Federated Learning(FL)protects data privacy through a distributed training mechanism,yet its decentralized nature also introduces new security vulnerabilities.Backdoor attacks inject malicious triggers into the global...Federated Learning(FL)protects data privacy through a distributed training mechanism,yet its decentralized nature also introduces new security vulnerabilities.Backdoor attacks inject malicious triggers into the global model through compromised updates,posing significant threats to model integrity and becoming a key focus in FL security.Existing backdoor attack methods typically embed triggers directly into original images and consider only data heterogeneity,resulting in limited stealth and adaptability.To address the heterogeneity of malicious client devices,this paper proposes a novel backdoor attack method named Capability-Adaptive Shadow Backdoor Attack(CASBA).By incorporating measurements of clients’computational and communication capabilities,CASBA employs a dynamic hierarchical attack strategy that adaptively aligns attack intensity with available resources.Furthermore,an improved deep convolutional generative adversarial network(DCGAN)is integrated into the attack pipeline to embed triggers without modifying original data,significantly enhancing stealthiness.Comparative experiments with Shadow Backdoor Attack(SBA)across multiple scenarios demonstrate that CASBA dynamically adjusts resource consumption based on device capabilities,reducing average memory usage per iteration by 5.8%.CASBA improves resource efficiency while keeping the drop in attack success rate within 3%.Additionally,the effectiveness of CASBA against three robust FL algorithms is also validated.展开更多
Zero-click attacks represent an advanced cybersecurity threat,capable of compromising devices without user interaction.High-profile examples such as Pegasus,Simjacker,Bluebugging,and Bluesnarfing exploit hidden vulner...Zero-click attacks represent an advanced cybersecurity threat,capable of compromising devices without user interaction.High-profile examples such as Pegasus,Simjacker,Bluebugging,and Bluesnarfing exploit hidden vulnerabilities in software and communication protocols to silently gain access,exfiltrate data,and enable long-term surveillance.Their stealth and ability to evade traditional defenses make detection and mitigation highly challenging.This paper addresses these threats by systematically mapping the tactics and techniques of zero-click attacks using the MITRE ATT&CK framework,a widely adopted standard for modeling adversarial behavior.Through this mapping,we categorize real-world attack vectors and better understand how such attacks operate across the cyber-kill chain.To support threat detection efforts,we propose an Active Learning-based method to efficiently label the Pegasus spyware dataset in alignment with the MITRE ATT&CK framework.This approach reduces the effort of manually annotating data while improving the quality of the labeled data,which is essential to train robust cybersecurity models.In addition,our analysis highlights the structured execution paths of zero-click attacks and reveals gaps in current defense strategies.The findings emphasize the importance of forward-looking strategies such as continuous surveillance,dynamic threat profiling,and security education.By bridging zero-click attack analysis with the MITRE ATT&CK framework and leveraging machine learning for dataset annotation,this work provides a foundation for more accurate threat detection and the development of more resilient and structured cybersecurity frameworks.展开更多
In recent years,with the rapid advancement of artificial intelligence,object detection algorithms have made significant strides in accuracy and computational efficiency.Notably,research and applications of Anchor-Free...In recent years,with the rapid advancement of artificial intelligence,object detection algorithms have made significant strides in accuracy and computational efficiency.Notably,research and applications of Anchor-Free models have opened new avenues for real-time target detection in optical remote sensing images(ORSIs).However,in the realmof adversarial attacks,developing adversarial techniques tailored to Anchor-Freemodels remains challenging.Adversarial examples generated based on Anchor-Based models often exhibit poor transferability to these new model architectures.Furthermore,the growing diversity of Anchor-Free models poses additional hurdles to achieving robust transferability of adversarial attacks.This study presents an improved cross-conv-block feature fusion You Only Look Once(YOLO)architecture,meticulously engineered to facilitate the extraction ofmore comprehensive semantic features during the backpropagation process.To address the asymmetry between densely distributed objects in ORSIs and the corresponding detector outputs,a novel dense bounding box attack strategy is proposed.This approach leverages dense target bounding boxes loss in the calculation of adversarial loss functions.Furthermore,by integrating translation-invariant(TI)and momentum-iteration(MI)adversarial methodologies,the proposed framework significantly improves the transferability of adversarial attacks.Experimental results demonstrate that our method achieves superior adversarial attack performance,with adversarial transferability rates(ATR)of 67.53%on the NWPU VHR-10 dataset and 90.71%on the HRSC2016 dataset.Compared to ensemble adversarial attack and cascaded adversarial attack approaches,our method generates adversarial examples in an average of 0.64 s,representing an approximately 14.5%improvement in efficiency under equivalent conditions.展开更多
An attack-resilient distributed Nash equilibrium(NE) seeking problem is addressed for noncooperative games of networked systems under malicious cyber-attacks,i.e.,false data injection(FDI) attacks.Different from many ...An attack-resilient distributed Nash equilibrium(NE) seeking problem is addressed for noncooperative games of networked systems under malicious cyber-attacks,i.e.,false data injection(FDI) attacks.Different from many existing distributed NE seeking works,it is practical and challenging to get resilient adaptively distributed NE seeking under unknown and unbounded FDI attacks.An attack-resilient NE seeking algorithm that is distributed(i.e.,independent of global information on the graph's algebraic connectivity,Lipschitz and monotone constants of pseudo-gradients,or number of players),is presented by means of incorporating the consensus-based gradient play with a distributed attack identifier so as to achieve simultaneous NE seeking and attack identification asymptotically.Another key characteristic is that FDI attacks are allowed to be unknown and unbounded.By exploiting nonsmooth analysis and stability theory,the global asymptotic convergence of the developed algorithm to the NE is ensured.Moreover,we extend this design to further consider the attack-resilient NE seeking of double-integrator players.Lastly,numerical simulation and practical experiment results are presented to validate the developed algorithms' effectiveness.展开更多
