{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,10]],"date-time":"2026-04-10T05:57:30Z","timestamp":1775800650810,"version":"3.50.1"},"reference-count":245,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"name":"Scientific and Technological Research Council of T\u00fcrkiye (T\u00dcB\u0130TAK) 1515 Frontier Research and Development Laboratories Support Program for T\u00fcrk Telekom 6G Research and Development Laboratory","award":["5249902"],"award-info":[{"award-number":["5249902"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Open J. Commun. Soc."],"published-print":{"date-parts":[[2026]]},"DOI":"10.1109\/ojcoms.2026.3678511","type":"journal-article","created":{"date-parts":[[2026,3,27]],"date-time":"2026-03-27T19:53:44Z","timestamp":1774641224000},"page":"3468-3511","source":"Crossref","is-referenced-by-count":0,"title":["When Beneficial Intelligence Turns Hostile: A Survey of Adversarial Threats in AI-Native 6G"],"prefix":"10.1109","volume":"7","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5796-3076","authenticated-orcid":false,"given":"M\u00fccahit","family":"Altinta\u015f","sequence":"first","affiliation":[{"name":"Research and Development Department, T&#x00FC;rk Telekom, 4&#x00B0;stanbul, T&#x00FC;rkiye"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7856-7053","authenticated-orcid":false,"given":"S\u00fcmeye Nur","family":"Karhan","sequence":"additional","affiliation":[{"name":"Research and Development Department, T&#x00FC;rk Telekom, 4&#x00B0;stanbul, T&#x00FC;rkiye"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-7836-3193","authenticated-orcid":false,"given":"Yasin Emre","family":"Tok","sequence":"additional","affiliation":[{"name":"Research and Development Department, T&#x00FC;rk Telekom, 4&#x00B0;stanbul, T&#x00FC;rkiye"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2425-5342","authenticated-orcid":false,"given":"Amine Gonca","family":"Toprak","sequence":"additional","affiliation":[{"name":"Research and Development Department, T&#x00FC;rk Telekom, 4&#x00B0;stanbul, T&#x00FC;rkiye"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7727-0197","authenticated-orcid":false,"given":"\u00d6yk\u00fc Berfin","family":"Mercan","sequence":"additional","affiliation":[{"name":"Research and Development Department, T&#x00FC;rk Telekom, 4&#x00B0;stanbul, T&#x00FC;rkiye"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"crossref","DOI":"10.1007\/978-981-19-2868-0","volume-title":"AI and Blockchain Technology in 6G Wireless Network","author":"Borah","year":"2022"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/MNET.103.2100587"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/MWC.001.2100338"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2023.3310063"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.5121\/csit.2024.141408"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.3390\/network5010001"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2023.110085"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/OJCOMS.2024.3386872"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/MCOMSTD.101.2000090"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2024.3373808"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/MNET.117.2100730"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3120143"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/OJCOMS.2021.3078081"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01580"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW56347.2022.00383"},{"key":"ref16","article-title":"Attacking slicing network via side-channel reinforcement learning attack","author":"Shao","year":"2024","journal-title":"arXiv:2409.11258"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2024.104031"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/TCOMM.2025.3547764"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/ICCWorkshops57953.2023.10283797"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/MNET.2024.3425152"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/MCOM.004.2400646"},{"key":"ref22","article-title":"QFAL: Quantum federated adversarial