2019 International Conference on Cyber Security and Protection of Digital Services (Cyber Security) (IEEE, 2019), pp. 1\u20134","DOI":"10.1109\/CyberSecPODS.2019.8885240"},{"issue":"3","key":"1290_CR56","doi-asserted-by":"publisher","first-page":"2476","DOI":"10.1109\/TSG.2019.2956161","volume":"11","author":"F Wei","year":"2019","unstructured":"Wei, F., Wan, Z., He, H.: Cyber-attack recovery strategy for smart grid based on deep reinforcement learning. IEEE Transactions on Smart Grid 11(3), 2476\u20132486 (2019)","journal-title":"IEEE Transactions on Smart Grid"},{"key":"1290_CR57","doi-asserted-by":"crossref","unstructured":"Perera, S., Jin, X., Maurushat, A., Opoku, D.G.J.: Factors affecting reputational damage to organisations due to cyberattacks, in Informatics, vol.\u00a09 (MDPI, 2022), p.\u00a028","DOI":"10.3390\/informatics9010028"},{"key":"1290_CR58","doi-asserted-by":"publisher","first-page":"1206","DOI":"10.1109\/ACCESS.2015.2461602","volume":"3","author":"A Gupta","year":"2015","unstructured":"Gupta, A., Jha, R.K.: A survey of 5g network: Architecture and emerging technologies. IEEE access 3, 1206\u20131232 (2015)","journal-title":"IEEE access"},{"key":"1290_CR59","unstructured":"Samarakoon, S., Siriwardhana, Y., Porambage, P., Liyanage, M., Chang, S.Y., Kim, J., Kim, J., Ylianttila, M.: 5g-nidd: A comprehensive network intrusion detection dataset generated over 5g wireless network. arXiv preprint arXiv:2212.01298 (2022)"},{"key":"1290_CR60","doi-asserted-by":"crossref","unstructured":"Tavallaee, M., Bagheri, E., Lu, W., Ghorbani, A.A.: A detailed analysis of the KDD CUP 99 data set, in 2009 IEEE symposium on computational intelligence for security and defense applications (Ieee, 2009), pp. 1\u20136","DOI":"10.1109\/CISDA.2009.5356528"},{"issue":"4","key":"1290_CR61","doi-asserted-by":"publisher","first-page":"262","DOI":"10.1145\/382912.382923","volume":"3","author":"J McHugh","year":"2000","unstructured":"McHugh, J.: Testing intrusion detection systems: a critique of the 1998 and 1999 darpa intrusion detection system evaluations as performed by lincoln laboratory. ACM Transactions on Information and System Security (TISSEC) 3(4), 262\u2013294 (2000)","journal-title":"ACM Transactions on Information and System Security (TISSEC)"},{"key":"1290_CR62","doi-asserted-by":"crossref","unstructured":"Sharafaldin, I., Lashkari, A.H., Hakak, S., Ghorbani, A.A.: Developing realistic distributed denial of service (DDoS) attack dataset and taxonomy, in 2019 International Carnahan Conference on Security Technology (ICCST) (IEEE, 2019), pp. 1\u20138","DOI":"10.1109\/CCST.2019.8888419"},{"key":"1290_CR63","doi-asserted-by":"publisher","first-page":"106576","DOI":"10.1109\/ACCESS.2020.3000421","volume":"8","author":"AA Hady","year":"2020","unstructured":"Hady, A.A., Ghubaish, A., Salman, T., Unal, D., Jain, R.: Intrusion detection system for healthcare systems using medical and network data: A comparison study. IEEE Access 8, 106576\u2013106584 (2020)","journal-title":"IEEE Access"},{"key":"1290_CR64","doi-asserted-by":"publisher","DOI":"10.1016\/j.adhoc.2021.102621","volume":"122","author":"M Ahmed","year":"2021","unstructured":"Ahmed, M., Byreddy, S., Nutakki, A., Sikos, L.F., Haskell-Dowland, P.: Ecu-ioht: A dataset for analyzing cyberattacks in internet of health things. Ad Hoc Netw. 122, 102621 (2021)","journal-title":"Ad Hoc Netw."},{"key":"1290_CR65","doi-asserted-by":"publisher","DOI":"10.1016\/j.iot.2024.101351","volume":"28","author":"S Dadkhah","year":"2024","unstructured":"Dadkhah, S., Neto, E.C.P., Ferreira, R., Molokwu, R.C., Sadeghi, S., Ghorbani, A.A.: Ciciomt 2024: A benchmark dataset for multi-protocol security assessment in iomt. Internet of Things 28, 101351 (2024)","journal-title":"Internet of Things"},{"issue":"13","key":"1290_CR66","doi-asserted-by":"publisher","first-page":"5941","DOI":"10.3390\/s23135941","volume":"23","author":"ECP Neto","year":"2023","unstructured":"Neto, E.C.P., Dadkhah, S., Ferreira, R., Zohourian, A., Lu, R., Ghorbani, A.A.: Ciciot 2023: A real-time dataset and benchmark for large-scale attacks in iot environment. Sensors 23(13), 5941 (2023)","journal-title":"Sensors"},{"key":"1290_CR67","doi-asserted-by":"crossref","unstructured":"Neto, E.C.P., Taslimasa, H., Dadkhah, S., Iqbal, S., Xiong, P., Rahman, T., Ghorbani, A.A.: Ciciov2024: Advancing realistic ids approaches against dos and spoofing attack in iov can bus. Internet of Things. 101209 (2024)","DOI":"10.1016\/j.iot.2024.101209"},{"key":"1290_CR68","doi-asserted-by":"publisher","first-page":"165263","DOI":"10.1109\/ACCESS.2020.3022633","volume":"8","author":"MS Elsayed","year":"2020","unstructured":"Elsayed, M.S., Le-Khac, N.A., Jurcut, A.D.: Insdn: A novel sdn intrusion dataset. Ieee Access 8, 165263\u2013165284 (2020)","journal-title":"Ieee Access"},{"key":"1290_CR69","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2021.107524","volume":"233","author":"I Sarhan","year":"2021","unstructured":"Sarhan, I., Spruit, M.: Open-cykg: An open cyber threat intelligence knowledge graph. Knowl.-Based Syst. 233, 107524 (2021)","journal-title":"Knowl.-Based Syst."},{"key":"1290_CR70","doi-asserted-by":"crossref","unstructured":"Li, Z., Zeng, J., Chen, Y., Liang, Z.: AttacKG: Constructing technique knowledge graph from cyber threat intelligence reports, in European Symposium on Research in Computer Security (Springer, 2022), pp. 589\u2013609","DOI":"10.1007\/978-3-031-17140-6_29"},{"key":"1290_CR71","unstructured":"Agrawal, G., Pal, K., Deng, Y., Liu, H., Baral, C.: Aiseckg: Knowledge graph dataset for cybersecurity education. AAAI-MAKE 2023: Challenges Requiring the Combination of Machine Learning, p. 2023. (2023)"},{"key":"1290_CR72","doi-asserted-by":"crossref","unstructured":"Doldy, D., Garridoy, J.S.: An energy-based model for neuro-symbolic reasoning on knowledge graphs, in 2021 20th IEEE International Conference on Machine Learning and Applications (ICMLA) (IEEE, 2021), pp. 916\u2013921","DOI":"10.1109\/ICMLA52953.2021.00151"},{"key":"1290_CR73","doi-asserted-by":"crossref","unstructured":"Liu, Z., Su, H., Wang, N., Huang, C.: Coreference Resolution for Cybersecurity Entity: Towards Explicit, Comprehensive Cybersecurity Knowledge Graph with Low Redundancy, in International Conference on Security and Privacy in Communication Systems (Springer, 2022), pp. 89\u2013108","DOI":"10.1007\/978-3-031-25538-0_6"},{"key":"1290_CR74","unstructured":"Varga, A., Hornig, R.: An overview of the OMNeT++ simulation environment, in 1st International ICST Conference on Simulation Tools and Techniques for Communications, Networks and Systems (2010)"},{"issue":"14","key":"1290_CR75","first-page":"527","volume":"14","author":"TR Henderson","year":"2008","unstructured":"Henderson, T.R., Lacage, M., Riley, G.F., Dowell, C., Kopena, J.: Network simulations with the ns-3 simulator. SIGCOMM demonstration 14(14), 527 (2008)","journal-title":"SIGCOMM demonstration"},{"issue":"13","key":"1290_CR76","doi-asserted-by":"publisher","first-page":"1397","DOI":"10.1002\/cpe.1867","volume":"24","author":"A Beloglazov","year":"2012","unstructured":"Beloglazov, A., Buyya, R.: Optimal online deterministic algorithms and adaptive heuristics for energy and performance efficient dynamic consolidation of virtual machines in cloud data centers. Concurrency and Computation: Practice and Experience 24(13), 1397\u20131420 (2012)","journal-title":"Concurrency and Computation: Practice and Experience"},{"key":"1290_CR77","unstructured":"Gnatyuk, S., Berdibayev, R., Avkurova, Z., Verkhovets, O., Bauyrzhan, M.: Studies on Cloud-based