8 papers
ShellGames: Speculative LLM-Driven SSH Deception
Umberto Salviati, Fabio De Gaspari, Mauro Conti +1
Cyber deception and Moving Target Defense are promising strategies that aim to disrupt adversaries by increasing uncertainty. However, sustaining long-lived, credible interactive s…
When Entropy Is Not Enough: Multi-Modal Classification of Encrypted and Compressed Data Fragments
Fabio De Gaspari, Dorjan Hitaj, Samuele Salaris +1
Reliable identification of encrypted data fragments is essential in cybersecurity, with applications to ransomware detection, digital forensics, and large-scale data analysis. Dist…
I can't recognize (yet): Delayed Rendering to Defeat Visual Phishing Detectors
Ying Yuan, Cristiano Alex Rado, Giovanni Apruzzese +2
Phishing webpages are continuously polluting the Web. Plenty of countermeasures have been proposed and the most advanced techniques leverage machine-learning methods that infer whe…
Behavior-Aware and Generalizable Defense Against Black-Box Adversarial Attacks for ML-Based IDS
Sabrine Ennaji, Elhadj Benkhelifa, Luigi Vincenzo Mancini
Machine learning based intrusion detection systems are increasingly targeted by black box adversarial attacks, where attackers craft evasive inputs using indirect feedback such as…
MAYA: Addressing Inconsistencies in Generative Password Guessing through a Unified Benchmark
William Corrias, Fabio De Gaspari, Dorjan Hitaj +1
Recent advances in generative models have led to their application in password guessing, with the aim of replicating the complexity, structure, and patterns of human-created passwo…
Do You Trust Your Model? Emerging Malware Threats in the Deep Learning Ecosystem
Dorjan Hitaj, Giulio Pagnotta, Fabio De Gaspari +4
Training high-quality deep learning models is a challenging task due to computational and technical requirements. A growing number of individuals, institutions, and companies incre…