learning","author":"Maouaki","year":"2025","journal-title":"arXiv:2502.21171"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.30574\/wjarr.2025.25.2.0571"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/MCOM.001.2200326"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2021.3126076"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/MVT.2019.2921208"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2024.3384272"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2021.107930"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2024.3460656"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/1128817.1128824"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.5555\/2969033.2969125"},{"key":"ref32","article-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2014"},{"key":"ref33","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2015","journal-title":"arXiv:1412.6572"},{"key":"ref34","article-title":"Adversarial machine learning at scale","author":"Kurakin","year":"2017"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1002\/sam.11716"},{"key":"ref36","article-title":"The mathematics of adversarial attacks in AI\u2013Why deep learning is unstable despite the existence of stable neural networks","author":"Bastounis","year":"2021","journal-title":"arXiv:2109.06098"},{"key":"ref37","article-title":"Decision-based adversarial attacks: Reliable attacks against black-box machine learning models","author":"Brendel","year":"2018"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.3389\/frobt.2022.968305"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/LWC.2018.2867459"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3226905"},{"key":"ref42","article-title":"SCA: Improve semantic consistent in unrestricted adversarial attacks via ddpm inversion","author":"Pan","year":"2025"},{"key":"ref43","article-title":"Towards deep learning models resistant to adversarial attacks","volume-title":"Proc. Int. Conf. Learn. Represent. (ICLR)","author":"Madry"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.11302"},{"key":"ref48","first-page":"284","article-title":"Synthesizing robust adversarial examples","volume-title":"Proc. 35th Int. Conf. Mach. Learn.","author":"Athalye"},{"key":"ref49","article-title":"Hessian-free second-order adversarial examples for adversarial learning","author":"Qian","year":"2022"},{"key":"ref50","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","volume-title":"Proc. Int. Conf. Mach. Learn. (ICML)","author":"Croce"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/CISS48834.2020.1570617416"},{"key":"ref52","first-page":"2137","article-title":"Black-box adversarial attacks with limited queries and information","volume-title":"Proc. 35th Int. Conf. Mach. Learn.","author":"Ilyas"},{"key":"ref53","first-page":"5025","article-title":"Adversarial risk and the dangers of evaluating against weak attacks","volume-title":"Proc. 35th Int. Conf. Mach. Learn.","author":"Uesato"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.3301742"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"ref56","article-title":"Prior convictions: Black-box adversarial attacks with bandits and priors","author":"Ilyas","year":"2019"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1145\/3321707.3321749"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2019.2890858"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2022.3152526"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00045"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01029"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1145\/3394486.3403225"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00444"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2018\/543"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01464"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-83157-7_15"},{"key":"ref69","first-page":"1807","article-title":"Poisoning attacks against support vector machines","volume-title":"Proc. 29th Int. Conf. Mach. Learn. (ICML)","volume":"2","author":"Biggio"},{"key":"ref70","article-title":"BadNets: Identifying vulnerabilities in the machine learning model supply