Cyber Incidents Detection and Identification in Critical Infrastructure., in CPITS, pp. 68\u201380 (2021)"},{"key":"1290_CR78","doi-asserted-by":"crossref","unstructured":"Symeonides, M., Georgiou, Z., Trihinas, D., Pallis, G., Dikaiakos, M.D.: Fogify: A fog computing emulation framework, in 2020 IEEE\/ACM Symposium on Edge Computing (SEC) (IEEE, 2020), pp. 42\u201354","DOI":"10.1109\/SEC50012.2020.00011"},{"issue":"9","key":"1290_CR79","first-page":"1275","volume":"47","author":"H Gupta","year":"2017","unstructured":"Gupta, H., Vahid Dastjerdi, A., Ghosh, S.K., Buyya, R.: ifogsim: A toolkit for modeling and simulation of resource management techniques in the internet of things, edge and fog computing environments. Software: Practice and Experience 47(9), 1275\u20131296 (2017)","journal-title":"Software: Practice and Experience"},{"issue":"6","key":"1290_CR80","doi-asserted-by":"publisher","first-page":"1981","DOI":"10.1109\/TSC.2019.2914649","volume":"14","author":"A Singh","year":"2019","unstructured":"Singh, A., Auluck, N., Rana, O., Jones, A., Nepal, S.: Scheduling real-time security aware tasks in fog networks. IEEE Trans. Serv. Comput. 14(6), 1981\u20131994 (2019)","journal-title":"IEEE Trans. Serv. Comput."},{"issue":"10","key":"1290_CR81","doi-asserted-by":"publisher","first-page":"2899","DOI":"10.1016\/j.jpdc.2014.06.008","volume":"74","author":"H Casanova","year":"2014","unstructured":"Casanova, H., Giersch, A., Legrand, A., Quinson, M., Suter, F.: Versatile, scalable, and accurate simulation of distributed applications and platforms. Journal of Parallel and Distributed Computing 74(10), 2899\u20132917 (2014). (http:\/\/hal.inria.fr\/hal-01017319)","journal-title":"Journal of Parallel and Distributed Computing"},{"key":"1290_CR82","doi-asserted-by":"crossref","unstructured":"Lantz, B., Heller, B., McKeown, N.: A network in a laptop: rapid prototyping for software-defined networks, in Proceedings of the 9th ACM SIGCOMM Workshop on Hot Topics in Networks, pp. 1\u20136 (2010)","DOI":"10.1145\/1868447.1868466"},{"key":"1290_CR83","doi-asserted-by":"crossref","unstructured":"Fontes, R.R., Afzal, S., Brito, S.H., Santos, M.A., Rothenberg, C.E.: Mininet-WiFi: Emulating software-defined wireless networks, in 2015 11th International Conference on Network and Service Management (CNSM) (IEEE, 2015), pp. 384\u2013389","DOI":"10.1109\/CNSM.2015.7367387"},{"key":"1290_CR84","doi-asserted-by":"crossref","unstructured":"Wette, P., Dr\u00e4xler, M., Schwabe, A., Wallaschek, F., Zahraee, M.H., Karl, H.: Maxinet: Distributed emulation of software-defined networks, in 2014 IFIP Networking Conference (IEEE, 2014), pp. 1\u20139","DOI":"10.1109\/IFIPNetworking.2014.6857078"},{"key":"1290_CR85","doi-asserted-by":"crossref","unstructured":"McGregor, I.: The relationship between simulation and emulation, in Proceedings of the Winter Simulation Conference, vol.\u00a02 (IEEE, 2002), pp. 1683\u20131688","DOI":"10.1109\/WSC.2002.1166451"},{"key":"1290_CR86","doi-asserted-by":"crossref","unstructured":"Janisch, J., Pevn\u1ef3, T., Lis\u1ef3, V.: Nasimemu: Network attack simulator & emulator for training agents generalizing to novel scenarios. arXiv preprint arXiv:2305.17246 (2023)","DOI":"10.1007\/978-3-031-54129-2_35"},{"issue":"3","key":"1290_CR87","doi-asserted-by":"publisher","first-page":"2333","DOI":"10.1109\/TNSM.2022.3176781","volume":"19","author":"K Hammar","year":"2022","unstructured":"Hammar, K., Stadler, R.: Intrusion prevention through optimal stopping. IEEE Trans. Netw. Serv. Manage. 19(3), 2333\u20132348 (2022)","journal-title":"IEEE Trans. Netw. Serv. Manage."},{"key":"1290_CR88","unstructured":"Team, M.D.R.: Cyberbattlesim. (2021). Created by Christian Seifert, Michael Betser, William Blum, James Bono, Kate Farris, Emily Goren, Justin Grana, Kristian Holsheimer, Brandon Marken, Joshua Neil, Nicole Nichols, Jugal Parikh, Haoran Wei https:\/\/github.com\/microsoft\/cyberbattlesim"},{"key":"1290_CR89","unstructured":"Standen, M., Lucas, M., Bowman, D., Richer, T.J., Kim, J., Marriott, D.: Cyborg: A gym for the development of autonomous cyber agents, (2021). arXiv preprint arXiv:2108.09118"},{"key":"1290_CR90","unstructured":"Li, L., Fayad, R., Taylor, A.: Cygil: A cyber gym for training autonomous agents over emulated network systems, (2021). arXiv preprint arXiv:2109.03331"},{"key":"1290_CR91","doi-asserted-by":"crossref","unstructured":"Akbari, I., Tahoun, E., Salahuddin, M.A., Limam, N., Boutaba, R.: ATMoS: Autonomous threat mitigation in SDN using reinforcement learning, in NOMS 2020-2020 IEEE\/IFIP Network Operations and Management Symposium (IEEE, 2020), pp. 1\u20139","DOI":"10.1109\/NOMS47738.2020.9110426"},{"key":"1290_CR92","doi-asserted-by":"crossref","unstructured":"Lanier, M., Vorobeychik, Y.: CyGym: A simulation-based game-theoretic analysis framework for cybersecurity, in International Conference on Game Theory and AI for Security (Springer, 2025), pp. 143\u2013171","DOI":"10.1007\/978-3-032-08064-6_8"},{"key":"1290_CR93","unstructured":"Zhu, Y., Kellermann, A., Bowman, D., Li, P., Gupta, A., Danda, A., Fang, R., Jensen, C., Ihli, E., Benn, J.: Cve-bench: a benchmark for ai agents\u2019 ability to exploit real-world web application vulnerabilities, (2025). arXiv preprint arXiv:2503.17332"},{"key":"1290_CR94","unstructured":"Zhang, A.K., Perry, N., Dulepet, R., Ji, J., Menders, C., Lin, J.W., Jones, E., Hussein, G., Liu, S., Jasper, D.: Cybench: A framework for evaluating cybersecurity capabilities and risks of language models, (2024). arXiv preprint arXiv:2408.08926"},{"key":"1290_CR95","doi-asserted-by":"crossref","unstructured":"Tihanyi, N., Ferrag, M.A., Jain, R., Bisztray, T., Debbah, M.: Cybermetric: A benchmark dataset based on retrieval-augmented generation for evaluating llms in cybersecurity knowledge, in 2024 IEEE International Conference on Cyber Security and Resilience (CSR) (IEEE, 2024), pp. 296\u2013302","DOI":"10.1109\/CSR61664.2024.10679494"},{"key":"1290_CR96","unstructured":"Bhatt, M., Chennabasappa, S., Li, Y., Nikolaidis, C., Song, D., Wan, S., Ahmad, F., Aschermann, C., Chen, Y., Kapil, D.: Cyberseceval 2: A wide-ranging cybersecurity evaluation suite for large language models, (2024). arXiv preprint arXiv:2404.13161"},{"key":"1290_CR97","doi-asserted-by":"crossref","unstructured":"Hou, B., Cai, Z., Wu, K., Su, J., Xiong, Y.: 6Hit: A reinforcement learning-based approach to target generation for Internet-wide IPv6 scanning, in IEEE INFOCOM 2021-IEEE Conference on Computer Communications (IEEE, 2021), pp. 1\u201310","DOI":"10.1109\/INFOCOM42981.2021.9488794"},{"key":"1290_CR98","doi-asserted-by":"crossref","unstructured":"Belalis, I., Spathoulas, G.P., Anagnostopoulos, I.: Evading Detection During Network Reconnaissance., in ICISSP, pp. 528\u2013534 (2023)","DOI":"10.5220\/0011685900003405"},{"issue":"7","key":"1290_CR99","doi-asserted-by":"publisher","first-page":"818","DOI":"10.3390\/electronics10070818","volume":"10","author":"P Koloveas","year":"2021","unstructured":"Koloveas, P., Chantzios, T., Alevizopoulou, S., Skiadopoulos, S., Tryfonopoulos, C.: intime: A machine learning-based framework for gathering and leveraging web data to cyber-threat intelligence. Electronics 10(7), 818 (2021)","journal-title":"Electronics"},{"key":"1290_CR100","doi-asserted-by":"crossref","unstructured":"Leevy, J.L., Hancock, J., Khoshgoftaar, T.M., Seliya, N.: Iot reconnaissance attack classification with random undersampling and ensemble feature selection, in 2021 IEEE 7th International Conference on Collaboration and Internet Computing (CIC) (IEEE, 2021), pp. 