Internet of Things(IoTs)devices are bringing about a revolutionary change our society by enabling connectivity regardless of time and location.However,The extensive deployment of these devices also makes them attracti...Internet of Things(IoTs)devices are bringing about a revolutionary change our society by enabling connectivity regardless of time and location.However,The extensive deployment of these devices also makes them attractive victims for themalicious actions of adversaries.Within the spectrumof existing threats,Side-ChannelAttacks(SCAs)have established themselves as an effective way to compromise cryptographic implementations.These attacks exploit unintended,unintended physical leakage that occurs during the cryptographic execution of devices,bypassing the theoretical strength of the crypto design.In recent times,the advancement of deep learning has provided SCAs with a powerful ally.Well-trained deep-learningmodels demonstrate an exceptional capacity to identify correlations between side-channel measurements and sensitive data,thereby significantly enhancing such attacks.To further understand the security threats posed by deep-learning SCAs and to aid in formulating robust countermeasures in the future,this paper undertakes an exhaustive investigation of leading-edge SCAs targeting Advanced Encryption Standard(AES)implementations.The study specifically focuses on attacks that exploit power consumption and electromagnetic(EM)emissions as primary leakage sources,systematically evaluating the extent to which diverse deep learning techniques enhance SCAs acrossmultiple critical dimensions.These dimensions include:(i)the characteristics of publicly available datasets derived from various hardware and software platforms;(ii)the formalization of leakage models tailored to different attack scenarios;(iii)the architectural suitability and performance of state-of-the-art deep learning models.Furthermore,the survey provides a systematic synthesis of current research findings,identifies significant unresolved issues in the existing literature and suggests promising directions for future work,including cross-device attack transferability and the impact of quantum-classical hybrid computing on side-channel security.展开更多
The integrity of perception data transmitted over in-vehicle networks is important for the safety of autonomous driving.However,legacy protocols like the Controller Area Network(CAN)bus which lacks essential security ...The integrity of perception data transmitted over in-vehicle networks is important for the safety of autonomous driving.However,legacy protocols like the Controller Area Network(CAN)bus which lacks essential security features make In-Vehicle Networks(IVNs)vulnerable to data tampering attacks.Current research typically focuses on detecting the attack itself but ignores the information recovery from the missing data,leading to an unsafe autonomous driving system.To address the issue,we propose a 3D object recovery framework to recover the missing data caused by the tampering attack that occurred in in-vehicle networks.The proposed framework exploits both temporal and spatial context for the 3D object recovery,where a temporal branch is designed to learn the coordinate offsets of 3D objects based on historical data from previous frames,while a spatial branch employs information from the adjacent views of the attacked objects to locate the recovered objects from the overlapped regions in the current frame.By integrating the temporal and spatial clues,the framework effectively recovers the missing objects from the resting ones,thereby enhancing the immunity of in-vehicle networks for the tampering attack.Extensive experiments on the nuScenes dataset demonstrate that the proposed framework significantly improves 3D object detection performance under the attack when compared to the method without recovery.Additionally,the recovery performance becomes better as the attack intensity increases,highlighting the framework’s robustness in high-risk scenarios.The source will be available upon publication.展开更多
Deep neural networks(DNNs)have been widely applied in the field of synthetic aperture radar(SAR)image while they are facing more and more serious threats from a variety of malicious attacks.As one of the malicious att...Deep neural networks(DNNs)have been widely applied in the field of synthetic aperture radar(SAR)image while they are facing more and more serious threats from a variety of malicious attacks.As one of the malicious attacks with strong destructiveness and stealth,backdoor attacks have severely affected DNNs,but there are no related research studies concerning the backdoor attacks against the DNNs-based SAR image classification models.In this work,we make the first attempt to automatically design a constrained multi-objective invisible and adaptive backdoor attack termed as CMo-IABA for DNNs-based SAR image classification.In the CMo-IABA,we firstly generate an initial trigger-based backdoor attack randomly by a random combination of pixels with random noise conforming to the Gaussian distribution.Then,we design multi-objective functions by considering the trade-off between maximizing the attack success rate and minimizing L2 distance-based invisibility.The classification error between the backdoor DNN and the clean model is considered as the constraint to maintain the original performance of the model.To solve the optimization problem,a discrete non-dominated sorting genetic algorithm-II is introduced as the search engine with the developed crossover operation and mutation operation.The superiority of the proposed CMo-IABA to five state-of-the-art backdoor attacks on six different types of DNNs-based SAR image classification models has been demonstrated by the experimental results on Fudan University SAR(FUSAR)-ship and moving and stationary target acquisition and recognition(MSTAR)datasets in terms of attack success rate and L2 distance-based invisibility.展开更多
The publisher regrets the CRediT authorship contribution statement was inserted incorrectly and the correct statement should be updated as below:Zengji Liu:Writing-review&editing,Writing-original draft,Visualizati...The publisher regrets the CRediT authorship contribution statement was inserted incorrectly and the correct statement should be updated as below:Zengji Liu:Writing-review&editing,Writing-original draft,Visualization,Validation,Supervision,Software,Resources,Project administration,Methodology,Investigation,Funding acquisition,Formal analysis,Data curation,Conceptualization.Mengge Liu:Writing-review&editing,Writing-original draft,Investigation.Qi Wang:Writing-review&editing,Writing-original draft.Yi Tang:Writing-review&editing,Writing-original draft.展开更多
In this paper,a security defense issue is investigated for networked control systems susceptible to stochastic denial of service(DoS) attacks by using the sliding mode control method.To utilize network communication r...In this paper,a security defense issue is investigated for networked control systems susceptible to stochastic denial of service(DoS) attacks by using the sliding mode control method.To utilize network communication resources more effectively,a novel adaptive event-triggered(AET) mechanism is introduced,whose triggering coefficient can be adaptively adjusted according to the evolution trend of system states.Differing from existing event-triggered(ET) mechanisms,the proposed one demonstrates exceptional relevance and flexibility.It is closely related to attack probability,and its triggering coefficient dynamically adjusts depending on the presence or absence of an attack.To leverage attacker information more effectively,a switching-like sliding mode security controller is designed,which can autonomously select different controller gains based on the sliding function representing the attack situation.Sufficient conditions for the existence of the switching-like sliding mode secure controller are presented to ensure the stochastic stability of the system and the reachability of the sliding surface.Compared with existing time-invariant control strategies within the triggered interval,more resilient defense performance can be expected since the correlation with attack information is established in both the proposed AET scheme and the control strategy.Finally,a simulation example is conducted to verify the effectiveness and feasibility of the proposed security control method.展开更多
