{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,4]],"date-time":"2026-08-04T16:28:21Z","timestamp":1785860901052,"version":"3.56.0"},"reference-count":139,"publisher":"MDPI AG","issue":"2","license":[{"start":{"date-parts":[[2023,5,4]],"date-time":"2023-05-04T00:00:00Z","timestamp":1683158400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Penn State InudstryXchange"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JCP"],"abstract":"<jats:p>Recent advances in machine learning have created an opportunity to embed artificial intelligence in software-intensive systems. These artificial intelligence systems, however, come with a new set of vulnerabilities making them potential targets for cyberattacks. This research examines the landscape of these cyber attacks and organizes them into a taxonomy. It further explores potential defense mechanisms to counter such attacks and the use of these mechanisms early during the development life cycle to enhance the safety and security of artificial intelligence systems.<\/jats:p>","DOI":"10.3390\/jcp3020010","type":"journal-article","created":{"date-parts":[[2023,5,5]],"date-time":"2023-05-05T03:57:31Z","timestamp":1683259051000},"page":"166-190","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":31,"title":["Cybersecurity for AI Systems: A Survey"],"prefix":"10.3390","volume":"3","author":[{"given":"Raghvinder S.","family":"Sangwan","sequence":"first","affiliation":[{"name":"School of Graduate Professional Studies, The Pennsylvania State University, 30 E. Swedesford Road, Malvern, PA 19355, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8976-7894","authenticated-orcid":false,"given":"Youakim","family":"Badr","sequence":"additional","affiliation":[{"name":"School of Graduate Professional Studies, The Pennsylvania State University, 30 E. Swedesford Road, Malvern, PA 19355, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Satish M.","family":"Srinivasan","sequence":"additional","affiliation":[{"name":"School of Graduate Professional Studies, The Pennsylvania State University, 30 E. Swedesford Road, Malvern, PA 19355, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2023,5,4]]},"reference":[{"key":"ref_1","unstructured":"Comiter, M. (2023, March 08). Attacking Artificial Intelligence: AI\u2019s Security Vulnerability and What Policymakers Can Do about It. Available online: https:\/\/www.belfercenter.org\/sites\/default\/files\/2019-08\/AttackingAI\/AttackingAI.pdf."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"54","DOI":"10.1109\/MC.2019.2909955","article-title":"Security engineering for machine learning","volume":"52","author":"Mcgraw","year":"2019","journal-title":"IEEE Comput."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"1075","DOI":"10.1109\/TVCG.2019.2934631","article-title":"Explaining vulnerabilities to adversarial machine learning through visual analytics","volume":"26","author":"Ma","year":"2019","journal-title":"IEEE Trans. Vis. Comput. Graph."},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Kim, J., and Park, N. (2020). Blockchain-based data-preserving AI learning environment model for AI cybersecurity systems in IoT service environments. Appl. Sci., 10.","DOI":"10.3390\/app10144718"},{"key":"ref_5","first-page":"1893","article-title":"Systematic poisoning attacks on and defenses for machine learning in healthcare","volume":"19","author":"Raghunathan","year":"2014","journal-title":"IEEE J. Biomed. Health Inform."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"450","DOI":"10.1109\/TETCI.2020.2968933","article-title":"A system-driven taxonomy of attacks and defenses in adversarial machine learning","volume":"4","author":"Sadeghi","year":"2020","journal-title":"IEEE Trans. Emerg. Top. Comput. Intell."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Sagar, R., Jhaveri, R., and Borrego, C. (2020). Applications in security and evasions in machine learning: A survey. Electronics, 9.","DOI":"10.3390\/electronics9010097"},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"100199","DOI":"10.1016\/j.cosrev.2019.100199","article-title":"A taxonomy and survey of attacks against machine learning","volume":"34","author":"Pitropakis","year":"2019","journal-title":"Comput. Sci. Rev."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"2929","DOI":"10.1007\/s12652-018-0714-6","article-title":"Handling the adversarial attacks","volume":"10","author":"Cao","year":"2019","journal-title":"J. Ambient. Intell. Humaniz. Comput."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"12","DOI":"10.1016\/j.jpdc.2019.03.003","article-title":"The security of machine learning in an adversarial setting: A survey","volume":"130","author":"Wang","year":"2019","journal-title":"J. Parallel Distrib. Comput."