41\u201349","DOI":"10.1109\/CIC52973.2021.00016"},{"key":"1290_CR101","doi-asserted-by":"crossref","unstructured":"Viet, H.N., Van, Q.N., Trang, L.L.T., Nathan, S.: Using deep learning model for network scanning detection, in Proceedings of the 4th International Conference on Frontiers of Educational Technologies, pp. 117\u2013121 (2018)","DOI":"10.1145\/3233347.3233379"},{"key":"1290_CR102","doi-asserted-by":"crossref","unstructured":"Nhu, N.X., Nghia, T.T., Quyen, N.H., Pham, V.H., Duy, P.T., et\u00a0al.: Leveraging Deep Reinforcement Learning for Automating Penetration Testing in Reconnaissance and Exploitation Phase, in 2022 RIVF International Conference on Computing and Communication Technologies (RIVF) (IEEE, 2022), pp. 41\u201346","DOI":"10.1109\/RIVF55975.2022.10013801"},{"key":"1290_CR103","doi-asserted-by":"crossref","unstructured":"Sehwag, V., Bhagoji, A.N., Song, L., Sitawarin, C., Cullina, D., Chiang, M., Mittal, P.: Analyzing the robustness of open-world machine learning, in Proceedings of the 12th ACM Workshop on Artificial Intelligence and Security, pp. 105\u2013116 (2019)","DOI":"10.1145\/3338501.3357372"},{"key":"1290_CR104","unstructured":"Song, W., Li, X., Afroz, S., Garg, D., Kuznetsov, D., Yin, H.: Mab-malware: A reinforcement learning framework for attacking static malware classifiers, (2020). arXiv preprint arXiv:2003.03100"},{"key":"1290_CR105","doi-asserted-by":"crossref","unstructured":"Rigaki, M., Garcia, S.: The Power of MEME: Adversarial Malware Creation with Model-Based Reinforcement Learning, in European Symposium on Research in Computer Security (Springer, 2023), pp. 44\u201364","DOI":"10.1007\/978-3-031-51482-1_3"},{"key":"1290_CR106","doi-asserted-by":"crossref","unstructured":"Ebrahimi, M., Pacheco, J., Li, W., Hu, J.L., Chen, H.: Binary black-box attacks against static malware detectors with reinforcement learning in discrete action spaces, in 2021 IEEE Security and Privacy Workshops (SPW) (IEEE, 2021), pp. 85\u201391","DOI":"10.1109\/SPW53761.2021.00021"},{"key":"1290_CR107","doi-asserted-by":"crossref","unstructured":"Rigaki, M., Garcia, S.: Bringing a GAN to a knife-fight: Adapting malware communication to avoid detection, in 2018 IEEE Security and Privacy Workshops (SPW) (IEEE, 2018), pp. 70\u201375","DOI":"10.1109\/SPW.2018.00019"},{"key":"1290_CR108","doi-asserted-by":"crossref","unstructured":"Zhong, F., Cheng, X., Yu, D., Gong, B., Song, S., Yu, J.: Malfox: Camouflaged adversarial malware example generation based on conv-gans against black-box detectors. IEEE Transactions on Computers (2023)","DOI":"10.1109\/TC.2023.3236901"},{"key":"1290_CR109","doi-asserted-by":"crossref","unstructured":"Peppes, N., Alexakis, T., Daskalakis, E., Demestichas, K., Adamopoulou, E.: Malware image generation and detection method using dcgans and transfer learning. IEEE Access , (2023)","DOI":"10.1109\/ACCESS.2023.3319436"},{"key":"1290_CR110","unstructured":"Kamran, S.A., Sengupta, S., Tavakkoli, A.: Semi-supervised conditional gan for simultaneous generation and detection of phishing urls: A game theoretic perspective, (2021). arXiv:2108.01852 arXiv preprint"},{"key":"1290_CR111","doi-asserted-by":"crossref","unstructured":"AlEroud, A., Karabatis, G.: Bypassing detection of URL-based phishing attacks using generative adversarial deep neural networks, in Proceedings of the sixth international workshop on security and privacy analytics, pp. 53\u201360 (2020)","DOI":"10.1145\/3375708.3380315"},{"key":"1290_CR112","doi-asserted-by":"crossref","unstructured":"Al-Qurashi, R., AlEroud, A., Saifan, A.A., Alsmadi, M., Alsmadi, I.: Generating Optimal Attack Paths in Generative Adversarial Phishing, in 2021 IEEE International Conference on Intelligence and Security Informatics (ISI) (IEEE, 2021), pp. 1\u20136","DOI":"10.1109\/ISI53945.2021.9624751"},{"issue":"4","key":"1290_CR113","doi-asserted-by":"publisher","first-page":"109","DOI":"10.1007\/s11229-023-04334-9","volume":"202","author":"T Freiesleben","year":"2023","unstructured":"Freiesleben, T., Grote, T.: Beyond generalization: a theory of robustness in machine learning. Synthese 202(4), 109 (2023)","journal-title":"Synthese"},{"key":"1290_CR114","doi-asserted-by":"publisher","first-page":"67","DOI":"10.1016\/j.jss.2017.11.001","volume":"137","author":"R Yan","year":"2018","unstructured":"Yan, R., Xiao, X., Hu, G., Peng, S., Jiang, Y.: New deep learning method to detect code injection attacks on hybrid applications. J. Syst. Softw. 137, 67\u201377 (2018)","journal-title":"J. Syst. Softw."},{"key":"1290_CR115","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2021.102903","volume":"61","author":"L Erd\u0151di","year":"2021","unstructured":"Erd\u0151di, L., Sommervoll, \u00c5.\u00c5., Zennaro, F.M.: Simulating sql injection vulnerability exploitation using q-learning reinforcement learning agents. Journal of Information Security and Applications 61, 102903 (2021)","journal-title":"Journal of Information Security and Applications"},{"issue":"1","key":"1290_CR116","doi-asserted-by":"publisher","first-page":"225","DOI":"10.1007\/s10207-023-00738-3","volume":"23","author":"\u00c5\u00c5 Sommervoll","year":"2024","unstructured":"Sommervoll, \u00c5.\u00c5., Erd\u0151di, L., Zennaro, F.M.: Simulating all archetypes of sql injection vulnerability exploitation using reinforcement learning agents. Int. J. Inf. Secur. 23(1), 225\u2013246 (2024)","journal-title":"Int. J. Inf. Secur."},{"key":"1290_CR117","doi-asserted-by":"publisher","first-page":"128617","DOI":"10.1109\/ACCESS.2019.2939870","volume":"7","author":"S Abaimov","year":"2019","unstructured":"Abaimov, S., Bianchi, G.: Coddle: Code-injection detection with deep learning. IEEE Access 7, 128617\u2013128627 (2019)","journal-title":"IEEE Access"},{"key":"1290_CR118","doi-asserted-by":"crossref","unstructured":"Burgos-Mellado, C., Zu\u00f1iga-Bauerle, C., Mu\u00f1oz-Carpintero, D., Arias-Esquivel, Y., C\u00e0rdenas-Dobson, R., Dragi\u010cevi\u0107, T., Donoso, F., Watson, A.: Reinforcement learning-based method to exploit vulnerabilities of false data injection attack detectors in modular multilevel converters. IEEE Transactions on Power Electronics (2023)","DOI":"10.1109\/TPEL.2023.3263728"},{"key":"1290_CR119","unstructured":"Bengio, Y., Mindermann, S., Privitera, D., Besiroglu, T., Bommasani, R., Casper, S., Choi, Y., Fox, P., Garfinkel, B., Goldfarb, D.: International ai safety report, (2025). arXiv preprint arXiv:2501.17805"},{"key":"1290_CR120","doi-asserted-by":"crossref","unstructured":"Komiya, R., Paik, I., Hisada, M.: Classification of malicious web code by machine learning, in 2011 3rd International Conference on Awareness Science and Technology (iCAST) (IEEE, 2011), pp. 406\u2013411","DOI":"10.1109\/ICAwST.2011.6163109"},{"key":"1290_CR121","doi-asserted-by":"crossref","unstructured":"Tommy, R., Sundeep, G., Jose, H.: Automatic detection and correction of vulnerabilities using machine learning, in 2017 International Conference on Current Trends in Computer, Electrical, Electronics and Communication (CTCEEC) (IEEE, 2017), pp. 1062\u20131065","DOI":"10.1109\/CTCEEC.2017.8454995"},{"key":"1290_CR122","doi-asserted-by":"crossref","unstructured":"AlMajali, A., Al-Abed, L., Mutleq, R., Samamah, Z., Shhadeh, A.A., Mohd, B.J., Yousef, K.M.A.: Vulnerability Exploitation Using Reinforcement Learning, in 2023 IEEE Jordan International Joint Conference on Electrical Engineering and Information Technology (JEEIT) (IEEE, 2023), pp. 281\u2013286","DOI":"10.1109\/JEEIT58638.2023.10185700"},{"key":"1290_CR123","doi-asserted-by":"crossref","unstructured":"Solano, J., Lopez, C., Rivera, E., Castelblanco, A., Tengana, L., Ochoa, M.: Scrap: synthetically composed replay attacks vs. adversarial machine learning attacks against mouse-based biometric authentication, in Proceedings of the 13th ACM Workshop on Artificial Intelligence and Security, pp. 37\u201347 (2020)","DOI":"10.1145\/3411508.3421378"},{"key":"1290_CR124","doi-asserted-by":"crossref","unstructured":"Wenger, E., Bronckers, M., Cianfarani, C., Cryan, J., Sha, A., Zheng, H., Zhao, B.Y.: Hello, It\u2019s Me: Deep Learning-based Speech Synthesis Attacks in the Real World, in Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security, pp. 235\u2013251 (2021)","DOI":"10.1145\/3460120.3484742"},{"key":"1290_CR125","doi-asserted-by":"crossref","unstructured":"Lee, J.G., Roh, Y., Song, H., Whang, S.E.: Machine learning robustness, fairness, and their convergence, in Proceedings of the 27th ACM SIGKDD conference on knowledge discovery & data mining, 4046\u20134047 (2021)","DOI":"10.1145\/3447548.3470799"},{"key":"1290_CR126","doi-asserted-by":"crossref","unstructured":"Kujanp\u00e4\u00e4, K., Victor, W.: A.