Dear Editor,The integration of distributed energy resources(DERs)and communication infrastructures makes distribution networks increasingly cyber-physical,requiring resilient and real-time voltage regulation.Network p...Dear Editor,The integration of distributed energy resources(DERs)and communication infrastructures makes distribution networks increasingly cyber-physical,requiring resilient and real-time voltage regulation.Network partitioning enables scalable control,yet existing methods often ignore communication and security constraints or rely on costly optimization,limiting practicality under dynamic and adversarial conditions.展开更多
Dear Editor,This letter deals with the security control for nonlinear cyber-physical systems(CPSs)under mixed deception attacks.Both sensors and actuators are assumed to be injected deception data during the data tran...Dear Editor,This letter deals with the security control for nonlinear cyber-physical systems(CPSs)under mixed deception attacks.Both sensors and actuators are assumed to be injected deception data during the data transmission via networks.In order to identify the unknown dynamics of the attacked system,a neural network(NN)is adopted,on basis of which an NN-based secure observer is designed to diminish the attack impact on state estimation.Then,by resorting to the reinforcement learning approach,the secure control strategy is presented via actor-critic and zero-sum games.At last,the designed control scheme is proved via a numerical simulation.展开更多
In response to the escalating APT attacks both in China and globally,this paper analyzes the characteristics and attack chains associated with APT attacks,conducting a detailed examination of the attack methods at eac...In response to the escalating APT attacks both in China and globally,this paper analyzes the characteristics and attack chains associated with APT attacks,conducting a detailed examination of the attack methods at each stage.Focusing on railway e-tickets,a critical component of railway information infrastructure,we analyze the characteristics of the network architecture and outline its security vulnerabilities The APT attack chain comprises four stages:reconnaissance,penetration,expansion,and harvesting.Based on the characteristics of railway e-ticket services and the limitations of existing security measures,we define the security domains of the railway e-ticket 12306network and the passenger ticket network.This allows us to establish a multi-level defense model against APT attacks that includes:preventing information leakage,attack confrontation,behavior analysis,and backdoor review.Deployment strategies and a series of technical measures are introduced to enhance the flexibility of e-tickets in responding to APT attacks,improve the accuracy of event tracing,and ensure timely response and remediation.Our findings aim to provide a valuable reference for the security design,implementation,operation,and maintenance of the railway e-ticket network.展开更多
Large language models(LLMs)have revolutionized AI applications across diverse domains.However,their widespread deployment has introduced critical security vulnerabilities,particularly prompt injection attacks that man...Large language models(LLMs)have revolutionized AI applications across diverse domains.However,their widespread deployment has introduced critical security vulnerabilities,particularly prompt injection attacks that manipulate model behavior through malicious instructions.Following Kitchenham’s guidelines,this systematic review synthesizes 128 peer-reviewed studies from 2022 to 2025 to provide a unified understanding of this rapidly evolving threat landscape.Our findings reveal a swift progression from simple direct injections to sophisticated multimodal attacks,achieving over 90%success rates against unprotected systems.In response,defense mechanisms show varying effectiveness:input preprocessing achieves 60%–80%detection rates and advanced architectural defenses demonstrate up to 95%protection against known patterns,though significant gaps persist against novel attack vectors.We identified 37 distinct defense approaches across three categories,but standardized evaluation frameworks remain limited.Our analysis attributes these vulnerabilities to fundamental LLM architectural limitations,such as the inability to distinguish instructions from data and attention mechanism vulnerabilities.This highlights critical research directions such as formal verification methods,standardized evaluation protocols,and architectural innovations for inherently secure LLM designs.展开更多
Optimizing convolutional neural networks(CNNs)for IoT attack detection remains a critical yet challenging task due to the need to balance multiple performance metrics beyond mere accuracy.This study proposes a unified...Optimizing convolutional neural networks(CNNs)for IoT attack detection remains a critical yet challenging task due to the need to balance multiple performance metrics beyond mere accuracy.This study proposes a unified and flexible optimization framework that leverages metaheuristic algorithms to automatically optimize CNN configurations for IoT attack detection.Unlike conventional single-objective approaches,the proposed method formulates a global multi-objective fitness function that integrates accuracy,precision,recall,and model size(speed/model complexity penalty)with adjustable weights.This design enables both single-objective and weightedsum multi-objective optimization,allowing adaptive selection of optimal CNN configurations for diverse deployment requirements.Two representativemetaheuristic algorithms,GeneticAlgorithm(GA)and Particle Swarm Optimization(PSO),are employed to optimize CNNhyperparameters and structure.At each generation/iteration,the best configuration is selected as themost balanced solution across optimization objectives,i.e.,the one achieving themaximum value of the global objective function.Experimental validation on two benchmark datasets,Edge-IIoT and CIC-IoT2023,demonstrates that the proposed GA-and PSO-based models significantly enhance detection accuracy(94.8%–98.3%)and generalization compared with manually tuned CNN configurations,while maintaining compact architectures.The results confirm that the multi-objective framework effectively balances predictive performance and computational efficiency.This work establishes a generalizable and adaptive optimization strategy for deep learning-based IoT attack detection and provides a foundation for future hybrid metaheuristic extensions in broader IoT security applications.展开更多
The surge in smishing attacks underscores the urgent need for robust,real-time detection systems powered by advanced deep learning models.This paper introduces PhishNet,a novel ensemble learning framework that integra...The surge in smishing attacks underscores the urgent need for robust,real-time detection systems powered by advanced deep learning models.This paper introduces PhishNet,a novel ensemble learning framework that integrates transformer-based models(RoBERTa)and large language models(LLMs)(GPT-OSS 120B,LLaMA3.370B,and Qwen332B)to enhance smishing detection performance significantly.To mitigate class imbalance,we apply synthetic data augmentation using T5 and leverage various text preprocessing techniques.Our system employs a duallayer voting mechanism:weighted majority voting among LLMs and a final ensemble vote to classify messages as ham,spam,or smishing.Experimental results show an average accuracy improvement from 96%to 98.5%compared to the best standalone transformer,and from 93%to 98.5%when compared to LLMs across datasets.Furthermore,we present a real-time,user-friendly application to operationalize our detection model for practical use.PhishNet demonstrates superior scalability,usability,and detection accuracy,filling critical gaps in current smishing detection methodologies.展开更多
