{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,22]],"date-time":"2025-10-22T23:14:41Z","timestamp":1761174881899,"version":"build-2065373602"},"reference-count":40,"publisher":"Polish Information Processing Society","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"DOI":"10.15439\/2025f9981","type":"proceedings-article","created":{"date-parts":[[2025,10,22]],"date-time":"2025-10-22T07:44:23Z","timestamp":1761119063000},"page":"699-704","source":"Crossref","is-referenced-by-count":0,"title":["AI-MTD: Zero-Trust Artificial Intelligence Model Security Based on Moving Target Defense"],"prefix":"10.15439","volume":"43","author":[{"ORCID":"https:\/\/orcid.org\/0009-0008-9274-802X","authenticated-orcid":true,"given":"Daniel","family":"Gilkarov","sequence":"first","affiliation":[{"name":"Ariel University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2055-2211","authenticated-orcid":true,"given":"Ran","family":"Dubin","sequence":"additional","affiliation":[{"name":"Ariel University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"6175","published-online":{"date-parts":[[2025,10,15]]},"reference":[{"key":"ref1","doi-asserted-by":"crossref","unstructured":"E. Wenger, J. Passananti, A. N. Bhagoji, Y. Yao, H. Zheng, and B. Y.\nZhao, \u201cBackdoor attacks against deep learning systems in the physical\nworld,\u201d in Proceedings of the IEEE\/CVF conference on computer vision\nand pattern recognition, 2021, pp. 6206\u20136215.","DOI":"10.1109\/CVPR46437.2021.00614"},{"key":"ref2","doi-asserted-by":"crossref","unstructured":"M. Chen, G. He, and J. Wu, \u201cZddr: A zero-shot defender for adversarial\nsamples detection and restoration,\u201d IEEE Access, 2024.","DOI":"10.1109\/ACCESS.2024.3356568"},{"key":"ref3","doi-asserted-by":"crossref","unstructured":"K. Nguyen, T. Fernando, C. Fookes, and S. Sridharan, \u201cPhysical\nadversarial attacks for surveillance: A survey,\u201d IEEE Transactions on\nNeural Networks and Learning Systems, 2023.","DOI":"10.1109\/TNNLS.2023.3321432"},{"key":"ref4","doi-asserted-by":"crossref","unstructured":"Y. Yao, J. Duan, K. Xu, Y. Cai, Z. Sun, and Y. Zhang, \u201cA survey on\nlarge language model (llm) security and privacy: The good, the bad, and\nthe ugly,\u201d High-Confidence Computing, p. 100211, 2024.","DOI":"10.1016\/j.hcc.2024.100211"},{"key":"ref5","unstructured":"N. S. Agency, \u201cDeploying ai systems securely, best practices for deploying secure and resilient ai systems,\u201d 2024, accessed: 2024-05-01. [Online]. Available: https:\/\/media.defense.gov\/2024\/Apr\/15\/2003439257\/-1\/-1\/0\/CSI-DEPLOYING-AI-SYSTEMS-SECURELY.PDF"},{"key":"ref6","unstructured":"M. ATLAS, \u201cMitre atlas,\u201d 2024, accessed: 2024-05-01. [Online].