\u00a0Ilin, Automating Privilege Escalation with Deep Reinforcement Learning, in Proceedings of the 14th ACM Workshop on Artificial Intelligence and Security, pp. 157\u2013168 (2021)","DOI":"10.1145\/3474369.3486877"},{"key":"1290_CR127","doi-asserted-by":"crossref","unstructured":"Mehmood, M., Amin, R., Muslam, M.M.A., Xie, J., Aldabbas, H.: Privilege escalation attack detection and mitigation in cloud using machine learning, IEEE Access (2023)","DOI":"10.1109\/ACCESS.2023.3273895"},{"key":"1290_CR128","doi-asserted-by":"publisher","DOI":"10.1016\/j.asoc.2020.106089","volume":"89","author":"S Sharmeen","year":"2020","unstructured":"Sharmeen, S., Huda, S., Abawajy, J., Hassan, M.M.: An adaptive framework against android privilege escalation threats using deep learning and semi-supervised approaches. Appl. Soft Comput. 89, 106089 (2020)","journal-title":"Appl. Soft Comput."},{"issue":"5","key":"1290_CR129","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3453158","volume":"54","author":"I Rosenberg","year":"2021","unstructured":"Rosenberg, I., Shabtai, A., Elovici, Y., Rokach, L.: Adversarial machine learning attacks and defense methods in the cyber security domain. ACM Computing Surveys (CSUR) 54(5), 1\u201336 (2021)","journal-title":"ACM Computing Surveys (CSUR)"},{"key":"1290_CR130","doi-asserted-by":"publisher","first-page":"48867","DOI":"10.1109\/ACCESS.2019.2908033","volume":"7","author":"Z Fang","year":"2019","unstructured":"Fang, Z., Wang, J., Li, B., Wu, S., Zhou, Y., Huang, H.: Evading anti-malware engines with deep reinforcement learning. IEEE Access 7, 48867\u201348879 (2019)","journal-title":"IEEE Access"},{"key":"1290_CR131","unstructured":"Quertier, T., Marais, B., Morucci, S., Fournel, B.: Merlin-malware evasion with reinforcement learning, (2022). arXiv preprint arXiv:2203.12980"},{"issue":"4","key":"1290_CR132","doi-asserted-by":"publisher","first-page":"1975","DOI":"10.1109\/TNSM.2020.3031843","volume":"17","author":"G Apruzzese","year":"2020","unstructured":"Apruzzese, G., Andreolini, M., Marchetti, M., Venturi, A., Colajanni, M.: Deep reinforcement adversarial learning against botnet evasion attacks. IEEE Trans. Netw. Serv. Manage. 17(4), 1975\u20131987 (2020)","journal-title":"IEEE Trans. Netw. Serv. Manage."},{"key":"1290_CR133","doi-asserted-by":"crossref","unstructured":"Hitaj, B., Gasti, P., Ateniese, G., Perez-Cruz, F.: Passgan: A deep learning approach for password guessing, in Applied Cryptography and Network Security: 17th International Conference, ACNS 2019, Bogota, Colombia, June 5\u20137, 2019, Proceedings 17 (Springer, 2019), pp. 217\u2013237","DOI":"10.1007\/978-3-030-21568-2_11"},{"key":"1290_CR134","doi-asserted-by":"crossref","unstructured":"Zhang, M., Zhang, Q., Hu, X., Liu, W.: A password cracking method based on structure partition and bilstm recurrent neural network, in Proceedings of the 8th International Conference on Communication and Network Security, pp. 79\u201383 (2018)","DOI":"10.1145\/3290480.3290501"},{"key":"1290_CR135","doi-asserted-by":"crossref","unstructured":"Chen, Z., Zhang, X.: A Reinforcement Learning-based Sequence Generation Algorithm for Password Guessing, in GLOBECOM 2022-2022 IEEE Global Communications Conference (IEEE, 2022), pp. 4891\u20134896","DOI":"10.1109\/GLOBECOM48099.2022.10000814"},{"issue":"5","key":"1290_CR136","doi-asserted-by":"publisher","first-page":"3371","DOI":"10.1109\/TDSC.2021.3095417","volume":"19","author":"M Amouei","year":"2021","unstructured":"Amouei, M., Rezvani, M., Fateh, M.: Rat: Reinforcement-learning-driven and adaptive testing for vulnerability discovery in web application firewalls. IEEE Trans. Dependable Secure Comput. 19(5), 3371\u20133386 (2021)","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"1290_CR137","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2023.109987","volume":"235","author":"N Liu","year":"2023","unstructured":"Liu, N., Jia, C., Hou, B., Hou, C., Chen, Y., Cai, Z.: 6search: A reinforcement learning-based traceroute approach for efficient ipv6 topology discovery. Comput. Netw. 235, 109987 (2023)","journal-title":"Comput. Netw."},{"key":"1290_CR138","doi-asserted-by":"publisher","first-page":"9","DOI":"10.1016\/j.comcom.2020.10.013","volume":"165","author":"T Bai","year":"2021","unstructured":"Bai, T., Bian, H., Salahuddin, M.A., Abou Daya, A., Limam, N., Boutaba, R.: Rdp-based lateral movement detection using machine learning. Comput. Commun. 165, 9\u201319 (2021)","journal-title":"Comput. Commun."},{"key":"1290_CR139","unstructured":"Kushwaha, D., Nandakumar, D., Kakkar, A., Gupta, S., Choi, K., Redino, C., Rahman, A., Chandramohan, S.S., Bowen, E., Weeks, M.: Lateral movement detection using user behavioral analysis, (2022). arXiv preprint arXiv:2208.13524"},{"key":"1290_CR140","doi-asserted-by":"crossref","unstructured":"He, D., Gu, H., Zhu, S., Chan, S., Guizani, M.: A comprehensive detection method for the lateral movement stage of apt attacks. IEEE Internet of Things Journal (2023)","DOI":"10.1109\/JIOT.2023.3322412"},{"key":"1290_CR141","doi-asserted-by":"crossref","unstructured":"Bohara, A., Noureddine, M.A., Fawaz, A., Sanders, W.H.: An unsupervised multi-detector approach for identifying malicious lateral movement, in 2017 IEEE 36th Symposium on Reliable Distributed Systems (SRDS) (IEEE, 2017), pp. 224\u2013233","DOI":"10.1109\/SRDS.2017.31"},{"issue":"16","key":"1290_CR142","doi-asserted-by":"publisher","first-page":"14595","DOI":"10.1109\/JIOT.2021.3067904","volume":"9","author":"T Li","year":"2021","unstructured":"Li, T., Liu, W., Zeng, Z., Xiong, N.N.: Drlr: A deep-reinforcement-learning-based recruitment scheme for massive data collections in 6g-based iot networks. IEEE Internet Things J. 9(16), 14595\u201314609 (2021)","journal-title":"IEEE Internet Things J."},{"issue":"5","key":"1290_CR143","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3708497","volume":"57","author":"F Bayram","year":"2025","unstructured":"Bayram, F., Ahmed, B.S.: Towards trustworthy machine learning in production: An overview of the robustness in mlops approach. ACM Comput. Surv. 57(5), 1\u201335 (2025)","journal-title":"ACM Comput. Surv."