Pith. sign in

REVIEW 5 major objections 4 minor 193 references

Insights on Adversarial Attacks for Tabular Machine Learning via a Systematic Literature Review

T0 review · 5 major / 4 minor · reviewed 2026-08-15 · deepseek-v4-flash

Pith's one-line read This paper claims to be the first systematic literature review of adversarial attacks on tabular machine learning, synthesizing 53 studies and 61 attacks into a taxonomy and an eight-dimensional practical-consideration checklist.

desk verdict A genuinely useful first systematic map of tabular adversarial attacks, but the headline counts don't add up and need a revision pass before the synthesis can be trusted. read the letter →

arxiv 2506.15506 v1 pith:CLJA2QXI submitted 2025-06-18 cs.LG

classification cs.LG
keywords adversarialattackstabulardatasystematicliteraturereviewmachinelearningrobustnessevasionpracticalconsiderationsfeasibilityconstraints
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper tries to establish that adversarial attacks on tabular machine learning models are a distinct, still-fragmented research area and that the field's first systematic map can be drawn from 53 studies and 61 attacks. It claims to be the first systematic literature review focused specifically on tabular-data attacks, as opposed to the mature surveys in computer vision and natural language processing. The review's value would be to give researchers a shared inventory of attack strategies and a checklist of eight practical considerations that determine whether an attack matters outside the lab. Its core finding is that efficacy is essentially universal while robustness-related qualities like semantic preservation, plausibility, transferability, and defense awareness are rarely evaluated.

What carries the argument

The machinery is a three-level coding scheme, Considered/Acknowledged/Not considered, applied to eight practical dimensions, paired with a taxonomy of attacks by optimization strategy. The eight dimensions (efficacy, efficiency, transferability, feasibility, semantic preservation, plausibility, defense awareness, dataset suitability) function as a checklist that lets the review measure, study by study, how much of the real-world attack problem each paper addresses. The feasibility dimension is further decomposed into mutability constraints, structural constraints, and inter-feature relationships, because that is where tabular data differs most from images. The taxonomy of gradient-based, gradient-free, learning-based, and hybrid methods is what turns 53 heterogeneous papers into comparable counts.

What would settle it

Run the same review with a broader search (for example, replacing the exact phrase 'tabular data' with 'structured data', 'feature table', or domain terms like 'intrusion detection' or 'credit scoring') and have two independent coders apply the eight-dimension scheme; if substantially more attacks surface or inter-rater agreement is low, the reported 53-study corpus and the relative emphasis on efficacy versus feasibility would shift.

Watch

Extended reading notes

Core claim

Working from a PRISMA-guided search of four databases plus citation-chaining and supplementary searches, the paper identifies 53 eligible studies and 61 attacks, and claims this is the first domain-agnostic synthesis of adversarial attacks on tabular machine learning. It organizes the attacks by optimization strategy (gradient-based, gradient-free, learning-based, hybrid) and labels every study on eight practical dimensions: efficacy, efficiency, transferability, feasibility, semantic preservation, plausibility, defense awareness, and dataset suitability. The headline results are that all 53 studies measure efficacy; feasibility receives attention in 44 studies, subdivided into mutability, structural, and inter-feature constraints; and the harder-to-define criteria (semantics, plausibility) are addressed by only 6 and 11 studies respectively. The paper also reports fragmented venues, uneven dataset use, and limited shared benchmarking.

Load-bearing premise

The review's counts and gap analysis rest on the assumption that its search string, which requires the phrase 'tabular data', and its single-coder labeling of eight dimensions correctly capture all relevant attacks and each study's treatment of them.

Editorial extensions

If this is right

  • Future tabular adversarial research will need standardized benchmarks with shared datasets and metrics, because the review finds 34 of 61 datasets used in only one study and no consensus evaluation criteria.
  • Attack evaluation should move beyond accuracy or attack success rate to report query counts or runtime, transferability across models, and behavior under defenses; currently only 18 studies address efficiency and 19 test defenses.
  • Feasibility is the best-developed practical constraint, so new attacks should be expected to enforce at least structural constraints and ideally mutability and inter-feature dependencies.
  • The concepts of plausibility and semantic preservation need formal definitions for tabular data before they can be optimized; the paper finds them addressed in only 11 and 6 studies respectively.
  • New learning paradigms (pretraining, self-supervised and multitask learning, retrieval-augmented inference) and tasks like question answering over tables are open ground for adversarial robustness research, since current work covers almost exclusively supervised classification.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • A broader search that did not require the literal phrase 'tabular data' would likely recover additional domain-specific attacks, especially in cybersecurity and finance, where authors may describe their inputs as network flows or transactions instead.
  • The finding that all 53 studies measure efficacy but only a handful check plausibility or semantics suggests that publication pressure itself selects for attack success rate as the de facto bar, a dynamic that standardized benchmarks could counteract.
  • If the eight-dimension coding were applied to computer-vision attack papers, the plausibility and transferability columns would probably look very different; the contrast could give the tabular community a concrete target for maturity.
  • The review's venue fragmentation (46 venues for 53 papers) implies that progress may depend less on new attack algorithms than on shared infrastructure: a common benchmark, a common threat model, and release of attack code.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

5 major / 4 minor

Summary. This paper presents a systematic literature review of adversarial attacks on tabular machine learning, following the PRISMA 2020 workflow. The authors report identifying 53 studies and 61 distinct attacks, organize the attacks into gradient-based, gradient-free, learning-based, and hybrid categories, and code each study on eight practical-consideration dimensions (efficacy, efficiency, transferability, feasibility, semantic preservation, plausibility, defense awareness, dataset suitability). They analyze publication trends, attack methodologies, and datasets, and derive a set of research gaps and future directions for adversarial robustness in tabular ML.