Video surveillance systems play an important role in maintaining security in smart city environments.In this context,person identification(Re-ID)systems based on deep learning are currently drawing substantial academi...Video surveillance systems play an important role in maintaining security in smart city environments.In this context,person identification(Re-ID)systems based on deep learning are currently drawing substantial academic interest.However,these systems remain vulnerable to adversarial attacks.In existing methods,several attacks against Re-ID systems have been designed;nevertheless,they operate in the spatial domain.Existing attacks often suffer from perturbation visibility and low imperceptibility,making them easily detectable by human observers or automated detection systems.From this line of research,this study proposed a novel and potent alternative by designing frequency domain attacks,namely FreqAdv-FFT,FreqAdv-Wavelet,FreqAdv-Phase,FreqAdv-SelDCT,and FreqAdv-RandDCT.The frequency domain allows perturbations to be constructed in a way that utilizes the individual’s visual system’s decreased sensitivity to specific frequency ranges,making these perturbations less obvious.The proposed adversarial attacks were evaluated on two prominent datasets,Market-1501 and WB_WoB-ReID,across multiple models and attack variants.The highest performance degradation was observed with FreqAdv Wavelet on HRNet for the WB_WoB-ReID dataset,reducing the mean Average Precision(mAP)to 2.52%,and FreqAdv FFT on ResNet-50 for the Market-1501 dataset,achieving a mAP of 3.96%.The suggested attacks provide insights into establishing strong AI models as well as designing defenses for ReID-based surveillance systems that are relevant to the rising development of next-generation real-time applications.展开更多
Dear Editor,This letter studies the problem of stealthy attacks targeting stochastic event-based estimation,alongside proposing measures for their mitigation.A general attack framework is introduced,and the correspond...Dear Editor,This letter studies the problem of stealthy attacks targeting stochastic event-based estimation,alongside proposing measures for their mitigation.A general attack framework is introduced,and the corresponding stealthiness condition is analyzed.To enhance system security,we advocate for a single-dimensional encryption method,showing that securing a singular data element is sufficient to shield the system from the perils of stealthy attacks.展开更多
Grain-v1 is one of eSTREAM hardware-oriented finalists.A related-key chosen IV attack on Grain-v1 was first proposed by Lee et al.at ACISP 2008,where a pair of related keys should be cyclically shifted.This study impr...Grain-v1 is one of eSTREAM hardware-oriented finalists.A related-key chosen IV attack on Grain-v1 was first proposed by Lee et al.at ACISP 2008,where a pair of related keys should be cyclically shifted.This study improves the attack by relaxing the condition on related keys.Two keys K and K′are said to be related if K=(k0,k1,···,k79)and K′=(kα,···,k79,a0,a1,···,aα−1),where 1≤α≤12 and a0,a1,···,aα−1∈{0,1},which are not necessarily to be cyclically shifted.By choosingα=12,the proposed attack on Grain-v1 recovers four pairs of related keys which include five distinct keys with 227.59 chosen IVs,233.76 keystream bits,and 246.60 clock cycles.This result shows that Grain-v1 can not change keys by shifting and introducing a few new bits.展开更多
Graph Neural Networks(GNNs)have proven highly effective for graph classification across diverse fields such as social networks,bioinformatics,and finance,due to their capability to learn complex graph structures.Howev...Graph Neural Networks(GNNs)have proven highly effective for graph classification across diverse fields such as social networks,bioinformatics,and finance,due to their capability to learn complex graph structures.However,despite their success,GNNs remain vulnerable to adversarial attacks that can significantly degrade their classification accuracy.Existing adversarial attack strategies primarily rely on label information to guide the attacks,which limits their applicability in scenarios where such information is scarce or unavailable.This paper introduces an innovative unsupervised attack method for graph classification,which operates without relying on label information,thereby enhancing its applicability in a broad range of scenarios.Specifically,our method first leverages a graph contrastive learning loss to learn high-quality graph embeddings by comparing different stochastic augmented views of the graphs.To effectively perturb the graphs,we then introduce an implicit estimator that measures the impact of various modifications on graph structures.The proposed strategy identifies and flips edges with the top-K highest scores,determined by the estimator,to maximize the degradation of the model’s performance.In addition,to defend against such attack,we propose a lightweight regularization-based defense mechanism that is specifically tailored to mitigate the structural perturbations introduced by our attack strategy.It enhances model robustness by enforcing embedding consistency and edge-level smoothness during training.We conduct experiments on six public TU graph classification datasets:NCI1,NCI109,Mutagenicity,ENZYMES,COLLAB,and DBLP_v1,to evaluate the effectiveness of our attack and defense strategies.Under an attack budget of 3,the maximum reduction in model accuracy reaches 6.67%on the Graph Convolutional Network(GCN)and 11.67%on the Graph Attention Network(GAT)across different datasets,indicating that our unsupervised method induces degradation comparable to state-of-the-art supervised attacks.Meanwhile,our defense achieves the highest accuracy recovery of 3.89%(GCN)and 5.00%(GAT),demonstrating improved robustness against structural perturbations.展开更多
Nonlinear unsteady aerodynamic modeling at high angles of attack is critical for highprecision control law design of modern aircraft.Current modeling approaches primarily fall into two categories:expert's experien...Nonlinear unsteady aerodynamic modeling at high angles of attack is critical for highprecision control law design of modern aircraft.Current modeling approaches primarily fall into two categories:expert's experience-informed models and data-driven models.The accuracy of expert's experience-informed models is limited by the a priori expression terms.Data-driven model has a strong nonlinear mapping ability,but its performance depends on sample size and has insufficient generalization ability in small samples.To address these limitations,this paper proposes a physics-informed data-driven modeling framework,in which a Long Short-Term Memory(LSTM)neural network is trained to reconstruct the a priori expression terms in the differential equation model.While retaining the physical mechanism of the expert's experience-informed model,the data-driven method is utilized to enhance the prediction accuracy of the model.To validate the model,this paper conducts missile single-degree-of-freedom pitching and fighter two-degree-offreedom aerodynamics modeling at high angles of attack.Results show that,compared to a traditional differential equation model,a standalone LSTM network,and a hybrid multi-fidelity neural network,the proposed method achieves superior accuracy and generalizability in both cases,providing an effective solution for modeling complex nonlinear unsteady aerodynamic behaviors.展开更多
基金supported by the National Natural Science Foundation of China(Grant No.62172123)the Key Research and Development Program of Heilongjiang Province,China(GrantNo.2022ZX01A36).