chain","author":"Gu","year":"2017","journal-title":"arXiv:1708.06733"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00714"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00421"},{"key":"ref73","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00033"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.1109\/mwc.2025.3610574"},{"key":"ref75","doi-asserted-by":"publisher","DOI":"10.23919\/JCC.fa.2023-0206.202308"},{"key":"ref76","doi-asserted-by":"publisher","DOI":"10.1016\/j.jare.2024.02.012"},{"key":"ref77","doi-asserted-by":"publisher","DOI":"10.1109\/LWC.2020.3003400"},{"key":"ref78","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2024.3389119"},{"key":"ref79","doi-asserted-by":"publisher","DOI":"10.1109\/GLOBECOM54140.2023.10437795"},{"key":"ref80","doi-asserted-by":"publisher","DOI":"10.3390\/fi16070226"},{"key":"ref81","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2021.3104833"},{"key":"ref82","doi-asserted-by":"publisher","DOI":"10.1145\/3078971.3078974"},{"key":"ref83","doi-asserted-by":"publisher","DOI":"10.5555\/3241094.3241142"},{"key":"ref84","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2024.3418900"},{"key":"ref85","doi-asserted-by":"publisher","DOI":"10.3390\/s23115340"},{"key":"ref86","doi-asserted-by":"publisher","DOI":"10.1002\/nem.70003"},{"key":"ref87","doi-asserted-by":"publisher","DOI":"10.1007\/s10462-023-10417-3"},{"key":"ref88","doi-asserted-by":"publisher","DOI":"10.3390\/s25030854"},{"key":"ref89","doi-asserted-by":"publisher","DOI":"10.4018\/979-8-3693-2931-3.ch005"},{"key":"ref90","doi-asserted-by":"publisher","DOI":"10.1016\/j.csi.2021.103521"},{"key":"ref91","article-title":"Enhancing LLM-based autonomous driving agents to mitigate perception attacks","author":"Song","year":"2024","journal-title":"arXiv:2409.14488"},{"key":"ref92","doi-asserted-by":"publisher","DOI":"10.3390\/jcp3030025"},{"key":"ref93","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2021.3132954"},{"key":"ref94","doi-asserted-by":"publisher","DOI":"10.1007\/s10462-024-10796-1"},{"key":"ref95","first-page":"1846","article-title":"Free-rider attacks on model aggregation in federated learning","volume-title":"Proc. Int. Conf. Artif. Intell. Stat.","author":"Fraboni"},{"key":"ref96","doi-asserted-by":"publisher","DOI":"10.1186\/s42400-021-00105-6"},{"key":"ref97","doi-asserted-by":"publisher","DOI":"10.1007\/s43926-025-00123-7"},{"key":"ref98","doi-asserted-by":"publisher","DOI":"10.1109\/OJCOMS.2021.3103735"},{"key":"ref99","article-title":"Integrating sensing and communications in 6G? Not until it is secure to do so","author":"Su","year":"2025","journal-title":"arXiv:2503.15243"},{"key":"ref100","doi-asserted-by":"publisher","DOI":"10.3390\/network4040023"},{"key":"ref101","doi-asserted-by":"publisher","DOI":"10.1103\/PhysRevResearch.6.023020"},{"key":"ref102","article-title":"Quantum computing supported adversarial attackresilient autonomous vehicle perception module for traffic sign classification","author":"Majumder","year":"2025","journal-title":"arXiv:2504.12644"},{"key":"ref103","doi-asserted-by":"publisher","DOI":"10.1038\/s41598-021-84139-3"},{"key":"ref104","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2024.06.023"},{"key":"ref105","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-022-00644-0"},{"key":"ref106","doi-asserted-by":"publisher","DOI":"10.1109\/BlackSeaCom52164.2021.9527756"},{"key":"ref107","doi-asserted-by":"publisher","DOI":"10.1109\/GPECOM58364.2023.10175718"},{"key":"ref108","article-title":"Network and physical layer attacks and countermeasures to AI-enabled 6G O-RAN","author":"Rahman","year":"2021","journal-title":"arXiv:2106.02494"},{"key":"ref109","doi-asserted-by":"publisher","DOI":"10.1145\/3643833.3656119"},{"key":"ref110","doi-asserted-by":"publisher","DOI":"10.1109\/IWCMC.2019.8766505"},{"key":"ref111","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2021.3052888"},{"key":"ref112","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2021.3137084"},{"key":"ref113","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2022.3188930"},{"key":"ref114","doi-asserted-by":"publisher","DOI":"10.1002\/9781119723950.ch14"},{"key":"ref115","doi-asserted-by":"publisher","DOI":"10.1109\/DCOSS-IoT61029.2024.00017"},{"key":"ref116","article-title":"Adversarial attacks can deceive AI systems, leading to misclassification or incorrect decisions","author":"Radanliev","year":"2023","journal-title":"Preprints preprint"},{"key":"ref117","doi-asserted-by":"publisher","DOI":"10.70937\/itej.v1i01.9"},{"key":"ref118","doi-asserted-by":"publisher","DOI":"10.1109\/ICC45041.2023.10279339"},{"key":"ref119","first-page":"634","article-title":"Analyzing federated learning through an adversarial lens","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Bhagoji"},{"key":"ref120","doi-asserted-by":"publisher","DOI":"10.1145\/3571730"},{"key":"ref121","doi-asserted-by":"publisher","DOI":"10.1016\/j.hcc.2024.100211"},{"key":"ref122","article-title":"Ignore