Significance. If its quantitative synthesis were internally consistent, this would be a useful contribution: it is the first dedicated systematic review of adversarial attacks on tabular data, provides a clear taxonomy of attack strategies, documents a transparent PRISMA-style selection process, and compiles a detailed dataset inventory. The qualitative observations about fragmentation, lack of benchmarks, and uneven attention to practical considerations are plausible and valuable for orienting future work. However, the headline numbers that the review's conclusions rest on are not reproducible from the paper's own tables and figures, and the coding procedure for the eight practical considerations lacks evidence of reliability. The central claims are therefore defensible in direction but not yet fully supported in their quantitative form.

major comments (5)
  1. [Section 5.2, Figure 6, Tables 3–6] The attack counts are internally inconsistent and cannot be reconciled. The text in Section 5.2 reports 61 unique attacks and then states gradient-free 23, gradient-based 19, learning-based 15, hybrid 6, which sum to 63. Figure 6 reports gradient-free 21 and learning-based 15. Tables 3–6 contain 19 gradient-based, 21 gradient-free, 14 learning-based, and 6 hybrid rows, summing to 60. Because the abstract's '61 attacks' claim and the category comparisons in RQ2 derive from these counts, the text, figure, and tables must all be reconciled to a single verified count before the review can support its headline statistics.
  2. [Section 5.2.3, Table 5, Figure 6] The learning-based category count is self-contradictory. Section 5.2 states that learning-based attacks number 15, and Figure 6 shows 15, while Table 5 lists 14 rows. The text then says 'GAN-based methods (12 out of 14)', which conflicts with the 14 rows in Table 5 and with the stated total of 15. The 'GAN-dominated' narrative and the comparative claims about learning-based attacks depend on this ratio, so the total count and the GAN/non-GAN split must be corrected and made consistent across text, table, and figure.
  3. [Section 5.2 summary box and Section 6] The code-release statistic is inverted between two parts of the paper. The Section 5.2 summary states that 'only 21 out of 61 attacks having public code', whereas Section 6 states that '21 out of 61 attacks do not release their code'. These statements have opposite meanings for the open-source-availability gap. The 'Code' column in the attack tables should be re-audited and the summary and discussion rewritten to state one consistent, verified figure.
  4. [Section 5.3, Tables 8 and 9] The coding of the eight practical considerations, which underpins RQ3 and the gap analysis throughout the paper, is reported without a complete coding protocol or reliability evidence. Section 5.3 defines three labels (Considered, Acknowledged, Not considered) and Appendix B gives a mapping in Table 8, but there is no dual coding, no inter-rater reliability statistic, and no description of how disagreements were resolved. In addition, Table 9 contains a row for reference [98], which is a background citation and not one of the 53 included studies. Because the aggregate numbers in Figure 7 and the 'fewer than 19 studies' conclusions are built on this coding, the authors should provide the full coding sheet, remove non-included references, and report reliability or at least justify the coding's consistency.
  5. [Appendix A, Table 7] Table 7 lists reference [114] twice, with different years and venues (2022/2023 AAAI and 2024/2024 NextGenAISafety workshop). Since Table 7 is the enumeration of the 53 included studies, a duplicate row means the population count is not uniquely identifiable. This must be corrected to ensure that the '53 studies' figure is a count of distinct studies.
minor comments (4)
  1. [Section 5.3.7] The opening sentence is contradictory: '19 of the reviewed studies do not evaluate their attacks against any defense mechanism. Of the 19 that do ...' The first clause should presumably read '19 ... do evaluate their attacks against defense mechanisms', matching the subsequent 'Of the 19 that do'.
  2. [Section 5.3.8 and Section 5.3 summary box] The number of datasets used by only one study is given as 32 in Section 5.3.8 but as 34 in the Section 5.3 summary box. This should be checked and aligned.
  3. [Section 6 and Section 5.3.8] There are several typographical errors: 'is is' in Section 6, 'lipshitz' should be 'Lipschitz' in Section 6, and 'hypothetize' should be 'hypothesize' in Section 5.3.8.
  4. [Section 3] The search string requires the exact phrase 'tabular data'. Since the review claims to be a systematic consolidation of the field, the authors should either justify this restrictive term or report a sensitivity check with synonyms such as 'structured data' and 'table data' to demonstrate that relevant work was not missed.

Circularity Check

0 steps flagged · score 1.0 of 10

No significant circularity: the review's claims are descriptive syntheses of external literature; self-citations are present but not load-bearing.

full rationale

This is a systematic literature review rather than a derivation, so there are no equations, fitted parameters, or predictions that could reduce to inputs by construction. Its central claims—53 studies, 61 attacks, and eight practical considerations—are aggregations of externally published papers collected through a PRISMA search and coded with a self-defined rubric. Defining a coding instrument and then applying it to papers is standard review methodology; the coded outputs are not equivalent to the rubric's definition by construction. The paper does cite several works by its own authors ([37], [38], [111], [112], [113], [114]) as reviewed items and as context, and one conclusion about GAN-based attacks cites the authors' own empirical paper [38]. Those citations are descriptive or empirical rather than load-bearing theorems, and the central synthesis does not depend on a self-citation chain. The internal count inconsistencies noted in the manuscript (e.g., gradient-free 23 vs 21, learning-based 14 vs 15, and the reversed code-release statement) are data-quality and reproducibility concerns, not circularity. No claimed derivation is equivalent to its inputs by definition, so the circularity score is low.

Assumptions & free parameters 0 free parameters · 3 assumptions · 0 invented entities

The review does not fit a derivation-style ledger; no free parameters or invented entities are present. The central claims depend on three domain assumptions: search and database coverage, consistent coding, and metadata accuracy. These are listed as axioms.

assumptions (3)
  • domain assumption The search string and chosen databases recover the population of relevant studies on tabular adversarial attacks.
    Section 3 uses a query requiring the exact phrase "tabular data"; this relies on authors using that terminology and on database coverage.
  • domain assumption The three-label coding (Considered/Acknowledged/Not considered) is applied consistently and without bias across the 53 papers.
    Section 5.3 and Tables 8 and 9 assign labels per paper with no inter-rater reliability, dual coding, or detailed protocol.
  • domain assumption Citation counts and venue metadata from Google Scholar are accurate as of the stated retrieval date.
    Appendix A reports citation counts, but these are volatile and database-dependent.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Insights on Adversarial Attacks for Tabular Machine Learning via a Systematic Literature Review." pith.science (2026). https://pith.science/paper/CLJA2QXI

@misc{pith2026250615506,
  author       = {Pith},
  title        = {Pith review of: Insights on Adversarial Attacks for Tabular Machine Learning via a Systematic Literature Review},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/CLJA2QXI}},
  note         = {Machine review of arXiv:2506.15506}
}
read the original abstract

Adversarial attacks in machine learning have been extensively reviewed in areas like computer vision and NLP, but research on tabular data remains scattered. This paper provides the first systematic literature review focused on adversarial attacks targeting tabular machine learning models. We highlight key trends, categorize attack strategies and analyze how they address practical considerations for real-world applicability. Additionally, we outline current challenges and open research questions. By offering a clear and structured overview, this review aims to guide future efforts in understanding and addressing adversarial vulnerabilities in tabular machine learning.