},{"key":"1290_CR144","doi-asserted-by":"crossref","unstructured":"Wang, C., Redino, C., Rahman, A., Clark, R., Radke, D., Cody, T., Nandakumar, D., Bowen, E.: Discovering command and control (c2) channels on tor and public networks using reinforcement learning, (2024). arXiv preprint arXiv:2402.09200","DOI":"10.1109\/SoutheastCon52093.2024.10500045"},{"issue":"10","key":"1290_CR145","doi-asserted-by":"publisher","first-page":"9","DOI":"10.5815\/ijmecs.2013.10.02","volume":"5","author":"P Barthakur","year":"2013","unstructured":"Barthakur, P., Dahal, M., Ghose, M.K.: An efficient machine learning based classification scheme for detecting distributed command & control traffic of p2p botnets. International Journal of Modern Education and Computer Science 5(10), 9 (2013)","journal-title":"International Journal of Modern Education and Computer Science"},{"key":"1290_CR146","doi-asserted-by":"crossref","unstructured":"Richer, T.J.: Entropy-based detection of botnet command and control, in Proceedings of the Australasian computer science week multiconference, pp. 1\u20134 (2017)","DOI":"10.1145\/3014812.3014889"},{"issue":"14","key":"1290_CR147","doi-asserted-by":"publisher","first-page":"1987","DOI":"10.1002\/dac.2836","volume":"28","author":"M Aiello","year":"2015","unstructured":"Aiello, M., Mongelli, M., Papaleo, G.: Dns tunneling detection through statistical fingerprints of protocol messages and machine learning. Int. J. Commun Syst 28(14), 1987\u20132002 (2015)","journal-title":"Int. J. Commun Syst"},{"issue":"4","key":"1290_CR148","doi-asserted-by":"publisher","first-page":"794","DOI":"10.3390\/jcp3040035","volume":"3","author":"F Sobrero","year":"2023","unstructured":"Sobrero, F., Clavarezza, B., Ucci, D., Bisio, F.: Towards a near-real-time protocol tunneling detector based on machine learning techniques. Journal of Cybersecurity and Privacy 3(4), 794\u2013807 (2023)","journal-title":"Journal of Cybersecurity and Privacy"},{"issue":"3","key":"1290_CR149","doi-asserted-by":"publisher","first-page":"1900","DOI":"10.1109\/TDSC.2020.3041655","volume":"19","author":"H Wang","year":"2020","unstructured":"Wang, H., Wang, S., Xu, D., Zhang, X., Liu, X.: Generating effective software obfuscation sequences with reinforcement learning. IEEE Trans. Dependable Secure Comput. 19(3), 1900\u20131917 (2020)","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"1290_CR150","doi-asserted-by":"crossref","unstructured":"Mahdavifar, S., Hanafy\u00a0Salem, A., Victor, P., Razavi, A.H., Garzon, M., Hellberg, N., Lashkari, A.H.: Lightweight hybrid detection of data exfiltration using dns based on machine learning, in Proceedings of the 2021 11th International Conference on Communication and Network Security, pp. 80\u201386 (2021)","DOI":"10.1145\/3507509.3507520"},{"issue":"6","key":"1290_CR151","doi-asserted-by":"publisher","first-page":"1467","DOI":"10.3390\/electronics12061467","volume":"12","author":"O Abualghanam","year":"2023","unstructured":"Abualghanam, O., Alazzam, H., Elshqeirat, B., Qatawneh, M., Almaiah, M.A.: Real-time detection system for data exfiltration over dns tunneling using machine learning. Electronics 12(6), 1467 (2023)","journal-title":"Electronics"},{"key":"1290_CR152","doi-asserted-by":"crossref","unstructured":"Chung, M.H., Chignell, M., Wang, L., Jovicic, A., Raman, A.: Interactive machine learning for data exfiltration detection: Active learning with human expertise, in 2020 IEEE International Conference on Systems, Man, and Cybernetics (SMC) (IEEE, 2020), pp. 280\u2013287","DOI":"10.1109\/SMC42975.2020.9282831"},{"key":"1290_CR153","doi-asserted-by":"crossref","unstructured":"Cody, T., Rahman, A., Redino, C., Huang, L., Clark, R., Kakkar, A., Kushwaha, D., Park, P., Beling, P., Bowen, E.: Discovering exfiltration paths using reinforcement learning with attack graphs, in 2022 IEEE Conference on Dependable and Secure Computing (DSC) (IEEE, 2022), pp. 1\u20138","DOI":"10.1109\/DSC54232.2022.9888919"},{"key":"1290_CR154","doi-asserted-by":"crossref","unstructured":"Gangupantulu, R., Cody, T., Rahma, A., Redino, C., Clark, R., Park, P.: Crown jewels analysis using reinforcement learning with attack graphs, in 2021 IEEE Symposium Series on Computational Intelligence (SSCI) (IEEE, 2021), pp. 1\u20136","DOI":"10.1109\/SSCI50451.2021.9659947"},{"key":"1290_CR155","unstructured":"Rishu, R., Kakkar, A., Wang, C., Rahman, A., Redino, C., Nandakumar, D., Cody, T., Clark, R., Radke, D., Bowen, E.: Enhancing exfiltration path analysis using reinforcement learning, (2023). arXiv preprint arXiv:2310.03667"},{"issue":"1","key":"1290_CR156","doi-asserted-by":"publisher","first-page":"55","DOI":"10.1016\/j.eswa.2009.05.023","volume":"37","author":"YT Hou","year":"2010","unstructured":"Hou, Y.T., Chang, Y., Chen, T., Laih, C.S., Chen, C.M.: Malicious web content detection by machine learning. Expert Syst. Appl. 37(1), 55\u201360 (2010)","journal-title":"Expert Syst. Appl."},{"key":"1290_CR157","doi-asserted-by":"crossref","unstructured":"Singhal, S., Chawla, U., Shorey, R.: Machine learning & concept drift based approach for malicious website detection, in 2020 International Conference on COMmunication Systems & NETworkS (COMSNETS) (IEEE, 2020), pp. 582\u2013585","DOI":"10.1109\/COMSNETS48256.2020.9027485"},{"issue":"3","key":"1290_CR158","doi-asserted-by":"publisher","first-page":"326","DOI":"10.1145\/212094.212114","volume":"27","author":"T Dietterich","year":"1995","unstructured":"Dietterich, T.: Overfitting and undercomputing in machine learning. ACM computing surveys (CSUR) 27(3), 326\u2013327 (1995)","journal-title":"ACM computing surveys (CSUR)"},{"key":"1290_CR159","unstructured":"Roelofs, R., Shankar, V., Recht, B., Fridovich-Keil, S., Hardt, M., Miller, J., Schmidt, L.: A meta-analysis of overfitting in machine learning. Adv. Neural. Inf. Process. Syst. 32, (2019)"},{"key":"1290_CR160","unstructured":"Moshkovitz, M., Yang, Y.Y., Chaudhuri, K.: Connecting interpretability and robustness in decision trees through separation, in International Conference on Machine Learning (PMLR, 2021), pp. 7839\u20137849"},{"key":"1290_CR161","doi-asserted-by":"publisher","first-page":"153","DOI":"10.1016\/j.neucom.2019.10.051","volume":"401","author":"F Nie","year":"2020","unstructured":"Nie, F., Zhu, W., Li, X.: Decision tree svm: An extension of linear svm for non-linear classification. Neurocomputing 401, 153\u2013159 (2020)","journal-title":"Neurocomputing"},{"key":"1290_CR162","doi-asserted-by":"crossref","unstructured":"Ansari, S., Nassif, A.B., Mahmoud, S., Majzoub, S., Almajali, E., Jarndal, A., Bonny, T., Alnajjar, K.A., Hussain, A.: Impact of outliers on regression and classification models: An empirical analysis, in 2024 17th International Conference on Development in eSystem Engineering (DeSE) (IEEE, 2024), pp. 211\u2013218","DOI":"10.1109\/DeSE63988.2024.10912020"},{"issue":"10","key":"1290_CR163","doi-asserted-by":"publisher","first-page":"2585","DOI":"10.1007\/s10115-021-01605-0","volume":"63","author":"X Hu","year":"2021","unstructured":"Hu, X., Chu, L., Pei, J., Liu, W., Bian, J.: Model complexity of deep learning: A survey. Knowl. Inf. Syst. 63(10), 2585\u20132619 (2021)","journal-title":"Knowl. Inf. Syst."},{"key":"1290_CR164","doi-asserted-by":"publisher","first-page":"202","DOI":"10.1016\/j.procs.2022.12.023","volume":"215","author":"B Shah","year":"2022","unstructured":"Shah, B., Bhavsar, H.: Time complexity in deep learning models. Procedia Computer Science 215, 202\u2013210 (2022)","journal-title":"Procedia Computer Science"},{"issue":"1","key":"1290_CR165","doi-asserted-by":"publisher","first-page":"71","DOI":"10.1007\/s10207-025-00987-4","volume":"24","author":"S Khanzadeh","year":"2025","unstructured":"Khanzadeh, S., Neto, E.C.P., Iqbal, S., Alalfi, M., Buffett, S.: An exploratory study on domain knowledge infusion in deep learning for automated threat defense. Int. J. Inf. Secur. 24(1), 71 (2025)","journal-title":"Int. J. Inf. Secur."