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"31","DOI":"10.1109\/MSEC.2018.2888779","article-title":"Safe machine learning and defeating adversarial attacks","volume":"17","author":"Rouani","year":"2019","journal-title":"IEEE Secur."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Qiu, S., Liu, Q., Zhou, S., and Wu, C. (2019). Review of artificial intelligence adversarial attack and defense technologies. Appl. Sci., 9.","DOI":"10.3390\/app9050909"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"317","DOI":"10.1016\/j.patcog.2018.07.023","article-title":"Wild patterns: Ten years after the rise of adversarial machine learning","volume":"84","author":"Biggio","year":"2018","journal-title":"Pattern Recognit."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"e1245","DOI":"10.1002\/widm.1245","article-title":"A dynamic-adversarial mining approach to the security of machine learning","volume":"8","author":"Sethi","year":"2018","journal-title":"Wiley Interdiscip. Rev. Data Min. Knowl. Discov."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1186\/s42400-019-0027-x","article-title":"Adversarial attack and defense in reinforcement learning-from AI security view","volume":"2","author":"Chen","year":"2019","journal-title":"Cybersecurity"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"3267","DOI":"10.1109\/TII.2019.2951766","article-title":"DeSVig: Decentralized swift vigilance against adversarial attacks in industrial artificial intelligence systems","volume":"16","author":"Li","year":"2019","journal-title":"IEEE Trans. Ind. Inform."},{"key":"ref_17","first-page":"1","article-title":"A Genetic Attack Against Machine Learning Classifiers to Steal Biometric Actigraphy Profiles from Health Related Sensor Data","volume":"44","author":"Morin","year":"2020","journal-title":"J. Med. Syst."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"31","DOI":"10.1109\/MSP.2015.2426728","article-title":"Adversarial biometric recognition: A review on biometric system security from the adversarial machine-learning perspective","volume":"32","author":"Biggio","year":"2015","journal-title":"IEEE Signal Process. Mag."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"101698","DOI":"10.1016\/j.cose.2019.101698","article-title":"Query-efficient label-only attacks against black-box machine learning models","volume":"90","author":"Ren","year":"2020","journal-title":"Comput. Secur."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"2074","DOI":"10.1109\/TDSC.2020.3021008","article-title":"Man-in-the-middle attacks against machine learning classifiers via malicious generative models","volume":"18","author":"Wang","year":"2020","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"95","DOI":"10.1109\/MVT.2020.3002487","article-title":"Artificial intelligence security in 5G networks: Adversarial examples for estimating a travel time task","volume":"15","author":"Qiu","year":"2020","journal-title":"IEEE Veh. Technol. Mag."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"140","DOI":"10.1109\/MNET.011.2000088","article-title":"AI for beyond 5G networks: A cyber-security defense or offense enabler?","volume":"34","author":"Benzaid","year":"2020","journal-title":"IEEE Networks"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Apruzzese, G., Andreolini, M., Marchetti, M., Colacino, V.G., and Russo, G. (2020). AppCon: Mitigating Evasion Attacks to ML Cyber Detectors. Symmetry, 12.","DOI":"10.3390\/sym12040653"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"128250","DOI":"10.1109\/ACCESS.2020.3008433","article-title":"A brute-force black-box method to attack machine learning-based systems in cybersecurity","volume":"8","author":"Zhang","year":"2020","journal-title":"IEEE Access"},{"key":"ref_25","first-page":"1","article-title":"Adversarial perturbation attacks on ML-based cad: A case study on CNN-based lithographic hotspot detection","volume":"25","author":"Liu","year":"2020","journal-title":"ACM Trans. Des. Autom. Electron. Syst."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"419","DOI":"10.1016\/j.eswa.2017.09.053","article-title":"Quantifying the resilience of machine learning classifiers used for cyber security","volume":"92","author":"Katzir","year":"2018","journal-title":"Expert Syst. Appl."},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"326","DOI":"10.1016\/j.cose.2017.11.007","article-title":"Automated poisoning attacks and defenses in malware detection systems: An adversarial machine learning approach","volume":"73","author":"Chen","year":"2018","journal-title":"Comput. Secur."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3003816","article-title":"On the security of machine learning in malware c&c detection: A survey","volume":"49","author":"Gardiner","year":"2016","journal-title":"ACM Comput. Surv."