Figures

Figures reproduced from arXiv: 2506.15506 by the authors.

Figure 1
Figure 1. Overview of the research paper screening process. [PITH_FULL_IMAGE:figures/full_fig_p007_1.png] view at source ↗
Figure 3
Figure 3. Publications by venue type. Publications by Venue. We examine how publications are distributed by venue type, as seen historically in [PITH_FULL_IMAGE:figures/full_fig_p009_3.png] view at source ↗
Figure 5
Figure 5. Citations distribution per application domain. [PITH_FULL_IMAGE:figures/full_fig_p010_5.png] view at source ↗
Figures from the paper (5 more)
Figure 6
Figure 6. Figure 6: Distribution of attacks across tasks, target, knowledge, and optimization. [PITH_FULL_IMAGE:figures/full_fig_p013_6.png]
Figure 7
Figure 7. Figure 7: Aggregated statistics regarding practical considerations addressed across studies. [PITH_FULL_IMAGE:figures/full_fig_p019_7.png]
Figure 8
Figure 8. Figure 8: Distribution of Considered Practical Dimensions Across Studies. [PITH_FULL_IMAGE:figures/full_fig_p020_8.png]
Figure 10
Figure 10. Figure 10: Overlap between addressed feasibility constraints. [PITH_FULL_IMAGE:figures/full_fig_p022_10.png]
Figure 11
Figure 11. Figure 11: Distribution of datasets per year. 2 4 6 8 Number of Papers Using Dataset 0 10 20 30 Datasets 34 [PITH_FULL_IMAGE:figures/full_fig_p026_11.png]

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

193 extracted references · 66 canonical work pages

  1. [98]

    Nicolas Papernot, Patrick McDaniel, and Ian Goodfellow. 2016. Transferability in machine learning: from phenomena to black-box attacks using adversarial samples.arXiv preprint arXiv:1605.07277

  2. [114]

    Thibault Jean Angel Simonetto, Salah Ghamizi, and Maxime Cordy. 2024. Towards Adaptive Attacks on Constrained Tabular Machine Learning. ICML 2024 Workshop on the Next Generation of AI Safety

  3. [1]

    Neda Abdelhamid, Aladdin Ayesh, and Fadi Thabtah. 2014. Phishing detection based associative classification data mining.Expert Systems with Applications

  4. [2]

    Ahmed Abusnaina, Aminollah Khormali, DaeHun Nyang, Murat Yuksel, and Aziz Mohaisen. 2019. Examining the robustness of learning-based ddos detection in software defined networks.IEEE Conference on Dependable and Secure Computing (DSC)

  5. [3]

    Stefan Aeberhard and M. Forina. 1992. Wine. UCI Machine Learning Repository. DOI: https://doi.org/10.24432/C5PC7J

  6. [4]

    Akshay Agarwal and Nalini K Ratha. 2021. Black-Box Adversarial Entry in Finance through Credit Card Fraud Detection.CIKM Workshops

  7. [5]

    Airbnb. 2018. Lodging Airbnb Listings in Major U.S. Cities. http://insideairbnb.com/get-the-data.html

  8. [6]

    Elie Alhajjar, Paul Maxwell, and Nathaniel Bastian. 2021. Adversarial machine learning in network intrusion detection systems.Expert Systems with Applications

Show all 193 references
  1. [7]

    Nour Alhussien, Ahmed Aleroud, Abdullah Melhem, and Samer Y Khamaiseh. 2024. Constraining adversarial attacks on network intrusion detection systems: transferability and defense analysis.IEEE Transactions on Network and Service Management

  2. [8]

    Ahmed Alkhateeb. 2019. DeepMIMO: A generic deep learning dataset for millimeter wave and massive MIMO applications.arXiv preprint arXiv:1902.06435

  3. [9]

    Afnan Alotaibi and Murad A Rassam. 2023. Adversarial machine learning attacks against intrusion detection systems: A survey on strategies and defense.Future Internet

  4. [10]

    Hyrum S Anderson and Phil Roth. 2018. Ember: an open dataset for training static pe malware machine learning models.arXiv preprint arXiv:1804.04637

  5. [11]

    Psannis, Sotirios Goudos, and Panagiotis Sarigiannidis

    Dimitrios Christos Asimopoulos, Panagiotis Radoglou-Grammatikis, Ioannis Makris, Valeri Mladenov, Konstantinos E. Psannis, Sotirios Goudos, and Panagiotis Sarigiannidis. 2023. Breaching the Defense: Investigating FGSM and CTGAN Adversarial Attacks on IEC 60870-5-104 AI-enabled...

  6. [12]

    Mingqiang Bai, Puzhuo Liu, Fei Lv, Dongliang Fang, Shichao Lv, Weidong Zhang, and Limin Sun. 2024. Adversarial Attack against Intrusion Detectors in Cyber-Physical Systems With Minimal Perturbations.IEEE International Symposium on Parallel and Distributed Processing with Appli...

  7. [13]

    Vincent Ballet, Xavier Renard, Jonathan Aigrain, Thibault Laugel, Pascal Frossard, and Marcin Detyniecki. 2019. Imperceptible adversarial attacks on tabular data.arXiv preprint arXiv:1911.03274

  8. [14]

    Hongyan Bao, Yufei Han, Yujun Zhou, Xin Gao, and Xiangliang Zhang. 2023. Towards efficient and domain-agnostic evasion attack with high-dimensional categorical inputs.AAAI Conference on Artificial Intelligence

  9. [15]

    Barry Becker and Ronny Kohavi. 1996. Adult. UCI Machine Learning Repository. DOI: https://doi.org/10.24432/C5XW20

  10. [16]

    Elaheh Biglar Beigi, Hossein Hadian Jazi, Natalia Stakhanova, and Ali A Ghorbani. 2014. Towards effective feature selection in machine learning- based botnet detection approaches.IEEE Conference on Communications and Network Security

  11. [17]

    Matan Ben-Tov, Daniel Deutch, Nave Frost, and Mahmood Sharif. 2024. CaFA: Cost-aware, Feasible Attacks With Database Constraints Against Neural Tabular Classifiers.IEEE Symposium on Security and Privacy (SP)

  12. [18]