},{"key":"1290_CR166","unstructured":"Kaiser, L., Babaeizadeh, M., Milos, P., Osinski, B., Campbell, R.H., Czechowski, K., Erhan, D., Finn, C., Kozakowski, P., Levine, S.: Model-based reinforcement learning for atari, (2019). arXiv preprint arXiv:1903.00374"},{"key":"1290_CR167","unstructured":"Franke, J.K., K\u00f6hler, G., Biedenkapp, A., Hutter, F.: Sample-efficient automated deep reinforcement learning, (2020). arXiv preprint arXiv:2009.01555"},{"key":"1290_CR168","doi-asserted-by":"crossref","unstructured":"Zhu, J., Wu, F., Zhao, J.: An overview of the action space for deep reinforcement learning, in Proceedings of the 2021 4th international conference on algorithms, computing and artificial intelligence, pp. 1\u201310 (2021)","DOI":"10.1145\/3508546.3508598"},{"key":"1290_CR169","unstructured":"Ampel, B.M.: Predicting organizational cybersecurity risk: A deep learning approach. arXiv preprint arXiv:2012.14425 (2020)"},{"key":"1290_CR170","doi-asserted-by":"crossref","unstructured":"Hiromoto, R.E., Haney, M., Vakanski, A.: A secure architecture for IoT with supply chain risk management, in 2017 9th IEEE International Conference on Intelligent Data Acquisition and Advanced Computing Systems: Technology and Applications (IDAACS), vol.\u00a01 (IEEE, 2017), pp. 431\u2013435","DOI":"10.1109\/IDAACS.2017.8095118"},{"issue":"18","key":"1290_CR171","doi-asserted-by":"publisher","first-page":"15241","DOI":"10.1007\/s00521-022-06959-2","volume":"34","author":"HI Kure","year":"2022","unstructured":"Kure, H.I., Islam, S., Mouratidis, H.: An integrated cyber security risk management framework and risk predication for the critical infrastructure protection. Neural Comput. Appl. 34(18), 15241\u201315271 (2022)","journal-title":"Neural Comput. Appl."},{"key":"1290_CR172","doi-asserted-by":"publisher","first-page":"94318","DOI":"10.1109\/ACCESS.2021.3087109","volume":"9","author":"A Yeboah-Ofori","year":"2021","unstructured":"Yeboah-Ofori, A., Islam, S., Lee, S.W., Shamszaman, Z.U., Muhammad, K., Altaf, M., Al-Rakhami, M.S.: Cyber threat predictive analytics for improving cyber supply chain security. IEEE Access 9, 94318\u201394337 (2021)","journal-title":"IEEE Access"},{"key":"1290_CR173","doi-asserted-by":"crossref","unstructured":"Yeboah-Ofori, A., Mouratidis, H., Ismai, U., Islam, S., Papastergiou, S.: Cyber supply chain threat analysis and prediction using machine learning and ontology, in Artificial Intelligence Applications and Innovations: 17th IFIP WG 12.5 International Conference, AIAI 2021, Hersonissos, Crete, Greece, June 25\u201327, 2021, Proceedings 17 (Springer, 2021), pp. 518\u2013530","DOI":"10.1007\/978-3-030-79150-6_41"},{"key":"1290_CR174","doi-asserted-by":"publisher","first-page":"475","DOI":"10.1016\/j.ssci.2019.06.001","volume":"118","author":"N Paltrinieri","year":"2019","unstructured":"Paltrinieri, N., Comfort, L., Reniers, G.: Learning about risk: Machine learning for risk assessment. Saf. Sci. 118, 475\u2013486 (2019)","journal-title":"Saf. Sci."},{"key":"1290_CR175","doi-asserted-by":"crossref","unstructured":"Franco, M.F., Sula, E., Huertas, A., Scheid, E.J., Granville, L.Z., Stiller, B.: SecRiskAI: A machine learning-based approach for cybersecurity risk prediction in businesses, in 2022 IEEE 24th Conference on Business Informatics (CBI), vol.\u00a01 (IEEE, 2022), pp. 1\u201310","DOI":"10.1109\/CBI54897.2022.00008"},{"key":"1290_CR176","doi-asserted-by":"crossref","unstructured":"Liu, X., Konstantinou, C.: Reinforcement learning for cyber-physical security assessment of power systems, in 2019 IEEE Milan PowerTech (IEEE, 2019), pp. 1\u20136","DOI":"10.1109\/PTC.2019.8810568"},{"key":"1290_CR177","doi-asserted-by":"publisher","first-page":"208378","DOI":"10.1109\/ACCESS.2020.3038769","volume":"8","author":"X Liu","year":"2020","unstructured":"Liu, X., Ospina, J., Konstantinou, C.: Deep reinforcement learning for cybersecurity assessment of wind integrated power systems. IEEE access 8, 208378\u2013208394 (2020)","journal-title":"IEEE access"},{"issue":"4","key":"1290_CR178","doi-asserted-by":"publisher","first-page":"3613","DOI":"10.1109\/TSG.2021.3062700","volume":"12","author":"Y Zheng","year":"2021","unstructured":"Zheng, Y., Yan, Z., Chen, K., Sun, J., Xu, Y., Liu, Y.: Vulnerability assessment of deep reinforcement learning models for power system topology optimization. IEEE Transactions on Smart Grid 12(4), 3613\u20133623 (2021)","journal-title":"IEEE Transactions on Smart Grid"},{"key":"1290_CR179","doi-asserted-by":"crossref","unstructured":"Aota, M., Kanehara, H., Kubo, M., Murata, N., Sun, B., Takahashi, T.: Automation of vulnerability classification from its description using machine learning, in 2020 IEEE Symposium on Computers and Communications (ISCC) (IEEE, 2020), pp. 1\u20137","DOI":"10.1109\/ISCC50000.2020.9219568"},{"key":"1290_CR180","unstructured":"Yamaguchi, F., Rieck, K., et\u00a0al.: Vulnerability extrapolation: Assisted discovery of vulnerabilities using machine learning, in 5th USENIX workshop on offensive technologies (WOOT 11) (2011)"},{"key":"1290_CR181","doi-asserted-by":"publisher","first-page":"150672","DOI":"10.1109\/ACCESS.2020.3016774","volume":"8","author":"Z Bilgin","year":"2020","unstructured":"Bilgin, Z., Ersoy, M.A., Soykan, E.U., Tomur, E., \u00c7omak, P., Kara\u00e7ay, L.: Vulnerability prediction from source code using machine learning. IEEE Access 8, 150672\u2013150684 (2020)","journal-title":"IEEE Access"},{"key":"1290_CR182","doi-asserted-by":"publisher","first-page":"548","DOI":"10.1016\/j.future.2018.04.043","volume":"93","author":"L Zhou","year":"2019","unstructured":"Zhou, L., Su, C., Li, Z., Liu, Z., Hancke, G.P.: Automatic fine-grained access control in scada by machine learning. Futur. Gener. Comput. Syst. 93, 548\u2013559 (2019)","journal-title":"Futur. Gener. Comput. Syst."},{"issue":"4","key":"1290_CR183","doi-asserted-by":"publisher","first-page":"761","DOI":"10.1109\/THMS.2022.3163185","volume":"52","author":"G Fragkos","year":"2022","unstructured":"Fragkos, G., Johnson, J., Tsiropoulou, E.E.: Dynamic role-based access control policy for smart grid applications: an offline deep reinforcement learning approach. IEEE Transactions on Human-Machine Systems 52(4), 761\u2013773 (2022)","journal-title":"IEEE Transactions on Human-Machine Systems"},{"key":"1290_CR184","doi-asserted-by":"crossref","unstructured":"Cleveland, J., Mayhew, M.J., Adler, A., Atighetchi, M.: Scalable machine learning framework for behavior-based access control, in 2013 6th International Symposium on Resilient Control Systems (ISRCS) (IEEE, 2013), pp. 181\u2013185","DOI":"10.1109\/ISRCS.2013.6623773"},{"issue":"3","key":"1290_CR185","first-page":"83","volume":"20","author":"E Hamza","year":"2020","unstructured":"Hamza, E., Abou El Kalam, A., Outchakoucht, A., Benhadou, S.: Machine learning enhanced access control for big data. Int. J. Comput. Sci. Netw. Secur. 20(3), 83 (2020)","journal-title":"Int. J. Comput. Sci. Netw. Secur."