},{"key":"ref_29","first-page":"31","article-title":"A survey of game theoretic approaches for adversarial machine learning in cybersecurity tasks","volume":"40","author":"Dasgupta","year":"2019","journal-title":"AI Mag."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"49","DOI":"10.1109\/MSEC.2018.2888775","article-title":"Privacy-preserving machine learning: Threats and solutions","volume":"17","author":"Chang","year":"2019","journal-title":"IEEE Secur. Priv."},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"31","DOI":"10.1016\/j.cose.2004.06.011","article-title":"A taxonomy of network and computer attacks","volume":"24","author":"Hansman","year":"2005","journal-title":"Comput. Secur."},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"554","DOI":"10.1007\/s12204-013-1439-5","article-title":"Ontology-based model of network and computer attacks for security assessment","volume":"18","author":"Gao","year":"2013","journal-title":"J. Shanghai Jiaotong Univ."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"38","DOI":"10.1093\/itnow\/bwy018","article-title":"The secret of machine learning","volume":"60","author":"Gonzalez","year":"2018","journal-title":"ITNow"},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"68","DOI":"10.1109\/MSP.2016.51","article-title":"Machine learning in adversarial settings","volume":"14","author":"Mcdaniel","year":"2016","journal-title":"IEEE Secur. Priv."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"121","DOI":"10.1007\/s10994-010-5188-5","article-title":"The security of machine learning","volume":"81","author":"Barreno","year":"2010","journal-title":"Mach. Learn."},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Barreno, M., Nelson, B., Sears, R., Joseph, A.D., and Tygar, J.D. (2006, January 21\u201324). Can machine learning be secure?. Proceedings of the 2006 ACM Symposium on Information, Computer and Communications Security, Taipei, Taiwan.","DOI":"10.1145\/1128817.1128824"},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"984","DOI":"10.1109\/TKDE.2013.57","article-title":"Security evaluation of pattern classifiers under attack","volume":"26","author":"Biggio","year":"2013","journal-title":"IEEE Trans. Knowl. Data Eng."},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Mu\u00f1oz-Gonz\u00e1lez, L., Biggio, B., Demontis, A., Paudice, A., Wongrassamee, V., Lupu, E.C., and Roli, F. (2017, January 3). Towards poisoning of deep learning algorithms with back-gradient optimization. Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security, Dallas, TX, USA.","DOI":"10.1145\/3128572.3140451"},{"key":"ref_39","unstructured":"Nelson, B., Barreno, M., Chi, F.J., Joseph, A.D., Rubinstein, B.I., Saini, U., Sutton, C., Tygar, J.D., and Xia, K. (2008, January 15). Exploiting machine learning to subvert your spam filter. Proceedings of the First USENIX Workshop on Large Scale Exploits and Emergent Threats, San Francisco, CA, USA."},{"key":"ref_40","unstructured":"Biggio, B., Nelson, B., and Laskov, P. (2012). Poisoning attacks against support vector machines. arXiv."},{"key":"ref_41","unstructured":"Bhagoji, A.N., Chakraborty, S., Mittal, P., and Calo, S. (2018, January 7). Model poisoning attacks in federated learning. Proceedings of the Workshop on Security in Machine Learning (SecML), Collocated with the 32nd Conference on Neural Information Processing Systems, Montreal, QC, Canada."},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"47230","DOI":"10.1109\/ACCESS.2019.2909068","article-title":"Badnets: Evaluating backdooring attacks on deep neural networks","volume":"7","author":"Gu","year":"2019","journal-title":"IEEE Access"},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Samuel, J., Mathewson, N., Cappos, J., and Dingledine, R. (2010, January 4\u20138). Survivable key compromise in software update systems. Proceedings of the 17th ACM Conference on Computer and Communications Security, Chicago, IL, USA.","DOI":"10.1145\/1866307.1866315"},{"key":"ref_44","doi-asserted-by":"crossref","unstructured":"Liu, K., Dolan-Gavitt, B., and Garg, S. (2018, January 10\u201312). Fine-pruning: Defending against backdooring attacks on deep neural networks. Proceedings of the International Symposium on Research in Attacks, Intrusions, and Defenses, Heraklion, Crete, Greece.","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"ref_45","unstructured":"Gu, T., Dolan-Gavitt, B., and Garg, S. (2017). Badnets: Identifying vulnerabilities in the machine learning model supply chain. arXiv."