\nAvailable: https:\/\/atlas.mitre.org\/"},{"key":"ref7","unstructured":"OWSAP, \u201cOwasp machine learning security top ten,\u201d 2023,\naccessed: 2023-10-15. [Online]. Available: https:\/\/owasp.org\/www-project-machine-learning-security-top-10\/"},{"key":"ref8","unstructured":"MITRE, \u201cMitre atlas,\u201d 2023, accessed: 2023-10-15. [Online]. Available:\nhttps:\/\/atlas.mitre.org\/"},{"key":"ref9","unstructured":"M. ATLAS, \u201cMitre atlas, user execution: Unsafe ml artifacts,\u201d\n2024, accessed: 2024-05-01. [Online]. Available: https:\/\/atlas.mitre.org\/techniques\/AML.T0011.000"},{"key":"ref10","doi-asserted-by":"crossref","unstructured":"R. Dubin, \u201cDisarming attacks inside neural network models,\u201d IEEE\nAccess, 2023.","DOI":"10.1109\/ACCESS.2023.3330141"},{"key":"ref11","unstructured":"E.\n Sultanik,\n \u201cNever\n a\n dill\n moment:\n Exploiting\n machine\n learning\n pickle\n files,\u201d\n 2022,\n accessed:\n 2022-12-19. [Online]. Available: https:\/\/blog.trailofbits.com\/2021\/03\/15\/never-a-dill-moment-exploiting-machine-learning-pickle-files\/"},{"key":"ref12","unstructured":"P. Zhou, \u201cHow to make hugging face to hug worms: Discovering\nand exploiting unsafe pickle.loads over pre-trained large model\nhubs,\u201d accessed: 2024-08-01. [Online]. Available: https:\/\/i.blackhat.com\/Asia-24\/Presentations\/Asia-24-Zhou-HowtoMakeHuggingFace.pdf"},{"key":"ref13","unstructured":"M. Slaviero, \u201cSour pickles, a serialized exploitation guide in one part,\u201d\naccessed: 2023-05-01. [Online]. Available: https:\/\/media.blackhat.com\/bh-us-11\/Slaviero\/BH_US_11_Slaviero_Sour_Pickles_Slides.pdf"},{"key":"ref14","unstructured":"D. Gilkarov, \u201cAI-MTD Code Repository,\u201d 2025, accessed: 2025-06-04.\n[Online]. Available: https:\/\/github.com\/ArielCyber\/AI-model-MTD.git"},{"key":"ref15","doi-asserted-by":"crossref","unstructured":"J.-H. Cho, D. P. Sharma, H. Alavizadeh, S. Yoon, N. Ben-Asher, T. J.\nMoore, D. S. Kim, H. Lim, and F. F. Nelson, \u201cToward proactive, adaptive\ndefense: A survey on moving target defense,\u201d IEEE Communications\nSurveys & Tutorials, vol. 22, no. 1, pp. 709\u2013745, 2020.","DOI":"10.1109\/COMST.2019.2963791"},{"key":"ref16","doi-asserted-by":"crossref","unstructured":"V. Heydari, \u201cMoving target defense for securing scada communications,\u201d\nIEEE Access, vol. 6, pp. 33 329\u201333 343, 2018.","DOI":"10.1109\/ACCESS.2018.2844542"},{"key":"ref17","doi-asserted-by":"crossref","unstructured":"M. Azab and M. Eltoweissy, \u201cMigrate: Towards a lightweight moving-target defense against cloud side-channels,\u201d in 2016 IEEE security and\nprivacy workshops (SPW). IEEE, 2016, pp. 96\u2013103.","DOI":"10.1109\/SPW.2016.28"},{"key":"ref18","doi-asserted-by":"crossref","unstructured":"M. Styugin, V. Zolotarev, A. Prokhorov, and R. Gorbil, \u201cNew approach\nto software code diversification in interpreted languages based on the\nmoving target technology,\u201d in 2016 IEEE 10th International Conference\non Application of Information and Communication Technologies (AICT).\nIEEE, 2016, pp. 1\u20135.","DOI":"10.1109\/ICAICT.2016.7991694"},{"key":"ref19","doi-asserted-by":"crossref","unstructured":"S. Banescu and A. Pretschner, \u201cA tutorial on software obfuscation,\u201d\nAdvances in Computers, vol. 108, pp. 283\u2013353, 2018.","DOI":"10.1016\/bs.adcom.2017.09.004"},{"key":"ref20","unstructured":"G. Mordehai, Y. Elovici, and G. Kedma, \u201cMethod and system for\nprotecting computerized systems from malicious code,\u201d Jul. 11 2017,\nuS Patent 9,703,954."