previous prompt: Attack techniques for language models","author":"Perez","year":"2022","journal-title":"arXiv:2211.09527"},{"key":"ref123","doi-asserted-by":"publisher","DOI":"10.1145\/3605764.3623985"},{"key":"ref124","article-title":"Prompt injection attack against LLM-integrated applications","author":"Liu","year":"2023","journal-title":"arXiv:2306.05499"},{"key":"ref125","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/872"},{"key":"ref126","doi-asserted-by":"publisher","DOI":"10.1145\/3394486.3403049"},{"key":"ref127","first-page":"1115","article-title":"Adversarial attack on graph structured data","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Dai"},{"key":"ref128","doi-asserted-by":"publisher","DOI":"10.1109\/ICITEICS61368.2024.10624973"},{"key":"ref129","doi-asserted-by":"publisher","DOI":"10.1109\/TCE.2024.3443328"},{"key":"ref130","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2018.07.023"},{"key":"ref131","doi-asserted-by":"publisher","DOI":"10.1109\/CCGridW59191.2023.00018"},{"key":"ref132","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2023.122223"},{"key":"ref133","doi-asserted-by":"publisher","DOI":"10.1109\/comst.2023.3319492"},{"key":"ref134","article-title":"Survey of vulnerabilities in large language models revealed by adversarial attacks","author":"Shayegani","year":"2023"},{"key":"ref135","doi-asserted-by":"publisher","DOI":"10.3390\/fi16030067"},{"key":"ref136","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3444193"},{"key":"ref137","doi-asserted-by":"publisher","DOI":"10.1109\/ton.2025.3629689"},{"key":"ref138","doi-asserted-by":"publisher","DOI":"10.1016\/j.cviu.2023.103877"},{"key":"ref139","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2024.3378263"},{"key":"ref140","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2023.3319492"},{"key":"ref141","doi-asserted-by":"publisher","DOI":"10.1109\/TWC.2024.3452438"},{"key":"ref142","doi-asserted-by":"publisher","DOI":"10.3390\/s24186156"},{"key":"ref143","doi-asserted-by":"publisher","DOI":"10.1109\/NaNA53684.2021.00093"},{"key":"ref144","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2018.2846401"},{"key":"ref145","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"ref146","doi-asserted-by":"publisher","DOI":"10.1109\/MNET.001.2300140"},{"key":"ref147","first-page":"1345","article-title":"High accuracy and high fidelity extraction of neural networks","volume-title":"Proc. 29th USENIX Conf. Secur. Symp.","author":"Jagielski"},{"issue":"3","key":"ref148","first-page":"43","article-title":"Cross-domain adversarial attack taxonomy for multimodal neural networks: Threat landscape and open challenges","volume":"2","author":"Azmat","year":"2025","journal-title":"Baltic J. Multidisciplinary Res."},{"key":"ref149","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2024.104090"},{"key":"ref150","doi-asserted-by":"publisher","DOI":"10.1109\/GLOBECOM54140.2023.10437125"},{"key":"ref151","doi-asserted-by":"publisher","DOI":"10.3390\/electronics12183752"},{"key":"ref152","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2021\/591"},{"key":"ref153","doi-asserted-by":"publisher","DOI":"10.1109\/EuCNC\/6GSummit51104.2021.9482503"},{"key":"ref154","doi-asserted-by":"publisher","DOI":"10.1016\/j.phycom.2022.101626"},{"key":"ref155","doi-asserted-by":"publisher","DOI":"10.1109\/ICSC63108.2024.10895785"},{"key":"ref156","doi-asserted-by":"publisher","DOI":"10.1109\/OJSP.2024.3453176"},{"key":"ref157","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2022.3155562"},{"key":"ref158","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-53510-9_8"},{"key":"ref159","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2024.3488836"},{"key":"ref160","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00740"},{"key":"ref161","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00035"},{"key":"ref162","first-page":"2958","article-title":"Adversarial weight perturbation helps robust generalization","volume-title":"Proc. NIPS","author":"Wu"},{"key":"ref163","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i8.20817"},{"key":"ref164","doi-asserted-by":"publisher","DOI":"10.1016\/j.mlwa.2020.100017"},{"key":"ref165","doi-asserted-by":"publisher","DOI":"10.1109\/ICNC64010.2025.10993578"},{"key":"ref166","doi-asserted-by":"publisher","DOI":"10.1631\/FITEE.2300474"},{"key":"ref167","article-title":"Adversarial