    Battista Biggio, Igino Corona, Davide Maiorca, Blaine Nelson, Nedim Šrndić, Pavel Laskov, Giorgio Giacinto, and Fabio Roli. 2013. Evasion attacks against machine learning at test time.Machine learning and knowledge discovery in databases: European conference, ECML pKDD

  13. [19]

    R. Bock. 2004. MAGIC Gamma Telescope. UCI Machine Learning Repository. DOI: https://doi.org/10.24432/C52C8B

  14. [20]

    Wieland Brendel, Jonas Rauber, and Matthias Bethge. 2018. Decision-based adversarial attacks: Reliable attacks against black-box machine learning models.International Conference on Learning Representations (ICLR)

  15. [21]

    Nicholas Carlini and David Wagner. 2017. Towards evaluating the robustness of neural networks.IEEE Symposium on Security and Privacy (SP)

  16. [22]

    Francesco Cartella, Orlando Anunciação, Yuki Funabiki, Daisuke Yamaguchi, Toru Akishita, and Olivier Elshocht. 2021. Adversarial attacks for tabular data: application to fraud detection and imbalanced data.CEUR Workshop Proceedings

  17. [23]

    Jiming Chen, Xiangshan Gao, Ruilong Deng, Yang He, Chongrong Fang, and Peng Cheng. 2020. Generating adversarial examples against machine learning-based intrusion detector in industrial control systems.IEEE Transactions on Dependable and Secure Computing

  18. [24]

    Jianbo Chen, Michael I Jordan, and Martin J Wainwright. 2020. HopSkipJumpAttack: A Query-Efficient Decision-Based Adversarial Attack.IEEE Symposium on Security and Privacy (SP)

  19. [25]

    Steven Chen, Nicholas Carlini, and David Wagner. 2020. Stateful detection of black-box adversarial attacks.ACM Workshop on Security and Privacy on Artificial Intelligence

  20. [26]

    Alesia Chernikova and Alina Oprea. 2022. FENCE: Feasible Evasion Attacks on Neural Networks in Constrained Environments.ACM Trans. Priv. Secur

  21. [27]

    Kang Leng Chiew, Choon Lin Tan, KokSheik Wong, Kelvin SC Yong, and Wei King Tiong. 2019. A new hybrid ensemble feature selection framework for machine learning-based phishing detection system.Information Sciences

  22. [28]

    Federico Concone, Salvatore Gaglio, Andrea Giammanco, Giuseppe Lo Re, and Marco Morana. 2024. AdverSPAM: Adversarial SPam account manipulation in online social networks.ACM Transactions on Privacy and Security

  23. [29]

    Igino Corona, Battista Biggio, Matteo Contini, Luca Piras, Roberto Corda, Mauro Mereu, Guido Mureddu, Davide Ariu, and Fabio Roli. 2017. Deltaphish: Detecting phishing webpages in compromised websites.European Symposium on Research in Computer Security. Manuscript submitted to...

  24. [30]

    Andrea Dal Pozzolo. 2015. Adaptive machine learning for credit card fraud detection. Université libre de Bruxelles

  25. [31]

    Arnaud de Servigny and Will Cukierski. 2014. Loan Default Prediction - Imperial College London. https://kaggle.com/competitions/loan-default- prediction. Kaggle

  26. [32]

    Christian Schroeder de Witt, Yongchao Huang, Philip HS Torr, and Martin Strohmeier. 2022. Fixed points in cyber space: Rethinking optimal evasion attacks in the age of AI-NIDS.ICML workshop on Machine Learning for Cybersecurity (ICML-ML4Cyber)

  27. [33]

    Islam Debicha, Benjamin Cochez, Tayeb Kenaza, Thibault Debatty, Jean-Michel Dricot, and Wim Mees. 2023. Adv-Bot: Realistic adversarial botnet attacks against network intrusion detection systems.Computers & Security

  28. [34]

    Mohamed Djilani, Salah Ghamizi, and Maxime Cordy. 2024. RobustBlack: Challenging Black-Box Adversarial Attacks on State-of-the-Art Defenses. arXiv preprint arXiv:2412.20987

  29. [35]

    Mingxing Duan, Kenli Li, Weinan Zhang, Jiarui Qin, and Bin Xiao. 2024. Attacking Click-through Rate Predictors via Generating Realistic Fake Samples.ACM Transactions on Knowledge Discovery from Data

  30. [36]

    Phan The Duy, Nghi Hoang Khoa, Hien Do Hoang, Van-Hau Pham, et al. 2023. Investigating on the robustness of flow-based intrusion detection system against adversarial samples using generative adversarial networks.Journal of Information Security and Applications

  31. [37]

    Salijona Dyrmishi, Salah Ghamizi, Thibault Simonetto, Yves Le Traon, and Maxime Cordy. 2023. On the empirical effectiveness of unrealistic adversarial hardening against realistic adversarial attacks.IEEE Symposium on Security and Privacy(SP)

  32. [38]

    Salijona Dyrmishi, Mihaela CÄ Stoian, Eleonora Giunchiglia, and Maxime Cordy. 2024. Deep generative models as an adversarial attack strategy for tabular machine learning.International Conference on Machine Learning and Cybernetics (ICMLC)

  33. [39]

    Mahmoud Said Elsayed, Nhien-An Le-Khac, and Anca D Jurcut. 2020. InSDN: A novel SDN intrusion dataset.IEEE Access

  34. [40]

    Ecenaz Erdemir, Jeffrey Bickford, Luca Melis, and Sergul Aydore. 2021. Adversarial robustness with non-uniform perturbations.Advances in Neural Information Processing Systems

  35. [41]

    Mohd Fazil and Muhammad Abulaish. 2018. A hybrid approach for detecting automated spammers in twitter.IEEE Transactions on Information Forensics and Security

  36. [42]

    FICO. 2018. HELOC Dataset. https://huggingface.co/datasets/mstz/heloc

  37. [43]

    Ronald A Fisher. 1936. The use of multiple measurements in taxonomic problems.Annals of eugenics

  38. [44]

    Veloso-Marcus Freire, Ananda and Guilherme Barreto. 2009. Wall-Following Robot Navigation Data. UCI Machine Learning Repository. DOI: https://doi.org/10.24432/C57C8W

  39. [45]

    Ji Gao, Beilun Wang, Zeming Lin, Weilin Xu, and Yanjun Qi. 2017. Deepcloak: Masking deep neural network models for robustness against adversarial samples.International Conference on Learning Representations (ICLR)

  40. [46]

    Sebastian Garcia, Martin Grill, Jan Stiborek, and Alejandro Zunino. 2014. An empirical comparison of botnet detection methods.Computers & Security

  41. [47]

    Sebastian Garcia, Agustin Parmisano, and Maria Jose Erquiaga. 2020. IoT-23: A labeled dataset with malicious and benign IoT network traffic.(No Title)

  42. [48]

    Nathan George. 2019. Lending Club Loan Data. https://www.kaggle.com/datasets/wordsforthewise/lending-club

  43. [49]

    Salah Ghamizi, Maxime Cordy, Martin Gubri, Mike Papadakis, Andrey Boystov, Yves Le Traon, and Anne Goujon. 2020. Search-based adversarial testing and improvement of constrained credit scoring systems.ACM Joint Meeting on European Software Engineering Conference and Symposium o...