摘要Federated Learning(FL)protects data privacy through a distributed training mechanism,yet its decentralized nature also introduces new security vulnerabilities.Backdoor attacks inject malicious triggers into the global model through compromised updates,posing significant threats to model integrity and becoming a key focus in FL security.Existing backdoor attack methods typically embed triggers directly into original images and consider only data heterogeneity,resulting in limited stealth and adaptability.To address the heterogeneity of malicious client devices,this paper proposes a novel backdoor attack method named Capability-Adaptive Shadow Backdoor Attack(CASBA).By incorporating measurements of clients’computational and communication capabilities,CASBA employs a dynamic hierarchical attack strategy that adaptively aligns attack intensity with available resources.Furthermore,an improved deep convolutional generative adversarial network(DCGAN)is integrated into the attack pipeline to embed triggers without modifying original data,significantly enhancing stealthiness.Comparative experiments with Shadow Backdoor Attack(SBA)across multiple scenarios demonstrate that CASBA dynamically adjusts resource consumption based on device capabilities,reducing average memory usage per iteration by 5.8%.CASBA improves resource efficiency while keeping the drop in attack success rate within 3%.Additionally,the effectiveness of CASBA against three robust FL algorithms is also validated.
摘要Zero-click attacks represent an advanced cybersecurity threat,capable of compromising devices without user interaction.High-profile examples such as Pegasus,Simjacker,Bluebugging,and Bluesnarfing exploit hidden vulnerabilities in software and communication protocols to silently gain access,exfiltrate data,and enable long-term surveillance.Their stealth and ability to evade traditional defenses make detection and mitigation highly challenging.This paper addresses these threats by systematically mapping the tactics and techniques of zero-click attacks using the MITRE ATT&CK framework,a widely adopted standard for modeling adversarial behavior.Through this mapping,we categorize real-world attack vectors and better understand how such attacks operate across the cyber-kill chain.To support threat detection efforts,we propose an Active Learning-based method to efficiently label the Pegasus spyware dataset in alignment with the MITRE ATT&CK framework.This approach reduces the effort of manually annotating data while improving the quality of the labeled data,which is essential to train robust cybersecurity models.In addition,our analysis highlights the structured execution paths of zero-click attacks and reveals gaps in current defense strategies.The findings emphasize the importance of forward-looking strategies such as continuous surveillance,dynamic threat profiling,and security education.By bridging zero-click attack analysis with the MITRE ATT&CK framework and leveraging machine learning for dataset annotation,this work provides a foundation for more accurate threat detection and the development of more resilient and structured cybersecurity frameworks.
摘要In recent years,with the rapid advancement of artificial intelligence,object detection algorithms have made significant strides in accuracy and computational efficiency.Notably,research and applications of Anchor-Free models have opened new avenues for real-time target detection in optical remote sensing images(ORSIs).However,in the realmof adversarial attacks,developing adversarial techniques tailored to Anchor-Freemodels remains challenging.Adversarial examples generated based on Anchor-Based models often exhibit poor transferability to these new model architectures.Furthermore,the growing diversity of Anchor-Free models poses additional hurdles to achieving robust transferability of adversarial attacks.This study presents an improved cross-conv-block feature fusion You Only Look Once(YOLO)architecture,meticulously engineered to facilitate the extraction ofmore comprehensive semantic features during the backpropagation process.To address the asymmetry between densely distributed objects in ORSIs and the corresponding detector outputs,a novel dense bounding box attack strategy is proposed.This approach leverages dense target bounding boxes loss in the calculation of adversarial loss functions.Furthermore,by integrating translation-invariant(TI)and momentum-iteration(MI)adversarial methodologies,the proposed framework significantly improves the transferability of adversarial attacks.Experimental results demonstrate that our method achieves superior adversarial attack performance,with adversarial transferability rates(ATR)of 67.53%on the NWPU VHR-10 dataset and 90.71%on the HRSC2016 dataset.Compared to ensemble adversarial attack and cascaded adversarial attack approaches,our method generates adversarial examples in an average of 0.64 s,representing an approximately 14.5%improvement in efficiency under equivalent conditions.
基金supported in part by the National Natural Science Foundation of China(62373022,U2241217,62141604)Beijing Natural Science Foundation(4252043,JQ23019)+4 种基金the Fundamental Research Funds for the Central Universities(JKF-2025037448805,JKF-2025086098295)the Aeronautical Science Fund(2023Z034051001)the Academic Excellence Foundation of BUAA for Ph.D. Studentsthe Science and Technology Innovation2030—Key Project of New Generation Artificial Intelligence(2020AAA0108200)the National Key Research and Development Program of China(2022YFB3305600)。
摘要An attack-resilient distributed Nash equilibrium(NE) seeking problem is addressed for noncooperative games of networked systems under malicious cyber-attacks,i.e.,false data injection(FDI) attacks.Different from many existing distributed NE seeking works,it is practical and challenging to get resilient adaptively distributed NE seeking under unknown and unbounded FDI attacks.An attack-resilient NE seeking algorithm that is distributed(i.e.,independent of global information on the graph's algebraic connectivity,Lipschitz and monotone constants of pseudo-gradients,or number of players),is presented by means of incorporating the consensus-based gradient play with a distributed attack identifier so as to achieve simultaneous NE seeking and attack identification asymptotically.Another key characteristic is that FDI attacks are allowed to be unknown and unbounded.By exploiting nonsmooth analysis and stability theory,the global asymptotic convergence of the developed algorithm to the NE is ensured.Moreover,we extend this design to further consider the attack-resilient NE seeking of double-integrator players.Lastly,numerical simulation and practical experiment results are presented to validate the developed algorithms' effectiveness.
基金The Key R&D Program of Hunan Province(Grant No.2025AQ2024)of the Department of Science and Technology of Hunan Province.Distinguished Young Scientists Fund(Grant No.24B0446)of Hunan Education Department.