},{"key":"ref_46","doi-asserted-by":"crossref","unstructured":"Wang, B., Yao, Y., Shan, S., Li, H., Viswanath, B., Zheng, H., and Zhao, B.Y. (2019, January 19\u201323). Neural cleanse: Identifying and mitigating backdoor attacks in neural networks. Proceedings of the IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA.","DOI":"10.1109\/SP.2019.00031"},{"key":"ref_47","unstructured":"Mcmahan, B., Moore, E., Ramage, D., Hampson, S., and Arcas, B.A. (2017, January 20\u201322). Communication-efficient learning of deep networks from decentralized data. Proceedings of the 20th International Conference of Artificial Intelligence and Statistics, Fort Lauderdale, FL, USA."},{"key":"ref_48","unstructured":"Bagdasaryan, E., Veit, A., Hua, Y., Estrin, D., and Shmatikov, V. (2020, January 26\u201328). How to backdoor federated learning. Proceedings of the International Conference on Artificial Intelligence and Statistics, Online."},{"key":"ref_49","doi-asserted-by":"crossref","unstructured":"Shokri, R., Stronati, M., Song, C., and Shmatikov, V. (2017, January 22\u201326). Membership inference attacks against machine learning models. Proceedings of the 2017 IEEE Symposium on Security and Privacy (SP), San Jose, CA, USA.","DOI":"10.1109\/SP.2017.41"},{"key":"ref_50","doi-asserted-by":"crossref","unstructured":"Salem, A., Zhang, Y., Humbert, M., Berrang, P., Fritz, M., and Backes, M. (2018). ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning Models. arXiv.","DOI":"10.14722\/ndss.2019.23119"},{"key":"ref_51","doi-asserted-by":"crossref","unstructured":"Jia, J., Salem, A., Backes, M., Zhang, Y., and Gong, N.Z. (2019, January 11\u201315). Memguard: Defending against black-box membership inference attacks via adversarial examples. Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, London, UK.","DOI":"10.1145\/3319535.3363201"},{"key":"ref_52","first-page":"265","article-title":"Calibrating noise to sensitivity in private data analysis","volume":"3876","author":"Dwork","year":"2006","journal-title":"Theory Cryptogr. Conf."},{"key":"ref_53","first-page":"601","article-title":"Stealing machine learning models via prediction apis","volume":"16","author":"Zhang","year":"2016","journal-title":"USENIX Secur. Symp."},{"key":"ref_54","doi-asserted-by":"crossref","unstructured":"Reith, R.N., Schneider, T., and Tkachenko, O. (2019, January 11). Efficiently stealing your machine learning models. Proceedings of the 18th ACM Workshop on Privacy in the Electronic Society, London, UK.","DOI":"10.1145\/3338498.3358646"},{"key":"ref_55","doi-asserted-by":"crossref","unstructured":"Weinsberg, U., Bhagat, S., Ioannidis, S., and Taft, N. (2012, January 9\u201313). BlurMe: Inferring and obfuscating user gender based on ratings. Proceedings of the Sixth ACM Conference on Recommender Systems, Dublin, Ireland.","DOI":"10.1145\/2365952.2365989"},{"key":"ref_56","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3372823","article-title":"The AI-based cyber threat landscape: A survey","volume":"53","author":"Kaloudi","year":"2020","journal-title":"ACM Comput. Surv."},{"key":"ref_57","unstructured":"Turchin, A. (2023, March 08). A Map: AGI Failures Modes and Levels, 2023. Available online: https:\/\/www.lesswrong.com\/posts\/hMQ5iFiHkChqgrHiH\/a-map-agi-failures-modes-and-levels."},{"key":"ref_58","doi-asserted-by":"crossref","first-page":"147","DOI":"10.1007\/s00146-018-0845-5","article-title":"Classification of global catastrophic risks connected with artificial intelligence","volume":"35","author":"Turchin","year":"2020","journal-title":"AI Soc."},{"key":"ref_59","unstructured":"Yampolskiy, R.V. (2016, January 12\u201313). Taxonomy of pathways to dangerous artificial intelligence. Proceedings of the Workshops at the Thirtieth AAAI Conference on Artificial Intelligence, Phoenix, AZ, USA."},{"key":"ref_60","unstructured":"Kumar, R.S.S., Brien, D.O., Albert, K., Vilj\u00f6en, S., and Snover, J. (2023, March 08). Failure Modes in Machine Learning. Available online: https:\/\/arxiv.org\/ftp\/arxiv\/papers\/1911\/1911.11034.pdf."},{"key":"ref_61","unstructured":"Hadfield-Menell, D., Milli, S., Abbeel, P., Russell, S., and Dragan, A. (2023, March 08). Inverse Reward Design. Available online: https:\/\/proceedings.neurips.cc\/paper\/2017\/hash\/32fdab6559cdfa4f167f8c31b9199643-Abstract.html."},{"key":"ref_62","doi-asserted-by":"crossref","first-page":"2874","DOI":"10.1007\/s10489-019-01417-4","article-title":"A novel multi-step reinforcement learning method for solving reward hacking","volume":"49","author":"Yuan","year":"2019","journal-title":"Appl. Intell."},{"key":"ref_63","unstructured":"Leike, J., Martic, M., Krakovna, V., Ortega, P.A., Everitt, T., Lefrancq, A., Orseau, L., and Legg, S. (2017). AI safety Gridworlds. arXiv."},{"key":"ref_64","unstructured":"Zhang, A., Lipton, Z.C., Li, M., and Smola, A. (2021). Dive into Deep Learning. arXiv."