2026· ITEGAM- Journal of Engineering and Technology for Industrial Applications (ITEGAM-JETIA)· Vol 12, pp. 566-583· 0 citations
TL;DR
A novel two-stage detection-based defense framework tailored for file fragment classification that mitigates the accuracy-robustness trade-off commonly associated with adversarial training is presented, providing an approach for improving the robustness of forensic classification systems against byte-level adversarial attacks such as padding and bit-flipping.
Abstract
File fragment classification is fundamental to digital forensics and network security, enabling the recovery and identification of files when metadata is corrupted or absent. While state-of-the-art deep learning models on the FFT-75 benchmark achieve 65–79% accuracy on clean fragments, they exhibit vulnerability to byte-level adversarial perturbations, and evaluation across 39 byte-level attack variants shows that the baseline accuracy drops from 71.1% on clean fragments to an average of 15.8% under adversarial perturbations. This paper presents a novel two-stage detection-based defense framework tailored for file fragment classification that mitigates the accuracy-robustness trade-off commonly associated with adversarial training. The framework integrates three components: (1) an attention-based adversarial detector achieving 95.46% specificity and 91.34% recall (91.44% overall accuracy); (2) an existing baseline file fragment classifier preserving 71.1% accuracy on clean fragments; and (3) a novel Dual-Scale Attention-based Robust CNN (DSAR-CNN) specifically designed for adversarial fragment classification, achieving 68.4% accuracy on adversarially perturbed samples (evaluated on the test set of 4.6M fragments) through multi-scale depth wise separable convolution, CBAM-style dual attention, learnable position embeddings, and split global pooling. Developed and evaluated across 75 file types and 39 attack variants from the FFT-75 benchmark, the complete pipeline achieves 70.91% accuracy on clean data (0.19 percentage point penalty) and 63.84% on adversarial data, yielding 70.20% accuracy in realistic mixed-threat scenarios (90% clean, 10% adversarial) - outperforming both the undefended baseline and the standard adversarial training benchmark. The framework provides an approach for improving the robustness of forensic classification systems against byte-level adversarial attacks such as padding and bit-flipping.
A systematic framework to enhance adversarial robustness is proposed, validated on the Malimg dataset and supersedes previous approaches by 13.15% in terms of the evasion rate and 37.34% in terms of retraining success.
Muhammad Arham Tariq, Allah Bux Sargano, Z. Habib et al.· International Journal of Inf...· 0 citations
The research methodology involved a systematic literature review using the Scopus database, adhering to Preferred Reporting Items for Systematic Reviews and Meta-Analyses guidelines, and focusing on recent advancements in attack and defence techniques.
It is demonstrated that clean-text performance is not a reliable predictor of adversarial robustness, and the results underscore the necessity for architecture-specific defences and frame smishing detection as an adversarial cybersecurity challenge rather than a static classification task.
Denzel Chiuseni, A. Bahizire, Silva Hama et al.· 0 citations
A robust, explainable detection framework is presented that combines a CNN backbone for extracting spatial artifacts with an LSTM module for modeling temporal inconsistencies across frames that enhances forensic decision support and increases practical readiness for content verification systems.
Lastone Banda, Esther J.· International Journal of Dat...· 0 citations
Deep-OCR (DeepSeek-OCR) advances document recognition by treating the visual modality as an optical compression medium, enabling long-context OCR at low token cost. However, its increased complexity may introduce new security vulnerabilities. In this paper, we present, to the best of our knowledge, the first pure black...
Wenbo Sun, Hong-Zong Li, Yanyun Wang et al.· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.