},{"key":"ref21","doi-asserted-by":"crossref","unstructured":"D. Evans, A. Nguyen-Tuong, and J. Knight, \u201cEffectiveness of moving\ntarget defenses,\u201d Moving Target Defense: Creating Asymmetric Uncertainty for Cyber Threats, pp. 29\u201348, 2011.","DOI":"10.1007\/978-1-4614-0977-9_2"},{"key":"ref22","unstructured":"R. Dubin, \u201cDisarming attacks inside neural network models code\nrepository,\u201d 2022, accessed: 2023-07-15. [Online]. Available: https:\/\/github.com\/ArielCyber\/AI-MODEL-CDR"},{"key":"ref23","unstructured":"Intel, \u201cReference architecture for privacy preserving machine learning\nwith intel\u00ae sgx and tensorflow* serving,\u201d accessed: 2023-05-01. [Online]. Available: https:\/\/www.intel.com\/content\/www\/us\/en\/developer\/articles\/technical\/privacy-preserving-ml-with-sgx-and-tensorflow.html"},{"key":"ref24","unstructured":"\u201cThe ai pc powered by intel is here. now, ai is for everyone.\u201d accessed:\n2023-05-01. [Online]. Available: https:\/\/www.intel.com\/content\/www\/us\/en\/products\/docs\/processors\/core-ultra\/ai-pc.html"},{"key":"ref25","unstructured":"A. Krizhevsky, I. Sutskever, and G. E. Hinton, \u201cImagenet classification\nwith deep convolutional neural networks,\u201d in Advances in Neural\nInformation Processing Systems, F. Pereira, C. Burges, L. Bottou,\nand K. Weinberger, Eds., vol. 25. Curran Associates, Inc.,\n2012. [Online]. Available: https:\/\/proceedings.neurips.cc\/paper_files\/paper\/2012\/file\/c399862d3b9d6b76c8436e924a68c45b-Paper.pdf"},{"key":"ref26","doi-asserted-by":"crossref","unstructured":"Z. Liu, H. Mao, C.-Y. Wu, C. Feichtenhofer, T. Darrell, and\nS. Xie, \u201cA convnet for the 2020s,\u201d 2022. [Online]. Available:\nhttps:\/\/arxiv.org\/abs\/2201.03545","DOI":"10.1109\/CVPR52688.2022.01167"},{"key":"ref27","doi-asserted-by":"crossref","unstructured":"G. Huang, Z. Liu, L. van der Maaten, and K. Q. Weinberger,\n\u201cDensely connected convolutional networks,\u201d 2018. [Online]. Available:\nhttps:\/\/arxiv.org\/abs\/1608.06993","DOI":"10.1109\/CVPR.2017.243"},{"key":"ref28","unstructured":"M. Tan and Q. V. Le, \u201cEfficientnet: Rethinking model scaling\nfor convolutional neural networks,\u201d 2020. [Online]. Available: https:\/\/arxiv.org\/abs\/1905.11946"},{"key":"ref29","unstructured":"\u2014\u2014, \u201cEfficientnetv2: Smaller models and faster training,\u201d 2021.\n[Online]. Available: https:\/\/arxiv.org\/abs\/2104.00298"},{"key":"ref30","doi-asserted-by":"crossref","unstructured":"I. Radosavovic, R. P. Kosaraju, R. Girshick, K. He, and P. Doll\u00e1r,\n\u201cDesigning network design spaces,\u201d 2020. [Online]. Available:\nhttps:\/\/arxiv.org\/abs\/2003.13678","DOI":"10.1109\/CVPR42600.2020.01044"},{"key":"ref31","unstructured":"L.-C. Chen, G. Papandreou, F. Schroff, and H. Adam, \u201cRethinking\natrous convolution for semantic image segmentation,\u201d 2017. [Online].