摘要Internet of Things(IoTs)devices are bringing about a revolutionary change our society by enabling connectivity regardless of time and location.However,The extensive deployment of these devices also makes them attractive victims for themalicious actions of adversaries.Within the spectrumof existing threats,Side-ChannelAttacks(SCAs)have established themselves as an effective way to compromise cryptographic implementations.These attacks exploit unintended,unintended physical leakage that occurs during the cryptographic execution of devices,bypassing the theoretical strength of the crypto design.In recent times,the advancement of deep learning has provided SCAs with a powerful ally.Well-trained deep-learningmodels demonstrate an exceptional capacity to identify correlations between side-channel measurements and sensitive data,thereby significantly enhancing such attacks.To further understand the security threats posed by deep-learning SCAs and to aid in formulating robust countermeasures in the future,this paper undertakes an exhaustive investigation of leading-edge SCAs targeting Advanced Encryption Standard(AES)implementations.The study specifically focuses on attacks that exploit power consumption and electromagnetic(EM)emissions as primary leakage sources,systematically evaluating the extent to which diverse deep learning techniques enhance SCAs acrossmultiple critical dimensions.These dimensions include:(i)the characteristics of publicly available datasets derived from various hardware and software platforms;(ii)the formalization of leakage models tailored to different attack scenarios;(iii)the architectural suitability and performance of state-of-the-art deep learning models.Furthermore,the survey provides a systematic synthesis of current research findings,identifies significant unresolved issues in the existing literature and suggests promising directions for future work,including cross-device attack transferability and the impact of quantum-classical hybrid computing on side-channel security.
基金funded by the Program of Songshan Laboratory(241110210100)the National Natural Science Foundation of China(62301497)+1 种基金the Science and Technology Research Program of Henan(252102211024)the Key Research and Development Program of Henan(231111212000).
摘要The integrity of perception data transmitted over in-vehicle networks is important for the safety of autonomous driving.However,legacy protocols like the Controller Area Network(CAN)bus which lacks essential security features make In-Vehicle Networks(IVNs)vulnerable to data tampering attacks.Current research typically focuses on detecting the attack itself but ignores the information recovery from the missing data,leading to an unsafe autonomous driving system.To address the issue,we propose a 3D object recovery framework to recover the missing data caused by the tampering attack that occurred in in-vehicle networks.The proposed framework exploits both temporal and spatial context for the 3D object recovery,where a temporal branch is designed to learn the coordinate offsets of 3D objects based on historical data from previous frames,while a spatial branch employs information from the adjacent views of the attacked objects to locate the recovered objects from the overlapped regions in the current frame.By integrating the temporal and spatial clues,the framework effectively recovers the missing objects from the resting ones,thereby enhancing the immunity of in-vehicle networks for the tampering attack.Extensive experiments on the nuScenes dataset demonstrate that the proposed framework significantly improves 3D object detection performance under the attack when compared to the method without recovery.Additionally,the recovery performance becomes better as the attack intensity increases,highlighting the framework’s robustness in high-risk scenarios.The source will be available upon publication.
基金supported in part by the Zhejiang Provincial Natural Science Foundation of China(LZ25F030007)the National Natural Science Foundation of China(62573326,62533016,62403122)+1 种基金the Shanghai Sailing Program(24YF2701300)Guangdong Key Laboratory of Data Security and Privacy Preserving(2023B1212060036)。
摘要Deep neural networks(DNNs)have been widely applied in the field of synthetic aperture radar(SAR)image while they are facing more and more serious threats from a variety of malicious attacks.As one of the malicious attacks with strong destructiveness and stealth,backdoor attacks have severely affected DNNs,but there are no related research studies concerning the backdoor attacks against the DNNs-based SAR image classification models.In this work,we make the first attempt to automatically design a constrained multi-objective invisible and adaptive backdoor attack termed as CMo-IABA for DNNs-based SAR image classification.In the CMo-IABA,we firstly generate an initial trigger-based backdoor attack randomly by a random combination of pixels with random noise conforming to the Gaussian distribution.Then,we design multi-objective functions by considering the trade-off between maximizing the attack success rate and minimizing L2 distance-based invisibility.The classification error between the backdoor DNN and the clean model is considered as the constraint to maintain the original performance of the model.To solve the optimization problem,a discrete non-dominated sorting genetic algorithm-II is introduced as the search engine with the developed crossover operation and mutation operation.The superiority of the proposed CMo-IABA to five state-of-the-art backdoor attacks on six different types of DNNs-based SAR image classification models has been demonstrated by the experimental results on Fudan University SAR(FUSAR)-ship and moving and stationary target acquisition and recognition(MSTAR)datasets in terms of attack success rate and L2 distance-based invisibility.
摘要The publisher regrets the CRediT authorship contribution statement was inserted incorrectly and the correct statement should be updated as below:Zengji Liu:Writing-review&editing,Writing-original draft,Visualization,Validation,Supervision,Software,Resources,Project administration,Methodology,Investigation,Funding acquisition,Formal analysis,Data curation,Conceptualization.Mengge Liu:Writing-review&editing,Writing-original draft,Investigation.Qi Wang:Writing-review&editing,Writing-original draft.Yi Tang:Writing-review&editing,Writing-original draft.
基金supported in part by Shanghai Natural Science Foundation(24ZR1454700)the National Natural Science Foundation of China(62503331,62533016,62573279,62173231,62203288)Shanghai Pujiang Program(23PJD033)。
摘要In this paper,a security defense issue is investigated for networked control systems susceptible to stochastic denial of service(DoS) attacks by using the sliding mode control method.To utilize network communication resources more effectively,a novel adaptive event-triggered(AET) mechanism is introduced,whose triggering coefficient can be adaptively adjusted according to the evolution trend of system states.Differing from existing event-triggered(ET) mechanisms,the proposed one demonstrates exceptional relevance and flexibility.It is closely related to attack probability,and its triggering coefficient dynamically adjusts depending on the presence or absence of an attack.To leverage attacker information more effectively,a switching-like sliding mode security controller is designed,which can autonomously select different controller gains based on the sliding function representing the attack situation.Sufficient conditions for the existence of the switching-like sliding mode secure controller are presented to ensure the stochastic stability of the system and the reachability of the sliding surface.Compared with existing time-invariant control strategies within the triggered interval,more resilient defense performance can be expected since the correlation with attack information is established in both the proposed AET scheme and the control strategy.Finally,a simulation example is conducted to verify the effectiveness and feasibility of the proposed security control method.