  44. [50]

    Zafar Gilani, Ekaterina Kochmar, and Jon Crowcroft. 2017. Classification of twitter accounts into automated agents and human users.IEEE/ACM International Conference on Advances in Social Networks Analysis and Mining

  45. [51]

    Jonathan Goh, Sridhar Adepu, Khurum Nazir Junejo, and Aditya Mathur. 2017. A dataset to support research in the design of secure water treatment systems.Critical Information Infrastructures Security

  46. [52]

    Yury Gorishniy, Akim Kotelnikov, and Artem Babenko. 2025. Tabm: Advancing tabular deep learning with parameter-efficient ensembling. International Conference on Learning Representations (ICLR)

  47. [53]

    Gilad Gressel, Niranjan Hegde, Archana Sreekumar, Rishikumar Radhakrishnan, Kalyani Harikumar, Krishnashree Achuthan, et al. 2021. Feature importance guided attack: A model agnostic adversarial attack.arXiv preprint arXiv:2106.14815

  48. [54]

    Jindong Gu, Xiaojun Jia, Pau de Jorge, Wenqain Yu, Xinwei Liu, Avery Ma, Yuan Xun, Anjun Hu, Ashkan Khakzar, Zhijiang Li, et al. 2023. A survey on transferability of adversarial examples across deep neural networks.Transactions on Machine Learning Research (TMLR)

  49. [55]

    Malliaros

    Kavya Gupta, Beatrice Pesquet-Popescu, Fateh Kaakai, Jean-Christophe Pesquet, and Fragkiskos D. Malliaros. 2021. An adversarial attacker for neural networks in regression problems.CEUR Workshop Proceedings

  50. [56]

    Abdelhakim Hannousse and Salima Yahiouche. 2021. Towards benchmark datasets for machine learning based website phishing detection: An experimental study.Engineering Applications of Artificial Intelligence

  51. [57]

    F Maxwell Harper and Joseph A Konstan. 2015. The movielens datasets: History and context.ACM Transactions on Interactive Intelligent Systems (TIIS)

  52. [58]

    Ke He, Dan Dongseong Kim, and Muhammad Rizwan Asghar. 2023. Adversarial machine learning for network intrusion detection systems: A comprehensive survey.IEEE Communications Surveys & Tutorials

  53. [59]

    Hans Hofmann. 1994. Statlog (German Credit Data). UCI Machine Learning Repository. DOI: https://doi.org/10.24432/C5NC77. Manuscript submitted to ACM Insights on Adversarial Attacks for Tabular Machine Learning via a Systematic Literature Review 31

  54. [60]

    Noah Hollmann, Samuel Müller, Lennart Purucker, Arjun Krishnakumar, Max Körfer, Shi Bin Hoo, Robin Tibor Schirrmeister, and Frank Hutter

  55. [61]

    Reeber-Erik Forman George Hopkins, Mark and Jaap Suermondt. 1999. Spambase. UCI Machine Learning Repository. DOI: https://doi.org/10.24432/C53G6X

  56. [62]

    Hussein Abbass

    Addison Howard, Bernadette Bouchon-Meunier, IEEE CIS, inversion, John Lei, Lynn@Vesta, Marcus2010, and Prof. Hussein Abbass. 2019. IEEE-CIS Fraud Detection. https://kaggle.com/competitions/ieee-fraud-detection. Kaggle

  57. [63]

    Niddal H Imam and Vassilios G Vassilakis. 2019. A survey of attacks against twitter spam detectors in an adversarial environment.Robotics

  58. [64]

    Lunhao Ju, Ruijing Cui, Jianbin Sun, and Zituo Li. 2022. A Robust Approach to Adversarial Attack on Tabular Data for Classification Algorithm Testing.International Conference on Big Data and Information Analytics (BigDIA)

  59. [65]

    Rohitha Karumanchi and Gilad Gressel. 2023. Minimum Selection Feature Importance Guided Attack.IEEE World Conference on Applied Intelligence and Computing (AIC)

  60. [66]

    Vidit Khazanchi, Pavan Kulkarni, Yuvaraj Govindarajulu, and Manojkumar Parmar. 2024. MISLEAD: Manipulating Importance of Selected features for Learning Epsilon in Evasion Attack Deception.arXiv preprint arXiv:2404.15656

  61. [67]

    Klim Kireev, Bogdan Kulynych, and Carmela Troncoso. 2023. Adversarial Robustness for Tabular Data through Cost and Utility Awareness.Annual Network and Distributed System Security Symposium (NDSS)

  62. [68]

    Barbara Kitchenham. 2004. Procedures for performing systematic reviews.Keele, UK, Keele University

  63. [69]

    Xiangyin Kong and Zhiqiang Ge. 2023. Adversarial attacks on regression systems via gradient optimization.IEEE Transactions on Systems, Man, and Cybernetics: Systems

  64. [70]

    Nishant Kumar, Siddharth Vimal, Kanishka Kayathwal, and Gaurav Dhama. 2021. Evolutionary Adversarial Attacks on Payment Systems.IEEE International Conference on Machine Learning and Applications (ICMLA)

  65. [71]

    Alexey Kurakin, Ian J Goodfellow, and Samy Bengio. 2018. Adversarial examples in the physical world.Artificial Intelligence Safety and Security

  66. [72]

    Jiahe Lan, Rui Zhang, Zheng Yan, Jie Wang, Yu Chen, and Ronghui Hou. 2022. Adversarial attacks and defenses in speaker recognition systems: A survey.Journal of Systems Architecture

  67. [73]

    Jehyun Lee, Pingxiao Ye, Ruofan Liu, Dinil Mon Divakaran, and Mun Choon Chan. 2020. Building robust phishing detection system: an empirical analysis.NDSS MADWeb