robustness of amortized Bayesian inference","author":"Gl\u00f6ckler","year":"2023"},{"key":"ref168","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01258-8_32"},{"issue":"2","key":"ref169","first-page":"61","article-title":"Explainable and trustworthy artificial intelligence in 6G THz networks: Challenges, solutions, and future perspectives","volume":"2","author":"Toprak","year":"2025","journal-title":"ITU J. Wireless Commun. Cybersecurity"},{"key":"ref170","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2025.111600"},{"key":"ref171","doi-asserted-by":"publisher","DOI":"10.1016\/j.rineng.2025.105409"},{"key":"ref172","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2025.3570973"},{"key":"ref173","first-page":"1310","article-title":"Certified adversarial robustness via randomized smoothing","volume-title":"Proc. 36th Int. Conf. Mach. Learn.","volume":"97","author":"Cohen"},{"key":"ref174","article-title":"Incremental randomized smoothing certification","author":"Ugare","year":"2024"},{"key":"ref175","article-title":"On the effectiveness of interval bound propagation for training verifiably robust models","author":"Gowal","year":"2018","journal-title":"arXiv:1810.12715"},{"key":"ref176","article-title":"Efficient neural network robustness certification with general activation functions","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Zhang"},{"key":"ref177","doi-asserted-by":"publisher","DOI":"10.1145\/3290354"},{"key":"ref178","first-page":"1129","article-title":"Automatic perturbation analysis for scalable certified robustness and beyond","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Xu"},{"key":"ref179","doi-asserted-by":"publisher","DOI":"10.52202\/068431-0744"},{"key":"ref180","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2023.3325721"},{"key":"ref181","doi-asserted-by":"publisher","DOI":"10.1145\/3561048"},{"key":"ref182","doi-asserted-by":"publisher","DOI":"10.1109\/ICUFN61752.2024.10624832"},{"key":"ref183","doi-asserted-by":"publisher","DOI":"10.1016\/j.inffus.2024.102303"},{"key":"ref184","doi-asserted-by":"publisher","DOI":"10.1109\/WCNC61545.2025.10978796"},{"key":"ref185","article-title":"Applications of explainable ai for 6G: Technical aspects, use cases, and research challenges","author":"Wang","year":"2021","journal-title":"arXiv:2112.04698"},{"key":"ref186","doi-asserted-by":"publisher","DOI":"10.1109\/OJCOMS.2025.3534626"},{"key":"ref187","doi-asserted-by":"publisher","DOI":"10.1109\/MCOM.001.2300172"},{"key":"ref188","doi-asserted-by":"publisher","DOI":"10.1109\/OJVT.2022.3219898"},{"key":"ref189","doi-asserted-by":"publisher","DOI":"10.1109\/TIA.2025.3532917"},{"key":"ref190","doi-asserted-by":"publisher","DOI":"10.1109\/JSTSP.2025.3633593"},{"key":"ref191","doi-asserted-by":"publisher","DOI":"10.1016\/j.procs.2025.03.073"},{"key":"ref192","doi-asserted-by":"publisher","DOI":"10.1109\/OJCOMS.2024.3438264"},{"key":"ref193","doi-asserted-by":"publisher","DOI":"10.3390\/info13080395"},{"key":"ref194","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2024.3523327"},{"key":"ref195","doi-asserted-by":"publisher","DOI":"10.1016\/j.iot.2023.100947"},{"key":"ref196","article-title":"Security and privacy of 6G federated learning-enabled dynamic spectrum sharing","author":"Vo","year":"2024","journal-title":"arXiv:2406.12330"},{"key":"ref197","doi-asserted-by":"publisher","DOI":"10.23919\/JCC.2020.09.009"},{"key":"ref198","doi-asserted-by":"publisher","DOI":"10.1109\/OJCOMS.2024.3449563"},{"key":"ref199","first-page":"118","article-title":"Machine learning with adversaries: Byzantine tolerant gradient descent","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"30","author":"Blanchard"},{"key":"ref200","first-page":"5650","article-title":"Byzantine-robust distributed learning: Towards optimal statistical rates","volume-title":"Proc. 35th Int. Conf. Mach. Learn.","author":"Yin"},{"key":"ref201","first-page":"3521","article-title":"The hidden vulnerability of distributed learning in byzantium","volume-title":"Proc. 35th