基金supported in part by the National Natural Science Foundation of China(62293500,62293504,62303242)the Young Elite Scientists Sponsorship Program by CAST(YESS20240325)+1 种基金the Young Elite Scientists Sponsorship Program by JASTI(JSTJ-2024-443)the China Postdoctoral Science Foundation(2023M731780)。
摘要Dear Editor,The integration of distributed energy resources(DERs)and communication infrastructures makes distribution networks increasingly cyber-physical,requiring resilient and real-time voltage regulation.Network partitioning enables scalable control,yet existing methods often ignore communication and security constraints or rely on costly optimization,limiting practicality under dynamic and adversarial conditions.
基金supported in part by the National Natural Science Foundation of China(62273180,62403245,62233012)Natural Science Foundation of Jiangsu Province of China(BK20241458,BK20232038)。
摘要Dear Editor,This letter deals with the security control for nonlinear cyber-physical systems(CPSs)under mixed deception attacks.Both sensors and actuators are assumed to be injected deception data during the data transmission via networks.In order to identify the unknown dynamics of the attacked system,a neural network(NN)is adopted,on basis of which an NN-based secure observer is designed to diminish the attack impact on state estimation.Then,by resorting to the reinforcement learning approach,the secure control strategy is presented via actor-critic and zero-sum games.At last,the designed control scheme is proved via a numerical simulation.
摘要In response to the escalating APT attacks both in China and globally,this paper analyzes the characteristics and attack chains associated with APT attacks,conducting a detailed examination of the attack methods at each stage.Focusing on railway e-tickets,a critical component of railway information infrastructure,we analyze the characteristics of the network architecture and outline its security vulnerabilities The APT attack chain comprises four stages:reconnaissance,penetration,expansion,and harvesting.Based on the characteristics of railway e-ticket services and the limitations of existing security measures,we define the security domains of the railway e-ticket 12306network and the passenger ticket network.This allows us to establish a multi-level defense model against APT attacks that includes:preventing information leakage,attack confrontation,behavior analysis,and backdoor review.Deployment strategies and a series of technical measures are introduced to enhance the flexibility of e-tickets in responding to APT attacks,improve the accuracy of event tracing,and ensure timely response and remediation.Our findings aim to provide a valuable reference for the security design,implementation,operation,and maintenance of the railway e-ticket network.
基金supported by 2023 Higher Education Scientific Research Planning Project of China Society of Higher Education(No.23PG0408)2023 Philosophy and Social Science Research Programs in Jiangsu Province(No.2023SJSZ0993)+2 种基金Nantong Science and Technology Project(No.JC2023070)Key Project of Jiangsu Province Education Science 14th Five-Year Plan(Grant No.B-b/2024/02/41)the Open Fund of Advanced Cryptography and System Security Key Laboratory of Sichuan Province(Grant No.SKLACSS-202407).
摘要Large language models(LLMs)have revolutionized AI applications across diverse domains.However,their widespread deployment has introduced critical security vulnerabilities,particularly prompt injection attacks that manipulate model behavior through malicious instructions.Following Kitchenham’s guidelines,this systematic review synthesizes 128 peer-reviewed studies from 2022 to 2025 to provide a unified understanding of this rapidly evolving threat landscape.Our findings reveal a swift progression from simple direct injections to sophisticated multimodal attacks,achieving over 90%success rates against unprotected systems.In response,defense mechanisms show varying effectiveness:input preprocessing achieves 60%–80%detection rates and advanced architectural defenses demonstrate up to 95%protection against known patterns,though significant gaps persist against novel attack vectors.We identified 37 distinct defense approaches across three categories,but standardized evaluation frameworks remain limited.Our analysis attributes these vulnerabilities to fundamental LLM architectural limitations,such as the inability to distinguish instructions from data and attention mechanism vulnerabilities.This highlights critical research directions such as formal verification methods,standardized evaluation protocols,and architectural innovations for inherently secure LLM designs.
摘要Optimizing convolutional neural networks(CNNs)for IoT attack detection remains a critical yet challenging task due to the need to balance multiple performance metrics beyond mere accuracy.This study proposes a unified and flexible optimization framework that leverages metaheuristic algorithms to automatically optimize CNN configurations for IoT attack detection.Unlike conventional single-objective approaches,the proposed method formulates a global multi-objective fitness function that integrates accuracy,precision,recall,and model size(speed/model complexity penalty)with adjustable weights.This design enables both single-objective and weightedsum multi-objective optimization,allowing adaptive selection of optimal CNN configurations for diverse deployment requirements.Two representativemetaheuristic algorithms,GeneticAlgorithm(GA)and Particle Swarm Optimization(PSO),are employed to optimize CNNhyperparameters and structure.At each generation/iteration,the best configuration is selected as themost balanced solution across optimization objectives,i.e.,the one achieving themaximum value of the global objective function.Experimental validation on two benchmark datasets,Edge-IIoT and CIC-IoT2023,demonstrates that the proposed GA-and PSO-based models significantly enhance detection accuracy(94.8%–98.3%)and generalization compared with manually tuned CNN configurations,while maintaining compact architectures.The results confirm that the multi-objective framework effectively balances predictive performance and computational efficiency.This work establishes a generalizable and adaptive optimization strategy for deep learning-based IoT attack detection and provides a foundation for future hybrid metaheuristic extensions in broader IoT security applications.
基金funded by the Deanship of Scientific Research(DSR)at King Abdulaziz University,Jeddah,under Grant No.(GPIP:1074-612-2024).
摘要The surge in smishing attacks underscores the urgent need for robust,real-time detection systems powered by advanced deep learning models.This paper introduces PhishNet,a novel ensemble learning framework that integrates transformer-based models(RoBERTa)and large language models(LLMs)(GPT-OSS 120B,LLaMA3.370B,and Qwen332B)to enhance smishing detection performance significantly.To mitigate class imbalance,we apply synthetic data augmentation using T5 and leverage various text preprocessing techniques.Our system employs a duallayer voting mechanism:weighted majority voting among LLMs and a final ensemble vote to classify messages as ham,spam,or smishing.Experimental results show an average accuracy improvement from 96%to 98.5%compared to the best standalone transformer,and from 93%to 98.5%when compared to LLMs across datasets.Furthermore,we present a real-time,user-friendly application to operationalize our detection model for practical use.PhishNet demonstrates superior scalability,usability,and detection accuracy,filling critical gaps in current smishing detection methodologies.