  68. [74]

    Kyumin Lee, Brian Eoff, and James Caverlee. 2011. Seven months with the devils: A long-term study of content polluters on twitter.AAAI Conference on Web and Social Media

  69. [75]

    Meredith Lee, Jesse Raffa, Marzyeh Ghassemi, Tom Pollard, Sharada Kalanidhi, Omar Badawi, Karen Matthys, and Leo Anthony Celi. 2020. WiDS (women in data science) datathon 2020: ICU mortality prediction (version 1.0. 0).PhysioNet

  70. [76]

    Jiangnan Li, Yingyuan Yang, Jinyuan Stella Sun, Kevin Tomsovic, and Hairong Qi. 2021. Conaml: Constrained adversarial machine learning for cyber-physical systems.ACM Asia Conference on Computer and Communications Security

  71. [77]

    Hairen Liao, Lingxiao Peng, Zhenchuan Liu, and Xuehua Shen. 2014. iPinYou global rtb bidding algorithm competition dataset.International Workshop on Data Mining for Online Advertising

  72. [78]

    Zilong Lin, Yong Shi, and Zhi Xue. 2022. Idsgan: Generative adversarial networks for attack generation against intrusion detection.Pacific-Asia Conference on Knowledge Discovery and Data Mining

  73. [79]

    Teng Long, Qi Gao, Lili Xu, and Zhangbing Zhou. 2022. A survey on adversarial attacks in computer vision: Taxonomy, visualization and future directions.Computers & Security

  74. [80]

    Fenglong Ma, Jing Gao, Qiuling Suo, Quanzeng You, Jing Zhou, and Aidong Zhang. 2018. Risk prediction on electronic health records with prior medical knowledge.ACM SIGKDD International Conference on Knowledge Discovery & Data Mining

  75. [81]

    Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2018. Towards deep learning models resistant to adversarial attacks.International Conference on Learning Representations (ICLR)

  76. [82]

    Sarthak Malik, Himanshi Charotia, and Gaurav Dhama. 2023. TETRAA - Trained and Selective Transmutation of Encoder-based Adversarial Attack.International Joint Conference on Neural Networks (IJCNN)

  77. [83]

    Mohammad Saiful Islam Mamun, Mohammad Ahmad Rathore, Arash Habibi Lashkari, Natalia Stakhanova, and Ali A Ghorbani. 2016. Detecting malicious urls using lexical analysis.Network and System Security

  78. [84]

    Nuno Martins, José Magalhães Cruz, Tiago Cruz, and Pedro Henriques Abreu. 2020. Adversarial machine learning applied to intrusion and malware scenarios: a systematic review.IEEE Access

  79. [85]

    Yael Mathov, Eden Levy, Ziv Katzir, Asaf Shabtai, and Yuval Elovici. 2022. Not all datasets are born equal: On heterogeneous tabular data and adversarial examples.Knowledge-Based Systems

  80. [86]

    Rami M Mohammad, Fadi Thabtah, and Lee McCluskey. 2012. An assessment of features related to phishing websites using an automated technique. International Conference for Internet Technology and Secured Transactions

  81. [87]

    Anna Montoya, inversion, KirillOdintsov, and Martin Kotek. 2018. Home Credit Default Risk. https://kaggle.com/competitions/home-credit- default-risk. Kaggle

  82. [88]

    Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, and Pascal Frossard. 2016. Deepfool: a simple and accurate method to fool deep neural networks. IEEE Conference on Computer Vision and Pattern Recognition (CVPR)

  83. [89]

    Sérgio Moro, Paulo Cortez, and Paulo Rita. 2014. A data-driven approach to predict the success of bank telemarketing.Decision Support Systems. Manuscript submitted to ACM 32 Dyrmishi et al

  84. [90]

    Thomas H Morris, Zach Thornton, and Ian Turnipseed. 2015. Industrial control system simulation and data logging for intrusion detection system research.Annual Southeastern Cyber Security Summit

  85. [91]

    Nour Moustafa and Jill Slay. 2015. UNSW-NB15: a comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set). Military Communications and Information Systems Conference (MilCIS)

  86. [92]

    Jay Nandy, Jatin Chauhan, Rishi Saket, and Aravindan Raghuveer. 2023. Non-Uniform Adversarial Perturbations for Discrete Tabular Datasets. ACM International Conference on Information and Knowledge Management

  87. [93]

    Quamar Niyaz, Weiqing Sun, and Ahmad Y Javaid. 2016. A deep learning based DDoS detection system in software-defined networking (SDN). arXiv preprint arXiv:1611.07400

  88. [94]

    Mohammad Nur Nobi, Ram Krishnan, Yufei Huang, Mehrnoosh Shakarami, and Ravi Sandhu. 2022. Toward deep learning based access control. ACM Conference on Data and Application Security and Privacy

  89. [95]

    Mohammad Nur Nobi, Ram Krishnan, and Ravi Sandhu. 2022. Adversarial Attacks in Machine Learning Based Access Control.CEUR Workshop Proceedings

  90. [96]

    Matthew J Page, Joanne E McKenzie, Patrick M Bossuyt, Isabelle Boutron, Tammy C Hoffmann, Cynthia D Mulrow, Larissa Shamseer, Jennifer M Tetzlaff, Elie A Akl, Sue E Brennan, et al. 2021. The PRISMA 2020 statement: an updated guideline for reporting systematic reviews.bmj

  91. [97]

    Anubha Pandey, Himanshu Chaudhary, Alekhya Bhatraju, Deepak Bhatt, and Maneet Singh. 2023. Improving the Robustness of Financial Models through Identification of the Minimal Vulnerable Feature Set.ACM International Conference on AI in Finance

  92. [99]

    Nicolas Papernot, Patrick McDaniel, Somesh Jha, Matt Fredrikson, Z Berkay Celik, and Ananthram Swami. 2016. The limitations of deep learning in adversarial settings.European Symposium on Security and Privacy (EuroS&P)

  93. [100]

    Denis Parfenov, Lyubov Grishina, Leonid Legashev, Artur Zhigalov, and Anton Parfenov. 2023. Investigation of the Security of ML-models in IoT Networks from Adversarial Attacks.IEEE Ural-Siberian Conference on Biomedical Engineering, Radioelectronics and Information Technology ...