Int. Conf. Mach. Learn.","author":"Mhamdi"},{"key":"ref202","doi-asserted-by":"publisher","DOI":"10.1109\/TNSE.2021.3083263"},{"key":"ref203","doi-asserted-by":"publisher","DOI":"10.1155\/2022\/2886795"},{"key":"ref204","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102827"},{"key":"ref205","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3516567"},{"key":"ref206","doi-asserted-by":"publisher","DOI":"10.1145\/3702995"},{"key":"ref207","doi-asserted-by":"publisher","DOI":"10.1109\/ICPADS56603.2022.00046"},{"key":"ref208","doi-asserted-by":"publisher","DOI":"10.1109\/ICCCR54399.2022.9790094"},{"key":"ref209","doi-asserted-by":"publisher","DOI":"10.3390\/electronics14112153"},{"key":"ref210","doi-asserted-by":"publisher","DOI":"10.1109\/EuCNC\/6GSummit60053.2024.10597131"},{"key":"ref211","doi-asserted-by":"publisher","DOI":"10.1109\/TNSE.2021.3115032"},{"key":"ref212","doi-asserted-by":"publisher","DOI":"10.1080\/00207179.2022.2117084"},{"key":"ref213","doi-asserted-by":"publisher","DOI":"10.23919\/ECC55457.2022.9838396"},{"key":"ref214","doi-asserted-by":"publisher","DOI":"10.3390\/fi17060233"},{"key":"ref215","doi-asserted-by":"publisher","DOI":"10.1109\/TVT.2021.3077893"},{"key":"ref216","article-title":"A novel zero-touch, zerotrust, AI\/ML enablement framework for IoT network security","author":"Shakya","year":"2025","journal-title":"arXiv:2502.03614"},{"key":"ref217","doi-asserted-by":"publisher","DOI":"10.1080\/09540091.2025.2603028"},{"key":"ref218","doi-asserted-by":"publisher","DOI":"10.1109\/WCNC51071.2022.9771619"},{"key":"ref219","doi-asserted-by":"publisher","DOI":"10.1109\/WiMob58348.2023.10187759"},{"key":"ref220","doi-asserted-by":"publisher","DOI":"10.1109\/TGCN.2025.3562895"},{"key":"ref221","doi-asserted-by":"publisher","DOI":"10.1007\/s11227-025-07097-x"},{"key":"ref222","doi-asserted-by":"publisher","DOI":"10.4018\/979-8-3373-1375-7.ch015"},{"key":"ref223","doi-asserted-by":"publisher","DOI":"10.1109\/OJCOMS.2024.3523368"},{"key":"ref224","doi-asserted-by":"publisher","DOI":"10.1109\/BigData62323.2024.10825993"},{"key":"ref225","doi-asserted-by":"publisher","DOI":"10.1109\/OJCOMS.2025.3599866"},{"key":"ref226","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2024.3392338"},{"key":"ref227","doi-asserted-by":"publisher","DOI":"10.1109\/CCWC57344.2023.10099144"},{"key":"ref228","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3033989"},{"key":"ref229","doi-asserted-by":"publisher","DOI":"10.1117\/12.2580498"},{"key":"ref230","doi-asserted-by":"publisher","DOI":"10.1016\/j.procs.2020.03.367"},{"key":"ref231","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2022.3205184"},{"key":"ref232","article-title":"Adversarial learning for wireless communications","author":"Zhang","year":"2023"},{"key":"ref233","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i8.16840"},{"key":"ref234","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2023.3317242"},{"key":"ref235","doi-asserted-by":"publisher","DOI":"10.1145\/3583683"},{"key":"ref236","doi-asserted-by":"publisher","DOI":"10.1109\/MCOM.006.2200730"},{"key":"ref237","article-title":"Enhancing TinyML security: Study of adversarial attack transferability","author":"Shah","journal-title":"arXiv:2407.11599"},{"key":"ref238","article-title":"Quantitative analysis of deeply quantized tiny neural networks robust to adversarial attacks","author":"Zakariyya","year":"2025"},{"key":"ref239","article-title":"Assessing adversarial robustness of large language models: An empirical study","author":"Yang","year":"2024"},{"key":"ref240","doi-asserted-by":"publisher","DOI":"10.1109\/ICAIRC64177.2024.10900215"},{"key":"ref241","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2022.3201243"},{"key":"ref242","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2024.3455090"},{"key":"ref243","doi-asserted-by":"publisher","DOI":"10.1007\/s10994-022-06177-w"},{"key":"ref244","doi-asserted-by":"publisher","DOI":"10.1109\/ICSP56322.2022.9965222"},{"key":"ref245","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP49357.2023.10096163"}],"container-title":["IEEE Open Journal of the Communications Society"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/8782661\/11343983\/11457016.pdf?arnumber=11457016","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,10]],"date-time":"2026-04-10T05:05:40Z","timestamp":1775797540000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11457016\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"references-count":245,"URL":"https:\/\/doi.org\/10.1109\/ojcoms.2026.3678511","relation":{},"ISSN":["2644-125X"],"issn-type":[{"value":"2644-125X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]}}}