},{"key":"1290_CR186","doi-asserted-by":"crossref","unstructured":"Gao, C., Yang, W., Ye, J., Xue, Y., Sun, J.: sguard+: Machine learning guided rule-based automated vulnerability repair on smart contracts. ACM Transactions on Software Engineering and Methodology (2024)","DOI":"10.1145\/3641846"},{"key":"1290_CR187","doi-asserted-by":"crossref","unstructured":"Zhang, F., Huff, P., McClanahan, K., Li, Q.: A machine learning-based approach for automated vulnerability remediation analysis, in 2020 IEEE Conference on Communications and Network Security (CNS) (IEEE, 2020), pp. 1\u20139","DOI":"10.1109\/CNS48642.2020.9162309"},{"issue":"6","key":"1290_CR188","doi-asserted-by":"publisher","first-page":"2977","DOI":"10.3390\/s23062977","volume":"23","author":"N Loftus","year":"2023","unstructured":"Loftus, N., Narman, H.S.: Use of machine learning in interactive cybersecurity and network education. Sensors 23(6), 2977 (2023)","journal-title":"Sensors"},{"key":"1290_CR189","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103502","volume":"135","author":"Z Li","year":"2023","unstructured":"Li, Z., Huang, C., Deng, S., Qiu, W., Gao, X.: A soft actor-critic reinforcement learning algorithm for network intrusion detection. Computers & Security 135, 103502 (2023)","journal-title":"Computers & Security"},{"issue":"3","key":"1290_CR190","doi-asserted-by":"publisher","first-page":"1634","DOI":"10.1109\/TCC.2020.3001017","volume":"10","author":"W Wang","year":"2020","unstructured":"Wang, W., Du, X., Shan, D., Qin, R., Wang, N.: Cloud intrusion detection method based on stacked contractive auto-encoder and support vector machine. IEEE transactions on cloud computing 10(3), 1634\u20131646 (2020)","journal-title":"IEEE transactions on cloud computing"},{"key":"1290_CR191","doi-asserted-by":"publisher","DOI":"10.1016\/j.vehcom.2019.100198","volume":"21","author":"HM Song","year":"2020","unstructured":"Song, H.M., Woo, J., Kim, H.K.: In-vehicle network intrusion detection using deep convolutional neural network. Vehicular Communications 21, 100198 (2020)","journal-title":"Vehicular Communications"},{"key":"1290_CR192","doi-asserted-by":"crossref","unstructured":"Zhang, W., Zhang, Y., et\u00a0al.: Intrusion detection model for industrial internet of things based on improved autoencoder. Computational Intelligence and Neuroscience 2022 (2022)","DOI":"10.1155\/2022\/1406214"},{"issue":"3","key":"1290_CR193","doi-asserted-by":"publisher","first-page":"41","DOI":"10.3390\/computers11030041","volume":"11","author":"H Alavizadeh","year":"2022","unstructured":"Alavizadeh, H., Alavizadeh, H., Jang-Jaccard, J.: Deep q-learning based reinforcement learning approach for network intrusion detection. Computers 11(3), 41 (2022)","journal-title":"Computers"},{"key":"1290_CR194","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2021.102923","volume":"61","author":"K Sethi","year":"2021","unstructured":"Sethi, K., Madhav, Y.V., Kumar, R., Bera, P.: Attention based multi-agent intrusion detection systems using reinforcement learning. Journal of Information Security and Applications 61, 102923 (2021)","journal-title":"Journal of Information Security and Applications"},{"issue":"4","key":"1290_CR195","doi-asserted-by":"publisher","first-page":"66","DOI":"10.1109\/MNET.011.2100068","volume":"35","author":"J Tao","year":"2021","unstructured":"Tao, J., Han, T., Li, R.: Deep-reinforcement-learning-based intrusion detection in aerial computing networks. IEEE Network 35(4), 66\u201372 (2021)","journal-title":"IEEE Network"},{"key":"1290_CR196","doi-asserted-by":"crossref","unstructured":"Hancox-Li, L.: Robustness in machine learning explanations: does it matter?, in Proceedings of the 2020 conference on fairness, accountability, and transparency (2020), pp. 640\u2013647","DOI":"10.1145\/3351095.3372836"},{"issue":"3","key":"1290_CR197","doi-asserted-by":"publisher","first-page":"1830","DOI":"10.1109\/JIOT.2020.3015042","volume":"8","author":"B Wang","year":"2020","unstructured":"Wang, B., Sun, Y., Sun, M., Xu, X.: Game-theoretic actor-critic-based intrusion response scheme (gtac-irs) for wireless sdn-based iot networks. IEEE Internet Things J. 8(3), 1830\u20131845 (2020)","journal-title":"IEEE Internet Things J."},{"key":"1290_CR198","doi-asserted-by":"crossref","unstructured":"Nil\u0103, C., Apostol, I., Patriciu, V.: Machine learning approach to quick incident response, in 2020 13th International Conference on Communications (COMM) (IEEE, 2020), pp. 291\u2013296","DOI":"10.1109\/COMM48946.2020.9141989"},{"key":"1290_CR199","doi-asserted-by":"crossref","unstructured":"Nil\u0103, C., Patriciu, V.: Taking advantage of unsupervised learning in incident response, in 2020 12th International Conference on Electronics, Computers and Artificial Intelligence (ECAI) (IEEE, 2020), pp. 1\u20136","DOI":"10.1109\/ECAI50035.2020.9223163"},{"key":"1290_CR200","doi-asserted-by":"crossref","unstructured":"Phan, T.V., Nguyen, T.G.: FEAR: Federated Cyber-Attack Reaction in Distributed Software-Defined Networks with Deep Q-Network, in 2022 Wireless Telecommunications Symposium (WTS) (IEEE, 2022), pp. 1\u20137","DOI":"10.1109\/WTS53620.2022.9768169"},{"key":"1290_CR201","doi-asserted-by":"crossref","unstructured":"Nguyen, H.H., Nguyen, T.G., Hoang, D.T., Le, D.T., Phan, T.V.: CARS: Dynamic Cyber-attack Reaction in SDN-based Networks with Q-learning, in 2021 International Conference on Advanced Technologies for Communications (ATC) (IEEE, 2021), pp. 156\u2013161","DOI":"10.1109\/ATC52653.2021.9598233"},{"key":"1290_CR202","doi-asserted-by":"crossref","unstructured":"McElwee, S., Heaton, J., Fraley, J., Cannady, J.: Deep learning for prioritizing and responding to intrusion detection alerts, in MILCOM 2017-2017 IEEE Military Communications Conference (MILCOM) (IEEE, 2017), pp. 1\u20135","DOI":"10.1109\/MILCOM.2017.8170757"},{"key":"1290_CR203","unstructured":"Uzoma, J., Falana, O., Obunadike, C., Oloyede, K., Obunadike, E.: Using artificial intelligence for automated incidence response in cybersecurity. International Journal of Information Technology (IJIT) 1(4) (2023)"},{"key":"1290_CR204","doi-asserted-by":"crossref","unstructured":"Cooper, A.F., Moss, E., Laufer, B., Nissenbaum, H.: Accountability in an algorithmic society: relationality, responsibility, and robustness in machine learning, in Proceedings of the 2022 ACM conference on fairness, accountability, and transparency, pp. 864\u2013876 (2022)","DOI":"10.1145\/3531146.3533150"},{"key":"1290_CR205","doi-asserted-by":"crossref","unstructured":"Chow, K.H., Deshpande, U., Seshadri, S., Liu, L.: SRA: Smart Recovery Advisor for Cyber Attacks, in Proceedings of the 2021 International Conference on Management of Data, pp. 2691\u20132695 (2021)","DOI":"10.1145\/3448016.3452766"},{"key":"1290_CR206","doi-asserted-by":"crossref","unstructured":"Elnaggar, M., Bezzo, N.: An IRL approach for cyber-physical attack intention prediction and recovery, in 2018 Annual American Control Conference (ACC) (IEEE, 2018), pp. 222\u2013227","DOI":"10.23919\/ACC.2018.8430922"},{"key":"1290_CR207","doi-asserted-by":"crossref","unstructured":"Fei, F., Tu, Z., Xu, D., Deng, X.: Learn-to-recover: Retrofitting uavs with reinforcement learning-assisted flight control under cyber-physical attacks, in 2020 IEEE International Conference on Robotics and Automation (ICRA) (IEEE, 2020), pp. 7358\u20137364","DOI":"10.1109\/ICRA40945.2020.9196611"},{"key":"1290_CR208","doi-asserted-by":"crossref","unstructured":"Akowuah, F., Prasad, R., Espinoza, C.O., Kong, F.: Recovery-by-learning: Restoring autonomous cyber-physical systems from sensor attacks, in 2021 IEEE 27th International conference on embedded and real-time computing systems and applications (RTCSA) (IEEE, 2021), pp. 61\u201366","DOI":"10.1109\/RTCSA52859.2021.00015"},{"key":"1290_CR209","doi-asserted-by":"publisher","DOI":"10.1016\/j.dss.2023.114102","volume":"177","author":"B Biswas","year":"2024","unstructured":"Biswas, B., Mukhopadhyay, A., Kumar, A., Delen, D.: A hybrid framework using explainable ai (xai) in cyber-risk management for defence and recovery against phishing attacks. Decis. Support Syst. 177, 114102 (2024)","journal-title":"Decis. Support Syst."