  94. [101]

    Ross Quinlan. 1987. Statlog (Australian Credit Approval). UCI Machine Learning Repository. DOI: https://doi.org/10.24432/C59012

  95. [102]

    Panagiotis Radoglou Grammatikis, Konstantinos Rompolos, Panagiotis Sarigiannidis, Vasileios Argyriou, Thomas Lagkas, Antonios Sarigiannidis, Sotirios Goudos, and Shaohua Wan. 2021. Modeling, detecting, and mitigating threats against industrial healthcare systems: a combined so...

  96. [103]

    UC Irvine Machine Learning Repository. 2017. Faulty Steel Plates Dataset. https://www.kaggle.com/datasets/uciml/faulty-steel-plates

  97. [104]

    Abhinav Saxena, Kai Goebel, Don Simon, and Neil Eklund. 2008. Damage propagation modeling for aircraft engine run-to-failure simulation. International Conference on Prognostics and Health Management

  98. [105]

    Iman Sharafaldin, Arash Habibi Lashkari, Ali A Ghorbani, et al. 2018. Toward generating a new intrusion detection dataset and intrusion traffic characterization.ICISSp

  99. [106]

    Ryan Sheatsley, Blaine Hoak, Eric Pauley, Yohan Beugin, Michael J Weisman, and Patrick McDaniel. 2021. On the robustness of domain constraints. ACM SIGSAC Conference on Computer and Communications Security

  100. [107]

    Ryan Sheatsley, Nicolas Papernot, Michael Weisman, Gunjan Verma, and Patrick McDaniel. 2020. Adversarial examples in constrained domains. arXiv preprint arXiv:2011.01183

  101. [108]

    Kn0w Thy Doma1n Name

    Hossein Shirazi, Bruhadeshwar Bezawada, and Indrakshi Ray. 2018. " Kn0w Thy Doma1n Name" Unbiased Phishing Detection Using Domain Name Based Features.ACM On Symposium on Access Control Models and Technologies

  102. [109]

    Hossein Shirazi, Bruhadeshwar Bezawada, Indrakshi Ray, and Charles Anderson. 2019. Adversarial sampling attacks against phishing detection. Data and Applications Security and Privacy, DBSec

  103. [110]

    Hossein Shirazi, Bruhadeshwar Bezawada, Indrakshi Ray, and Chuck Anderson. 2021. Directed adversarial sampling attacks on phishing detection. Journal of Computer Security

  104. [111]

    Thibault Simonetto, Salijona Dyrmishi, Salah Ghamizi, Maxime Cordy, and Yves Le Traon. 2022. A unified framework for adversarial attack and defense in constrained feature space.International Joint Conference on Artificial Intelligence (IJCAI)

  105. [112]

    Thibault Simonetto, Salah GHAMIZI, and Maxime Cordy. 2024. Constrained Adaptive Attack: Effective Adversarial Attack Against Deep Neural Networks for Tabular Data.Annual Conference on Neural Information Processing Systems (NeurIPS)

  106. [113]

    Thibault Simonetto, Salah Ghamizi, and Maxime Cordy. 2024. TabularBench: Benchmarking Adversarial Robustness for Tabular Deep Learning in Real-world Use-cases.Advances in Neural Information Processing Systems

  107. [115]

    Mihaela Cătălina Stoian, Salijona Dyrmishi, Maxime Cordy, Thomas Lukasiewicz, and Eleonora Giunchiglia. 2024. How realistic is your synthetic data? constraining deep generative models for tabular data.International Conference on Learning Representations (ICLR)

  108. [116]

    Fan Wei Lee Wenke Prodromidis Andreas Stolfo, Salvatore and Philip Chan. 1999. KDD Cup 1999 Data. UCI Machine Learning Repository. DOI: https://doi.org/10.24432/C51C7N

  109. [117]

    Peishuai Sun, Shuhao Li, Jiang Xie, Hongbo Xu, Zhenyu Cheng, and Rong Yang. 2023. GPMT: Generating practical malicious traffic based on adversarial attacks with little prior knowledge.Computers & Security. Manuscript submitted to ACM Insights on Adversarial Attacks for Tabular...

  110. [118]

    Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. 2014. Intriguing properties of neural networks.International Conference on Learning Representations (ICLR)

  111. [119]

    Choon Lin Tan. 2018. Phishing dataset for machine learning: Feature evaluation.Mendeley Data

  112. [120]

    Mahbod Tavallaee, Ebrahim Bagheri, Wei Lu, and Ali A Ghorbani. 2009. A detailed analysis of the KDD CUP 99 data set.IEEE Symposium on Computational Intelligence for Security and Defense Applications

  113. [121]

    Martin Teuffenbach, Ewa Piatkowska, and Paul Smith. 2020. Subverting network intrusion detection: Crafting adversarial examples accounting for domain-specific constraints.International Cross-Domain Conference (CD-MAKE)

  114. [122]

    Yunzhe Tian, Yingdi Wang, Endong Tong, Wenjia Niu, Liang Chang, Qi Alfred Chen, Gang Li, and Jiqiang Liu. 2020. Exploring data correlation between feature pairs for generating constraint-based adversarial examples.International Conference on Parallel and Distributed Systems (ICPADS)

  115. [123]

    Jean-Baptiste Tien, joycenv, and Olivier Chapelle. 2014. Display Advertising Challenge. https://kaggle.com/competitions/criteo-display-ad- challenge. Kaggle

  116. [124]

    Muhammad Usama, Muhammad Asim, Siddique Latif, Junaid Qadir, et al. 2019. Generative adversarial networks for launching and thwarting adversarial attacks on network intrusion detection systems.International wireless communications & mobile computing conference (IWCMC)

  117. [125]

    Bram Van Dooremaal, Pavlo Burda, Luca Allodi, and Nicola Zannone. 2021. Combining text and visual features to improve the identification of cloned webpages for early phishing detection.International Conference on A vailability, Reliability and Security

  118. [126]

    João Vitorino, Nuno Oliveira, and Isabel Praça. 2022. Adaptative Perturbation Patterns: Realistic Adversarial Learning for Robust Intrusion Detection.Future Internet

  119. [127]

    Di Wang, Xuemeng Wang, and Jinlong Fei. 2024. IDS-GAN: adversarial attack against intrusion detection based on generative adversarial networks. International Conference on Computer Vision, Image and Deep Learning (CVIDL)

  120. [128]

    Steve Wang and Will Cukierski. 2014. Click-Through Rate Prediction. https://kaggle.com/competitions/avazu-ctr-prediction. Kaggle