},{"key":"ref_65","first-page":"345","article-title":"From development to deployment: Dataset shift, causality, and shift-stable models in health AI","volume":"21","author":"Subbaswamy","year":"2020","journal-title":"Biostatistics"},{"key":"ref_66","first-page":"1309","article-title":"Invariant models for causal transfer learning","volume":"19","author":"Turner","year":"2018","journal-title":"J. Mach. Learn. Res."},{"key":"ref_67","doi-asserted-by":"crossref","first-page":"215","DOI":"10.1111\/rssb.12398","article-title":"Anchor regression: Heterogeneous data meet causality","volume":"83","author":"Meinshausen","year":"2021","journal-title":"J. R. Stat. Soc. Ser. B"},{"key":"ref_68","unstructured":"Gilmer, J., Adams, R.P., Goodfellow, I., Andersen, D., and Dahl, G.E. (2018). Motivating the Rules of the Game for Adversarial Example Research. arXiv."},{"key":"ref_69","unstructured":"Zhao, Z., Dua, D., and Singh, S. (2017). Generating natural adversarial examples. arXiv."},{"key":"ref_70","unstructured":"Chakraborty, A., Alam, M., Dey, V., Chattopadhyay, A., and Mukhopadhyay, D. (2018). Adversarial attacks and defences: A survey. arXiv."},{"key":"ref_71","doi-asserted-by":"crossref","unstructured":"Hitaj, B., Ateniese, G., and Perez-Cruz, F. (November, January 30). Deep models under the GAN: Information leakage from collaborative deep learning. Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, Dallas, TX, USA.","DOI":"10.1145\/3133956.3134012"},{"key":"ref_72","unstructured":"Tram\u00e8r, F., Kurakin, A., Papernot, N., Goodfellow, I., Boneh, D., and Mcdaniel, P. (2017). Ensemble adversarial training: Attacks and defenses. arXiv."},{"key":"ref_73","unstructured":"Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R. (2013). Intriguing properties of neural networks. arXiv."},{"key":"ref_74","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A. (2017). Towards deep learning models resistant to adversarial attacks. arXiv."},{"key":"ref_75","unstructured":"Papernot, N., Mcdaniel, P., and Goodfellow, I. (2016). Transferability in Machine Learning: From Phenomena to Black-Box Attacks using Adversarial Samples. arXiv."},{"key":"ref_76","doi-asserted-by":"crossref","unstructured":"Pang, R., Zhang, X., Ji, S., Luo, X., and Wang, T. (2020, January 6\u201310). AdvMind: Inferring Adversary Intent of Black-Box Attacks. Proceedings of the 26th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining, Virtual Event.","DOI":"10.1145\/3394486.3403241"},{"key":"ref_77","doi-asserted-by":"crossref","unstructured":"Vivek, B., Mopuri, K.R., and Babu, R.V. (2018, January 8\u201314). Gray-box adversarial training. Proceedings of the European Conference on Computer Vision, Munich, Germany.","DOI":"10.1007\/978-3-030-01267-0_13"},{"key":"ref_78","first-page":"1","article-title":"Securing your control system","volume":"112","author":"Fenrich","year":"2008","journal-title":"Power Eng."},{"key":"ref_79","unstructured":"Ilmoi (2023, March 08). Poisoning attacks on Machine Learning: A 15-year old security problem that\u2019s making a comeback. Available online: https:\/\/towardsdatascience.com\/poisoning-attacks-on-machine-learning-1ff247c254db."},{"key":"ref_80","first-page":"65","article-title":"Learning in a large function space: Privacy-preserving mechanisms for SVM learning","volume":"4","author":"Rubinstein","year":"2012","journal-title":"J. Priv. Confidentiality"},{"key":"ref_81","unstructured":"Steinhardt, J., Koh, P.W., and Liang, P. (2017, January 4\u20139). Certified defenses for data poisoning attacks. Proceedings of the 31st International Conference on Neural Information Processing Systems, Long Beach, CA, USA."},{"key":"ref_82","doi-asserted-by":"crossref","unstructured":"Mei, S., and Zhu, X. (2015, January 25\u201330). Using machine teaching to identify optimal training-set attacks on machine learners. Proceedings of the Twenty-Ninth AAAI Conference on Artificial Intelligence, Austin, TX, USA.","DOI":"10.1609\/aaai.v29i1.9569"},{"key":"ref_83","unstructured":"Kloft, M., and Laskov, P. (2010, January 13\u201315). Online anomaly detection under adversarial impact. Proceedings of the 13th International Conference on Artificial Intelligence and Statistics, Sardinia, Italy."},{"key":"ref_84","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/s10994-021-06119-y","article-title":"Stronger data poisoning attacks break data sanitization defenses","volume":"111","author":"Koh","year":"2022","journal-title":"Mach. Learn."},{"key":"ref_85","unstructured":"Shafahi, A., Huang, W.R., Najibi, M., Suciu, O., Studer, C., Dumitras, T., and Goldstein, T. (2018, January 3\u20138). Poison frogs! targeted clean-label poisoning attacks on Neural Networks. Proceedings of the 32nd International Conference on Neural Information Processing Systems, Montr\u00e9al, QC, Canada."