\nAvailable: https:\/\/arxiv.org\/abs\/1706.05587"},{"key":"ref32","unstructured":"S. Ren, K. He, R. Girshick, and J. Sun, \u201cFaster r-cnn: Towards\nreal-time object detection with region proposal networks,\u201d 2016.\n[Online]. Available: https:\/\/arxiv.org\/abs\/1506.01497"},{"key":"ref33","unstructured":"Z. Liu, J. Ning, Y. Cao, Y. Wei, Z. Zhang, S. Lin, and H. Hu, \u201cVideo swin\ntransformer,\u201d 2021. [Online]. Available: https:\/\/arxiv.org\/abs\/2106.13230"},{"key":"ref34","unstructured":"J. Devlin, M.-W. Chang, K. Lee, and K. Toutanova, \u201cBert: Pre-training\nof deep bidirectional transformers for language understanding,\u201d 2019.\n[Online]. Available: https:\/\/arxiv.org\/abs\/1810.04805"},{"key":"ref35","unstructured":"A. Baevski, H. Zhou, A. Mohamed, and M. Auli, \u201cwav2vec 2.0:\nA framework for self-supervised learning of speech representations,\u201d\n2020. [Online]. Available: https:\/\/arxiv.org\/abs\/2006.11477"},{"key":"ref36","doi-asserted-by":"crossref","unstructured":"D. Gilkarov and R. Dubin, \u201cSteganalysis of ai models lsb attacks,\u201d IEEE\nTransactions on Information Forensics and Security, 2024.","DOI":"10.1109\/TIFS.2024.3383770"},{"key":"ref37","doi-asserted-by":"crossref","unstructured":"R. Dubin, \u201cContent disarm and reconstruction of steganography\nmalware in neural network models,\u201d 2023, accessed: 2022-01-15.\n[Online]. Available: https:\/\/github.com\/randubin\/CDR-NN","DOI":"10.2139\/ssrn.4590246"},{"key":"ref38","unstructured":"H. Face, \u201cSafetensors,\u201d accessed: 2024-08-01. [Online]. Available:\nhttps:\/\/huggingface.co\/docs\/safetensors\/en\/index"},{"key":"ref39","doi-asserted-by":"crossref","unstructured":"J. Zheng, P. P. Chan, H. Chi, and Z. He, \u201cA concealed poisoning attack\nto reduce deep neural networks\u2019 robustness against adversarial samples,\u201d\nInformation Sciences, vol. 615, pp. 758\u2013773, 2022.","DOI":"10.1016\/j.ins.2022.09.060"},{"key":"ref40","unstructured":"H. Face, \u201cHugging face model zoo,\u201d accessed: 2023-05-01. [Online].\nAvailable: https:\/\/huggingface.co\/models"}],"event":{"name":"20th Conference on Computer Science and Intelligence Systems (FedCSIS)","theme":"Computer Science and Intelligence Systems","location":"Krak\u00f3w, Poland","acronym":"FedCSIS","number":"20","start":{"date-parts":[[2025,9,14]]},"end":{"date-parts":[[2025,9,17]]}},"container-title":["Annals of Computer Science and Information Systems","Proceedings of the 20th Conference on Computer Science and Intelligence Systems (FedCSIS)"],"original-title":[],"deposited":{"date-parts":[[2025,10,22]],"date-time":"2025-10-22T07:51:13Z","timestamp":1761119473000},"score":1,"resource":{"primary":{"URL":"https:\/\/annals-csis.org\/Volume_43\/drp\/9981.html"}},"subtitle":[],"proceedings-subject":"Computer Science and Information Systems","short-title":[],"issued":{"date-parts":[[2025,10,15]]},"references-count":40,"URL":"https:\/\/doi.org\/10.15439\/2025f9981","relation":{},"ISSN":["2300-5963"],"issn-type":[{"value":"2300-5963","type":"print"}],"subject":[],"published":{"date-parts":[[2025,10,15]]}}}