},{"key":"1290_CR210","doi-asserted-by":"crossref","unstructured":"\u015eAHiN, E., Arslan, N.N., \u00d6zdemir, D.: Unlocking the black box: an in-depth review on interpretability, explainability, and reliability in deep learning. Neural Computing and Applications 37(2), 859\u2013965 (2025)","DOI":"10.1007\/s00521-024-10437-2"},{"issue":"6","key":"1290_CR211","doi-asserted-by":"publisher","first-page":"2335","DOI":"10.1007\/s00530-022-00960-4","volume":"28","author":"Q Teng","year":"2022","unstructured":"Teng, Q., Liu, Z., Song, Y., Han, K., Lu, Y.: A survey on the interpretability of deep learning in medical diagnosis. Multimedia Syst. 28(6), 2335\u20132355 (2022)","journal-title":"Multimedia Syst."},{"key":"1290_CR212","unstructured":"Deng, G., Liu, Y., Mayoral-Vilches, V., Liu, P., Li, Y., Xu, Y., Zhang, T., Liu, Y., Pinzger, M., Rass, S.: $$\\{$$PentestGPT$$\\}$$: Evaluating and harnessing large language models for automated penetration testing, in 33rd USENIX Security Symposium (USENIX Security 24), pp. 847\u2013864 (2024)"},{"key":"1290_CR213","doi-asserted-by":"crossref","unstructured":"Isozaki, I., Shrestha, M., Console, R., Kim, E.: Towards automated penetration testing: Introducing llm benchmark, analysis, and improvements, in Adjunct Proceedings of the 33rd ACM Conference on User Modeling, Adaptation and Personalization, pp. 404\u2013419 (2025)","DOI":"10.1145\/3708319.3733804"},{"key":"1290_CR214","doi-asserted-by":"crossref","unstructured":"Shen, X., Wang, L., Li, Z., Chen, Y., Zhao, W., Sun, D., Wang, J., Ruan, W.: Pentestagent: Incorporating llm agents to automated penetration testing, in Proceedings of the 20th ACM Asia Conference on Computer and Communications Security, pp. 375\u2013391 (2025)","DOI":"10.1145\/3708821.3733882"},{"key":"1290_CR215","doi-asserted-by":"crossref","unstructured":"Wang, W., Gu, H., Wu, Z., Chen, H., Chen, X., Shi, F.: Ptfusion: Llm-driven context-aware knowledge fusion for web penetration testing. Information Fusion p. 103731 (2025)","DOI":"10.1016\/j.inffus.2025.103731"},{"key":"1290_CR216","doi-asserted-by":"crossref","unstructured":"Towhid, M.S., Iqbal, S., Neto, E.C.P., Shahriar, N., Buffett, S., Sultana, M., Taylor, A.: Cyber Threat Mitigation with Knowledge-Infused Reinforcement Learning and LLM-Guided Policies, in 2025 22nd Annual International Conference on Privacy, Security, and Trust (PST) (IEEE, 2025), pp. 1\u201310","DOI":"10.1109\/PST65910.2025.11268866"},{"key":"1290_CR217","doi-asserted-by":"crossref","unstructured":"Ahmed, H., Iqbal, S., Neto, E.C.P., Buffett, S., Sultana, M., Taylor, A.: Autonomous Multi-agent Cyber Defense: A Novel Approach Using Reinforcement Learning with Hierarchical LLM Critics, in 2025 Cyber Awareness and Research Symposium (CARS) (IEEE, 2025), pp. 1\u20135","DOI":"10.1109\/CARS67163.2025.11337724"},{"key":"1290_CR218","doi-asserted-by":"crossref","unstructured":"Kale, S.P., Kanwal, P., Honnavalli, P.B.: Agentic Penetration Testing using Secure Shell: Context-Aware Command Generation and Analysis Using Open-Source LLMs, in 2025 International Conference on Cybersecurity and AI-Based Systems (Cyber-AI) (IEEE, 2025), pp. 182\u2013189","DOI":"10.1109\/Cyber-AI66431.2025.11233438"},{"key":"1290_CR219","doi-asserted-by":"crossref","unstructured":"Salmani, P., Lewis, P.R.: A Reflective Architecture for LLM-based Systems, in 2025 IEEE International Conference on Autonomic Computing and Self-Organizing Systems Companion (ACSOS-C) (IEEE, 2025), pp. 61\u201368","DOI":"10.1109\/ACSOS-C66519.2025.00029"},{"key":"1290_CR220","doi-asserted-by":"crossref","unstructured":"Loevenich, J.F., Lopes, R.R.F.: Agentic Generative AI for Automation of Cyber Security Attack Chains in Tactical MANETs, in 2025 IEEE 50th Conference on Local Computer Networks (LCN) (IEEE, 2025), pp. 1\u20137","DOI":"10.1109\/LCN65610.2025.11146384"},{"issue":"6","key":"1290_CR221","doi-asserted-by":"publisher","first-page":"54","DOI":"10.1109\/MIC.2019.2960071","volume":"23","author":"A Sheth","year":"2019","unstructured":"Sheth, A., Gaur, M., Kursuncu, U., Wickramarachchi, R.: Shades of knowledge-infused learning for enhancing deep learning. IEEE Internet Comput. 23(6), 54\u201363 (2019)","journal-title":"IEEE Internet Comput."},{"issue":"11","key":"1290_CR222","doi-asserted-by":"publisher","first-page":"12387","DOI":"10.1007\/s10462-023-10448-w","volume":"56","author":"AD Garcez","year":"2023","unstructured":"Garcez, A.D., Lamb, L.C.: Neurosymbolic ai: The 3rd wave. Artif. Intell. Rev. 56(11), 12387\u201312406 (2023)","journal-title":"Artif. Intell. Rev."},{"issue":"4","key":"1290_CR223","doi-asserted-by":"publisher","first-page":"78","DOI":"10.1109\/MCE.2021.3095385","volume":"11","author":"R Rohan","year":"2021","unstructured":"Rohan, R., Funilkul, S., Pal, D., Thapliyal, H.: Humans in the loop: Cybersecurity aspects in the consumer iot context. IEEE Consumer Electronics Magazine 11(4), 78\u201384 (2021)","journal-title":"IEEE Consumer Electronics Magazine"},{"issue":"18","key":"1290_CR224","doi-asserted-by":"publisher","first-page":"6225","DOI":"10.3390\/s21186225","volume":"21","author":"T Krause","year":"2021","unstructured":"Krause, T., Ernst, R., Klaer, B., Hacker, I., Henze, M.: Cybersecurity in power grids: Challenges and opportunities. Sensors 21(18), 6225 (2021)","journal-title":"Sensors"},{"key":"1290_CR225","unstructured":"AI, N.: Artificial intelligence risk management framework (ai rmf 1.0). https:\/\/nvlpubsnist.gov\/nistpubs\/ai\/nist.aipp. 100\u20131 (2023)"},{"key":"1290_CR226","doi-asserted-by":"crossref","unstructured":"Staegemann, D., Volk, M., Saxena, A., Pohl, M., Nahhas, A., H\u00e4usler, R., Abdallah, M., Bosse, S., Jamous, N., Turowski, K.: Challenges in Data Acquisition and Management in Big Data Environments., in IoTBDS, pp. 193\u2013204 (2021)","DOI":"10.5220\/0010429001930204"},{"issue":"2","key":"1290_CR227","first-page":"760","volume":"25","author":"Y Shang","year":"2024","unstructured":"Shang, Y.: Detection and prevention of cyber defense attacks using machine learning algorithms. Scalable Computing: Practice and Experience 25(2), 760\u2013769 (2024)","journal-title":"Scalable Computing: Practice and Experience"},{"key":"1290_CR228","unstructured":"Chen, L., Acun, B., Ardalani, N., Sun, Y., Kang, F., Lyu, H., Kwon, Y., Jia, R., Wu, C.J., Zaharia, M.: Data acquisition: A new frontier in data-centric ai, (2023). arXiv:2311.13712 arXiv preprint"}],"container-title":["International Journal of Information Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-026-01290-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10207-026-01290-6","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-026-01290-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T17:02:37Z","timestamp":1784394157000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10207-026-01290-6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7,18]]},"references-count":228,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2026,8]]}},"alternative-id":["1290"],"URL":"https:\/\/doi.org\/10.1007\/s10207-026-01290-6","relation":{},"ISSN":["1615-5270"],"issn-type":[{"value":"1615-5270","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,7,18]]},"assertion":[{"value":"22 January 2026","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"13 June 2026","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"18 July 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"The authors declare no competing interests.","order":1,"name":"Ethics","label":"Competing interests","group":{"name":"EthicsHeading","label":"Declarations"}}],"article-number":"128"}}