},{"key":"ref_86","unstructured":"Suciu, O., Marginean, R., Kaya, Y., Daume, H., and Dumitras, T. (2018, January 15\u201317). When does machine learning {FAIL}? generalized transferability for evasion and poisoning attacks. Proceedings of the 27th Security Symposium, USENIX, Baltimore, MD, USA."},{"key":"ref_87","unstructured":"Goodfellow, I.J., Shlens, J., and Szegedy, C. (2014). Explaining and harnessing adversarial examples. arXiv."},{"key":"ref_88","doi-asserted-by":"crossref","unstructured":"Lyu, C., Huang, K., and Liang, H.N. (2015, January 14\u201317). A unified gradient regularization family for adversarial examples. Proceedings of the 2015 IEEE International Conference on Data Mining, Atlantic City, NJ, USA.","DOI":"10.1109\/ICDM.2015.84"},{"key":"ref_89","unstructured":"Papernot, N., and Mcdaniel, P. (2017). Extending defensive distillation. arXiv."},{"key":"ref_90","doi-asserted-by":"crossref","unstructured":"Papernot, N., Mcdaniel, P., Goodfellow, I., Jha, S., Celik, Z.B., and Swami, A. (2017, January 2\u20136). Practical black-box attacks against machine learning. Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security, Abu Dhabi, United Arab Emirates.","DOI":"10.1145\/3052973.3053009"},{"key":"ref_91","doi-asserted-by":"crossref","unstructured":"Xu, W., Evans, D., and Qi, Y. (2017). Feature squeezing: Detecting adversarial examples in deep neural networks. arXiv.","DOI":"10.14722\/ndss.2018.23198"},{"key":"ref_92","unstructured":"Hosseini, H., Chen, Y., Kannan, S., Zhang, B., and Poovendran, R. (2017). Blocking transferability of adversarial examples in black-box learning systems. arXiv."},{"key":"ref_93","doi-asserted-by":"crossref","unstructured":"Meng, D., and Chen, H. (November, January 30). Magnet: A two-pronged defense against adversarial examples. Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, Dallas, TX, USA.","DOI":"10.1145\/3133956.3134057"},{"key":"ref_94","doi-asserted-by":"crossref","first-page":"139","DOI":"10.1145\/3422622","article-title":"Generative adversarial networks","volume":"63","author":"Goodfellow","year":"2020","journal-title":"Commun. ACM"},{"key":"ref_95","unstructured":"Samangouei, P., Kabkab, M., and Chellappa, R. (2018). Defense-gan: Protecting classifiers against adversarial attacks using generative models. arXiv."},{"key":"ref_96","doi-asserted-by":"crossref","unstructured":"Weerasinghe, S., Alpcan, T., Erfani, S.M., and Leckie, C. (2020). Defending Distributed Classifiers Against Data Poisoning Attacks. arXiv.","DOI":"10.1109\/TIFS.2021.3058771"},{"key":"ref_97","unstructured":"Efron, B. (1982). CBMS-NSF Regional Conference Series in Applied Mathematics, Society for Industrial and Applied Mathematics."},{"key":"ref_98","unstructured":"Paudice, A., Mu\u00f1oz-Gonz\u00e1lez, L., and Lupu, E.C. (2018). Joint European Conference on Machine Learning and Knowledge Discovery in Databases, Springer."},{"key":"ref_99","unstructured":"Paudice, A., Mu\u00f1oz-Gonz\u00e1lez, L., Gyorgy, A., and Lupu, E.C. (2018). Detection of adversarial training examples in poisoning attacks through anomaly detection. arXiv."},{"key":"ref_100","doi-asserted-by":"crossref","unstructured":"Rubinstein, B.I., Nelson, B., Huang, L., Joseph, A.D., Lau, S., Rao, S., Taft, N., and Tygar, J.D. (2009, January 4\u20136). Antidote: Understanding and defending against poisoning of anomaly detectors. Proceedings of the 9th ACM SIGCOMM Conference on Internet Measurement, Chicago, IL, USA.","DOI":"10.1145\/1644893.1644895"},{"key":"ref_101","doi-asserted-by":"crossref","first-page":"2278","DOI":"10.1109\/5.726791","article-title":"Gradient-based learning applied to document recognition","volume":"86","author":"Lecun","year":"1998","journal-title":"Proc. IEEE"},{"key":"ref_102","unstructured":"Koh, P.W., and Liang, P. (2017, January 6\u201311). Understanding black-box predictions via influence functions. Proceedings of the International Conference on Machine Learning, Sydney, NSW, Australia."},{"key":"ref_103","first-page":"116","article-title":"Research Application of the Spam Filtering and Spammer Detection Algorithms on Social Media","volume":"3171","author":"Liubchenko","year":"2022","journal-title":"CEUR Workshop Proc."},{"key":"ref_104","doi-asserted-by":"crossref","first-page":"103070","DOI":"10.1016\/j.cose.2022.103070","article-title":"An automatic classification algorithm for software vulnerability based on weighted word vector and fusion neural network","volume":"126","author":"Wang","year":"2023","journal-title":"Comput. Secur."},{"key":"ref_105","doi-asserted-by":"crossref","unstructured":"Peri, N., Gupta, N., Huang, W.R., Fowl, L., Zhu, C., Feizi, S., Goldstein, T., and Dickerson, J.P. (2020, January 23\u201328). Deep k-NN defense against clean-label data poisoning attacks. Proceedings of the European Conference on Computer, Glasgow, UK.","DOI":"10.1007\/978-3-030-66415-2_4"},{"key":"ref_106","unstructured":"Natarajan, J. (2020). AI and Big Data\u2019s Potential for Disruptive Innovation, IGI Global."