基金supported by the National Research Foundation of Korea(NRF)grant funded by the Korea government(MSIT)(RS-2025-00563192&RS-2025-00518960).
摘要Video surveillance systems play an important role in maintaining security in smart city environments.In this context,person identification(Re-ID)systems based on deep learning are currently drawing substantial academic interest.However,these systems remain vulnerable to adversarial attacks.In existing methods,several attacks against Re-ID systems have been designed;nevertheless,they operate in the spatial domain.Existing attacks often suffer from perturbation visibility and low imperceptibility,making them easily detectable by human observers or automated detection systems.From this line of research,this study proposed a novel and potent alternative by designing frequency domain attacks,namely FreqAdv-FFT,FreqAdv-Wavelet,FreqAdv-Phase,FreqAdv-SelDCT,and FreqAdv-RandDCT.The frequency domain allows perturbations to be constructed in a way that utilizes the individual’s visual system’s decreased sensitivity to specific frequency ranges,making these perturbations less obvious.The proposed adversarial attacks were evaluated on two prominent datasets,Market-1501 and WB_WoB-ReID,across multiple models and attack variants.The highest performance degradation was observed with FreqAdv Wavelet on HRNet for the WB_WoB-ReID dataset,reducing the mean Average Precision(mAP)to 2.52%,and FreqAdv FFT on ResNet-50 for the Market-1501 dataset,achieving a mAP of 3.96%.The suggested attacks provide insights into establishing strong AI models as well as designing defenses for ReID-based surveillance systems that are relevant to the rising development of next-generation real-time applications.
基金supported by the National Natural Science Foundation of China(62303353,62273030,62573320)。
摘要Dear Editor,This letter studies the problem of stealthy attacks targeting stochastic event-based estimation,alongside proposing measures for their mitigation.A general attack framework is introduced,and the corresponding stealthiness condition is analyzed.To enhance system security,we advocate for a single-dimensional encryption method,showing that securing a singular data element is sufficient to shield the system from the perils of stealthy attacks.
基金National Natural Science Foundation of China(62372464)。
摘要Grain-v1 is one of eSTREAM hardware-oriented finalists.A related-key chosen IV attack on Grain-v1 was first proposed by Lee et al.at ACISP 2008,where a pair of related keys should be cyclically shifted.This study improves the attack by relaxing the condition on related keys.Two keys K and K′are said to be related if K=(k0,k1,···,k79)and K′=(kα,···,k79,a0,a1,···,aα−1),where 1≤α≤12 and a0,a1,···,aα−1∈{0,1},which are not necessarily to be cyclically shifted.By choosingα=12,the proposed attack on Grain-v1 recovers four pairs of related keys which include five distinct keys with 227.59 chosen IVs,233.76 keystream bits,and 246.60 clock cycles.This result shows that Grain-v1 can not change keys by shifting and introducing a few new bits.
基金funded by the National Key Research and Development Program of China(Grant No.2024YFE0209000)the NSFC(Grant No.U23B2019).
摘要Graph Neural Networks(GNNs)have proven highly effective for graph classification across diverse fields such as social networks,bioinformatics,and finance,due to their capability to learn complex graph structures.However,despite their success,GNNs remain vulnerable to adversarial attacks that can significantly degrade their classification accuracy.Existing adversarial attack strategies primarily rely on label information to guide the attacks,which limits their applicability in scenarios where such information is scarce or unavailable.This paper introduces an innovative unsupervised attack method for graph classification,which operates without relying on label information,thereby enhancing its applicability in a broad range of scenarios.Specifically,our method first leverages a graph contrastive learning loss to learn high-quality graph embeddings by comparing different stochastic augmented views of the graphs.To effectively perturb the graphs,we then introduce an implicit estimator that measures the impact of various modifications on graph structures.The proposed strategy identifies and flips edges with the top-K highest scores,determined by the estimator,to maximize the degradation of the model’s performance.In addition,to defend against such attack,we propose a lightweight regularization-based defense mechanism that is specifically tailored to mitigate the structural perturbations introduced by our attack strategy.It enhances model robustness by enforcing embedding consistency and edge-level smoothness during training.We conduct experiments on six public TU graph classification datasets:NCI1,NCI109,Mutagenicity,ENZYMES,COLLAB,and DBLP_v1,to evaluate the effectiveness of our attack and defense strategies.Under an attack budget of 3,the maximum reduction in model accuracy reaches 6.67%on the Graph Convolutional Network(GCN)and 11.67%on the Graph Attention Network(GAT)across different datasets,indicating that our unsupervised method induces degradation comparable to state-of-the-art supervised attacks.Meanwhile,our defense achieves the highest accuracy recovery of 3.89%(GCN)and 5.00%(GAT),demonstrating improved robustness against structural perturbations.
基金supported by the National Key Research and Development Program of China(No.2023YFB3002800)。
摘要Nonlinear unsteady aerodynamic modeling at high angles of attack is critical for highprecision control law design of modern aircraft.Current modeling approaches primarily fall into two categories:expert's experience-informed models and data-driven models.The accuracy of expert's experience-informed models is limited by the a priori expression terms.Data-driven model has a strong nonlinear mapping ability,but its performance depends on sample size and has insufficient generalization ability in small samples.To address these limitations,this paper proposes a physics-informed data-driven modeling framework,in which a Long Short-Term Memory(LSTM)neural network is trained to reconstruct the a priori expression terms in the differential equation model.While retaining the physical mechanism of the expert's experience-informed model,the data-driven method is utilized to enhance the prediction accuracy of the model.To validate the model,this paper conducts missile single-degree-of-freedom pitching and fighter two-degree-offreedom aerodynamics modeling at high angles of attack.Results show that,compared to a traditional differential equation model,a standalone LSTM network,and a hybrid multi-fidelity neural network,the proposed method achieves superior accuracy and generalizability in both cases,providing an effective solution for modeling complex nonlinear unsteady aerodynamic behaviors.