Jul 2026· International Journal of Innovations in Science, Engineering And Management· 0 citations· 15 references
TL;DR
The review explores the key adversarial attack classes: poisoning, evasion, model extraction, model extraction, model inversion, and membership inference and also white-box, black-box, and grey-box threat models.
Abstract
The rise of artificial intelligence (AI) and machine learning (ML) in cybersecurity has made Adversarial Machine Learning (AML) a key field of research. Though ML-based systems are more effective in intrusion detection, malware analysis, spam filtering and authentication, they are also susceptible to adversarial attacks that modify input samples, modify ML models or alter training data. The review explores the key adversarial attack classes: poisoning, evasion, model extraction, model inversion, and membership inference and also white-box, black-box, and grey-box threat models. It also provides an introduction to important defence methods like adversarial training, feature squeezing, defensive distillation, robust optimisation, detection-based methods, and ensemble learning. In addition, robustness evaluation metrics, benchmark datasets and attack assessment techniques to measure model robustness are highlighted. Lastly, the emerging trends are discussed in order to find future research directions in the field of creating trustworthy and resilient AI-based cybersecurity systems, such as Explainable AI, Federated Learning, Large Language Models, Autonomous Cyber defence, and Regulatory structures.
A detailed overview of the security risks associated with adversarial attacks is offered, including evasion attacks carried out at inference time, data poisoning that corrupts the training process, backdoor insertion that hides dormant triggers inside a model, and model inversion that leaks private information back out of a trained system.
Harsh Verma· International Journal of Sci...· 0 citations
A detailed empirical assessment of targeted adversarial vulnerability and defensive behaviour in a multi-class NIDS setting is presented and the results highlight long-standing, class-specific, robustness gaps and provide insights that could be used to design more robust intrusion detection systems.
Machine learning and deep learning have become essential components of modern cybersecurity because of their ability to detect malicious activities, classify network traffic, identify malware, recognize phishing attempts, and support automated incident response. However, machine learning–based cybersecurity classifiers are vulnerable to adversarial attacks in which attackers deliberately manipulate data, features, model inputs, or training processes to cause misclassification or evade detection. This study systematically analyzes adversarial attacks against machine learning–based cybersecurity classifiers and proposes a comprehensive defense framework to improve their robustness and reliability. The study examines major attack categories, including evasion, data poisoning, model extraction, inference, backdoor, and adversarial example attacks. It also analyzes attack surfaces, threat models, and the consequences of adversarial manipulation in intrusion detection, malware detection, phishing classification, and other AI-enabled cybersecurity systems. The findings indicate that adversarial attacks can significantly reduce detection performance, increase false-negative and false-positive rates, manipulate decision boundaries, and undermine trust in automated security systems. A defense-in-depth framework is proposed, incorporating secure data management, adversarial training, robust feature engineering, model validation, ensemble learning, anomaly detection, explainable AI, continuous monitoring, human oversight, and regular security auditing. The study concludes that no single defense mechanism can provide complete protection against adversarial machine learning attacks. Therefore, resilient AI-based cybersecurity requires a layered approach that protects data, features, models, inference processes, and the entire machine learning lifecycle.
Nwamini Bartholomew Tochukwu, C. Ezeaku-Ezeme· International journal of res...· 0 citations
Experimental results indicate that CNN-based NIDS are more vulnerable to adversarial attacks than ANN-based models, with adversarial examples successfully transferring across architectures, highlighting the critical risks associated with adversarial transferability.
Aasim Zafar, Shazra Wali, Sheikh Burhan Ul Haque· International Journal of Inf...· 0 citations
Abstract
The escalating scale and sophistication of cyber threats - including advanced persistent threats, ransomware, and zero-day exploits - has driven a decade-long shift in cybersecurity research away from static, signature-based defences and toward machine learning (ML) systems capable of learning attack patterns from data and generalising to previously unseen threats. This paper presents a systematic literature review of machine learning in cyber security, organising the field into classical supervised intrusion detection, deep learning and hybrid detection architectures, graph-based and provenance-aware detection, machine-learning-based malware and phishing detection, and the adversarial machine learning literature that studies how the very ML systems built to defend networks can themselves be attacked and manipulated. The review examines the benchmark datasets - including NSL-KDD, UNSW-NB15, and CICIDS2017 - and evaluation practices that recur across this literature, situates the technical literature against industry data on the real-world cost and frequency of breaches, and discusses cross-cutting challenges including class imbalance, concept drift, adversarial vulnerability, explainability, and the operational gap between benchmark accuracy and production deployment. The paper concludes by proposing a conceptual layered framework for machine-learning-based security operations that integrates detection, adversarial-robustness testing, and human-analyst oversight, and by outlining directions for future research.
Keywords: machine learning, cyber security, intrusion detection, malware detection, adversarial machine learning, phishing detection, network security
Dr. C. Thilagavathy, Saeed Mudether Saeed Taha, Krithik M S et al.· International Scientific Jou...· 0 citations
Many of the critical networks are now vulnerable to complex security threats, especially those launched by adversaries against the machine learning-driven security systems used by these networks. Such attacks take advantage of weaknesses in AI systems by perturbing the model with carefully designed perturbations, which result in misclassification of malicious content as benign, compromising the system's confidentiality, integrity, and availability. The adversarial threat is unlike traditional cyberattacks; it is dynamic, adaptive and can circumvent traditional intrusion detection capabilities. This paper provides an extensive literature review on the adversarial attack methods, detection and defence techniques of critical network infrastructures. This review includes peer-reviewed publications published between 2019 and 2024 from the leading academic databases such as IEEE Xplore, SpringerLink, ScienceDirect and Google Scholar. The total number of studies analyzed were 48, covering contributions in the fields of creating adversarial attack methods, machine learning and deep learning based detection methods, and mitigation techniques. The results indicate that adversarial attacks can be divided into the following categories: evasion attacks, poisoning attacks, and exploratory attacks, where some of the more sophisticated methods, including those based on gradient, optimization, and reinforcement learning, are very effective in evading security systems. Current solutions, however, suffer from limited real-time adaptability, cross-domain generalization ability, explainability and integration across the attack lifecycle. While there are several defence mechanisms proposed, such as adversarial training, anomaly detection, and input transformation, existing defences have difficulties in being adaptable in real time, cross-domain generalizable, explainable and suitable for certain phases of the attack lifecycle. The study highlights a number of critical research challenges such as the lack of a common defence framework, inadequate real-time detection capabilities, absence of a standardized data sets and poor ability to withstand adaptive adversaries. The paper suggests the creation of multi-strategic, adaptive, and real-time adversarial threat management systems that can sustain themselves in a heterogeneous network environment.
F. Okoye, Aghaizu Herman Chijioke, Shamsudeen Mohammed S.B· International journal of re...· 0 citations