},{"key":"ref_107","unstructured":"Tran, B., Li, J., and Madry, A. (2018, January 3\u20138). Spectral Signatures in Backdoor Attacks. Proceedings of the 32nd International Conference on Neural Information Processing Systems, Montr\u00e9al, QC, Canada."},{"key":"ref_108","doi-asserted-by":"crossref","first-page":"77","DOI":"10.1007\/s10462-018-09679-z","article-title":"Machine Learning and Deep Learning frameworks and libraries for large-scale","volume":"52","author":"Nguyen","year":"2019","journal-title":"Artif. Intell. Rev."},{"key":"ref_109","unstructured":"Wu, B., Wang, S., Yuan, X., Wang, C., Rudolph, C., and Yang, X. (2019). Defending Against Misclassification Attacks in Transfer Learning. arXiv."},{"key":"ref_110","doi-asserted-by":"crossref","first-page":"2163","DOI":"10.1109\/ACCESS.2015.2494536","article-title":"Channel-level acceleration of deep face representations","volume":"3","author":"Polyak","year":"2015","journal-title":"IEEE Access"},{"key":"ref_111","first-page":"118","article-title":"Machine learning with adversaries: Byzantine tolerant gradient descent","volume":"30","author":"Blanchard","year":"2017","journal-title":"31st Conf. Neural Inf. Process. Syst."},{"key":"ref_112","first-page":"1","article-title":"Distributed statistical machine learning in adversarial settings: Byzantine gradient descent","volume":"1","author":"Chen","year":"2017","journal-title":"Proc. Acm Meas. Anal. Comput. Syst."},{"key":"ref_113","unstructured":"Lundberg, S.M., and Lee, S.I. (2017, January 4\u20139). A unified approach to interpreting model predictions. Proceedings of the 31st International Conference on Neural Information Processing Systems, Long Beach, CA, USA."},{"key":"ref_114","unstructured":"Guerraoui, R., and Rouault, S. (2018, January 10\u201315). The hidden vulnerability of distributed learning in byzantium. Proceedings of the International Conference on Machine Learning, Stockholm, Sweden."},{"key":"ref_115","doi-asserted-by":"crossref","first-page":"1142","DOI":"10.1109\/TSP.2022.3153135","article-title":"Robust aggregation for federated learning","volume":"70","author":"Pillutla","year":"2022","journal-title":"IEEE Trans. Signal Process."},{"key":"ref_116","unstructured":"Yin, D., Chen, Y., Kannan, R., and Bartlett, P. (2018, January 10\u201315). Byzantine-robust distributed learning: Towards optimal statistical rates. Proceedings of the International Conference on Machine Learning, Stockholm, Sweden."},{"key":"ref_117","unstructured":"Bernstein, J., Wang, Y.X., Azizzadenesheli, K., and Anandkumar, A. (2018, January 10\u201315). signSGD: Compressed optimisation for non-convex problems. Proceedings of the International Conference on Machine Learning, Stockholm, Sweden."},{"key":"ref_118","unstructured":"Fung, C., Yoon, C.J., and Beschastnikh, I. (2018). Mitigating sybils in federated learning poisoning. arXiv."},{"key":"ref_119","unstructured":"Liu, Y., Yi, Z., and Chen, T. (2020). Backdoor attacks and defenses in feature-partitioned collaborative learning. arXiv."},{"key":"ref_120","unstructured":"Ozdayi, M.S., Kantarcioglu, M., and Gel, Y.R. (2023, March 08). Defending against Backdoors in Federated Learning with Robust Learning Rate. Available online: https:\/\/ojs.aaai.org\/index.php\/AAAI\/article\/view\/17118\/16925."},{"key":"ref_121","doi-asserted-by":"crossref","unstructured":"Yang, Z., Zhang, J., Chang, E.C., and Liang, Z. (2019, January 11\u201315). Neural network inversion in adversarial setting via background knowledge alignment. Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, London, UK.","DOI":"10.1145\/3319535.3354261"},{"key":"ref_122","doi-asserted-by":"crossref","unstructured":"Fredrikson, M., Lantz, E., Jha, S., Lin, S., Page, D., and Ristenpart, T. (2015, January 12\u201316). Model inversion attacks that exploit confidence information and basic countermeasures. Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, Denver, CO, USA.","DOI":"10.1145\/2810103.2813677"},{"key":"ref_123","doi-asserted-by":"crossref","unstructured":"Hidano, S., Murakai, T., Katsumata, S., Kiyomoto, S., and Hanaoka, G. (2017, January 28\u201330). Model inversion attacks for prediction systems: Without knowledge of non-sensitive attributes. Proceedings of the 2017 15th Annual Conference on Privacy, Security and Trust (PST), Calgary, AB, Canada.","DOI":"10.1109\/PST.2017.00023"},{"key":"ref_124","doi-asserted-by":"crossref","unstructured":"Wu, X., Fredrikson, M., Jha, S., and Naughton, J.F. (July, January 27). A methodology for formalizing model-inversion attacks. Proceedings of the 2016 IEEE 29th Computer Security Foundations Symposium (CSF), Lisbon, Portugal.","DOI":"10.1109\/CSF.2016.32"},{"key":"ref_125","doi-asserted-by":"crossref","unstructured":"Zhang, Y., Jia, R., Pei, H., Wang, W., Li, B., and Song, D. (2020, January 13\u201319). The secret revealer: Generative model-inversion attacks against deep neural networks. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Seattle, WA, USA.","DOI":"10.1109\/CVPR42600.2020.00033"},{"key":"ref_126","doi-asserted-by":"crossref","first-page":"137","DOI":"10.1504\/IJSN.2015.071829","article-title":"Hacking smart machines with smarter ones: How to extract meaningful data from machine learning classifiers","volume":"10","author":"Ateniese","year":"2015","journal-title":"Int. J. Secur. Networks"},{"key":"ref_127","doi-asserted-by":"crossref","unstructured":"Juuti, M., Szyller, S., Marchal, S., and Asokan, N. (2019, January 17\u201319). PRADA: Protecting against DNN model stealing attacks. Proceedings of the 2019 IEEE European Symposium on Security and Privacy (EuroS&P), Stockholm, Sweden.","DOI":"10.1109\/EuroSP.2019.00044"},{"key":"ref_128","doi-asserted-by":"crossref","unstructured":"Wang, B., and Gong, N.Z. (2018, January 21\u201323). Stealing hyperparameters in machine learning. Proceedings of the 2018 IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA.","DOI":"10.1109\/SP.2018.00038"},{"key":"ref_129","first-page":"1010","article-title":"Model Extraction Attacks on Recurrent Neural Networks","volume":"28","author":"Takemura","year":"2020","journal-title":"J. Inf. Process."},{"key":"ref_130","unstructured":"Hinton, G., Vinyals, O., and Dean, J. (2015). Distilling the knowledge in a neural network. arXiv."},{"key":"ref_131","unstructured":"Hsu, Y.C., Hua, T., Chang, S., Lou, Q., Shen, Y., and Jin, H. (2022). Language model compression with weighted low-rank factorization. arXiv."},{"key":"ref_132","unstructured":"Chandrasekaran, V., Chaudhuri, K., Giacomelli, I., Jha, S., and Yan, S. (2020, January 12\u201314). Exploring connections between active learning and model extraction. Proceedings of the 29th Security Symposium (USENIX), Boston, MA, USA."},{"key":"ref_133","doi-asserted-by":"crossref","unstructured":"Lee, T., Edwards, B., Molloy, I., and Su, D. (2019, January 20\u201322). Defending against neural network model stealing attacks using deceptive perturbations. Proceedings of the 2019 IEEE Security and Privacy Workshops (SPW), San Francisco, CA, USA.","DOI":"10.1109\/SPW.2019.00020"},{"key":"ref_134","doi-asserted-by":"crossref","unstructured":"Kesarwani, M., Mukhoty, B., Arya, V., and Mehta, S. (2018, January 3\u20137). Model extraction warning in MLaaS paradigm. Proceedings of the 34th Annual Computer Security Applications Conference, San Juan, PR, USA.","DOI":"10.1145\/3274694.3274740"},{"key":"ref_135","first-page":"17","article-title":"Privacy in Pharmacogenetics: An End-to-End Case Study of Personalized Warfarin Dosing","volume":"1","author":"Fredrikson","year":"2014","journal-title":"Proc. Usenix Secur. Symp."},{"key":"ref_136","unstructured":"Chaabane, A., Acs, G., and Kaafar, M.A. (2012, January 5\u20138). You are what you like! information leakage through users\u2019 interests. Proceedings of the 19th Annual Network & Distributed System Security Symposium (NDSS), San Diego, CA, USA."},{"key":"ref_137","doi-asserted-by":"crossref","first-page":"5802","DOI":"10.1073\/pnas.1218772110","article-title":"Private traits and attributes are predictable from digital records of human behavior","volume":"110","author":"Kosinski","year":"2013","journal-title":"Proc. Natl. Acad. Sci. USA"},{"key":"ref_138","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/2594455","article-title":"Joint link prediction and attribute inference using a social-attribute network","volume":"5","author":"Gong","year":"2014","journal-title":"Acm Trans. Intell. Syst. Technol."},{"key":"ref_139","unstructured":"Reynolds, N.A. (2023, March 08). An Empirical Investigation of Privacy via Obfuscation in Social Networks, 2020. Available online: https:\/\/figshare.mq.edu.au\/articles\/thesis\/An_empirical_investigation_of_privacy_via_obfuscation_in_social_networks\/19434461\/1."}],"container-title":["Journal of Cybersecurity and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2624-800X\/3\/2\/10\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T19:29:00Z","timestamp":1760124540000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2624-800X\/3\/2\/10"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,5,4]]},"references-count":139,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2023,6]]}},"alternative-id":["jcp3020010"],"URL":"https:\/\/doi.org\/10.3390\/jcp3020010","relation":{},"ISSN":["2624-800X"],"issn-type":[{"value":"2624-800X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,5,4]]}}}