activity
20172026
most citedEvasion Attacks against Machine Learning at Test Time

889 citations · 1.7k across the 40 of their papers we have counts for

collaborators
Showing 2026Show all

9 papers · 1 filter

cs.CR2026

Windows Malware Detector as a Compound AI System: Trade-Offs in Accuracy, Efficiency, and Adversarial Robustness

Andrea Ponte, Luca Demetrio, Luca Oneto +2

Industrial Windows malware detectors are commonly described as Compound AI Systems composed of multiple heterogeneous components, including rule-based mechanisms as well as machine…

cs.CR2026

EXE-Bench: Ranking the Tradeoffs of AI-based Windows Malware Detectors for Real-World Usability

Andrea Ponte, Daniel Gibert, Matous Kozak +5

Due to the lack of systematic evaluations, we are not yet able to determine which AI-based Windows malware detector to deploy in production, since existing evaluations (i) differ i…

cs.LG2026

Adversarial Frontiers: Minimum-Norm Attack Ensembles for Robustness Evaluation

Luca Scionis, Luca Melis, Maura Pintor +5

Adversarial robustness is commonly evaluated with predefined attack ensembles, such as AutoAttack, at a single perturbation budget and on a selective choice of pertur…

cs.CR2026

DroidBreaker: Practical and Functional Problem-Space Attacks on Machine-Learning Android Malware Detectors

Christian Scano, Diego Soi, Angelo Sotgiu +5

Adversarial APKs are Android applications modified in the problem space to evade machine-learning malware detectors. In this work, we first show that, despite claims, existing prob…

cs.AI2026

Latent-space Attacks for Refusal Evasion in Language Models

Giorgio Piras, Raffaele Mura, Fabio Brau +4

Safety-aligned language models are trained to refuse harmful requests, yet refusal behavior can be suppressed by steering their internal representations. Existing methods do so by…

cs.LG2026

Label-efficient Training Updates for Malware Detection over Time

Luca Minnei, Cristian Manca, Giorgio Piras +6

Machine Learning (ML)-based detectors are becoming essential to counter the proliferation of malware. However, common ML algorithms are not designed to cope with the dynamic nature…