  121. [129]

    Yutong Wang, Yufei Han, Hongyan Bao, Yun Shen, Fenglong Ma, Jin Li, and Xiangliang Zhang. 2020. Attackability characterization of adversarial evasion attack on discrete data.ACM SIGKDD International Conference on Knowledge Discovery & Data Mining

  122. [130]

    Jing Wu, Suiyao Chen, Qi Zhao, Renat Sergazinov, Chen Li, Shengjie Liu, Chongchao Zhao, Tianpei Xie, Hanqing Guo, Cheng Ji, et al . 2024. Switchtab: Switched autoencoders are effective tabular learners.AAAI Conference on Artificial Intelligence

  123. [131]

    Cihang Xie, Yuxin Wu, Laurens van der Maaten, Alan L Yuille, and Kaiming He. 2019. Feature denoising for improving adversarial robustness. IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)

  124. [132]

    Han Xu, Pengfei He, Jie Ren, Yuxuan Wan, Zitao Liu, Hui Liu, and Jiliang Tang. 2023. Probabilistic categorical adversarial attack and adversarial training.International Conference on Machine Learning (ICML)

  125. [133]

    I-Cheng Yeh and Che-hui Lien. 2009. The comparisons of data mining techniques for the predictive accuracy of probability of default of credit card clients.Expert systems with applications

  126. [134]

    Suleiman Y Yerima and Sakir Sezer. 2018. Droidfusion: A novel multilevel classifier fusion approach for android malware detection.IEEE Transactions on Cybernetics

  127. [135]

    Ying Yuan, Giovanni Apruzzese, and Mauro Conti. 2024. Multi-SpacePhish: Extending the evasion-space of adversarial attacks against phishing website detectors using machine learning.Digital Threats: Research and Practice

  128. [136]

    Hongyang Zhang, Yaodong Yu, Jiantao Jiao, Eric Xing, Laurent El Ghaoui, and Michael Jordan. 2019. Theoretically principled trade-off between robustness and accuracy.International Conference on Machine Learning (ICML)

  129. [137]

    Wei Emma Zhang, Quan Z Sheng, Ahoud Alhazmi, and Chenliang Li. 2020. Adversarial attacks on deep-learning models in natural language processing: A survey.ACM Transactions on Intelligent Systems and Technology (TIST)

  130. [138]

    Shuang Zhao, Jing Li, Jianmin Wang, Zhao Zhang, Lin Zhu, and Yong Zhang. 2021. attackgan: Adversarial attack against black-box ids using generative adversarial networks.Procedia Computer Science

  131. [139]

    Matjaz Zwitter and Milan Soklic. 1988. Breast Cancer. UCI Machine Learning Repository. DOI: https://doi.org/10.24432/C51P4M. Manuscript submitted to ACM 34 Dyrmishi et al. A Research trends Table 7. Metadata extracted from 53 papers under review. Citations obtained on 10/3/202...

  132. [141]

    2018 2022 PAKDD Conference Big Data, Data Mining, & Knowledge Discovery 426 Cybersecurity

  133. [142]

    2019 2019 arXiv Pre-Print Others 115 General

  134. [143]

    2019 2019 DBSec Conference Cybersecurity 45 Cybersecurity

  135. [144]

    2019 2019 IWCMC Conference Computer Networks & Communication 198 Cybersecurity

  136. [145]

    2019 2019 DSC Conference Cybersecurity 25 Cybersecurity

  137. [146]

    2020 2020 KDD Conference Big Data, Data Mining, & Knowledge Discovery 22 General

  138. [147]

    2020 2020 arXiv Pre-Print Others 27 General

  139. [148]

    2020 2020 ICPADS Conference System Design & Engineering 7 General

  140. [149]

    2020 2020 MAKE Conference AI & ML 20 Cybersecurity

  141. [150]

    2020 2020 ESEC/FSE Conference Others 31 Finance

  142. [151]

    2021 2020 ESWA Journal System Design & Engineering 189 Cybersecurity

  143. [152]

    2021 2021 NeurIPS Conference AI & ML 34 General

  144. [153]

    2021 2021 AI Safety Workshop AI & ML 30 General

  145. [154]

    2021 2021 arXiv Pre-Print Others 17 General

  146. [155]

    2021 2021 MUFin21 Workshop Big Data, Data Mining, & Knowledge Discovery 13 Finance

  147. [156]

    2021 2021 SafeAI Workshop AI & ML 95 Finance

  148. [157]

    2021 2021 ICMLA Conference AI & ML 17 Finance

  149. [158]

    2021 2021 JCS Journal Cybersecurity 9 Cybersecurity

  150. [159]

    2020 2021 AsiaCCS Conference Cybersecurity 76 Other

  151. [160]

    2021 2021 CCS Conference Cybersecurity 35 General

  152. [161]

    2021 2021 IIKI Conference Others 50 Cybersecurity

  153. [162]

    2021 2021 ICML-ML4Cyber Workshop AI & ML 5 Cybersecurity

  154. [163]

    2022 2022 BigDIA Conference Big Data, Data Mining, & Knowledge Discovery 5 General

  155. [164]

    2022 2022 Future Internet Journal Computer Networks & Communication 33 Cybersecurity

  156. [165]

    2020 2022 KBS Journal Big Data, Data Mining, & Knowledge Discovery 32 General

  157. [166]

    2022 2022 ITADATA Conference Big Data, Data Mining, & Knowledge Discovery 3 Other

  158. [167]

    2019 2022 TOPS Journal Cybersecurity 52 General

  159. [168]

    2022 2022 TDSC Journal System Design & Engineering 69 Cybersecurity

  160. [169]

    2021 2022 IJCAI Conference AI & ML 24 General

  161. [170]

    2022 2023 AAAI Conference AI & ML 4 General

  162. [171]

    2023 2023 USBEREIT Conference System Design & Engineering 1 Other

  163. [172]

    2023 2023 ICAIF Conference Others 3 Finance

  164. [173]

    2023 2023 IJCNN Conference AI & ML 0 General

  165. [174]

    2022 2023 NDSS Conference Cybersecurity 21 General

  166. [175]

    2023 2023 arXiv Pre-Print Others 0 General

  167. [176]

    2023 2023 SMC Journal System Design & Engineering 6 General

  168. [177]

    2023 2023 CIKM Conference Big Data, Data Mining, & Knowledge Discovery 2 General

  169. [178]

    2023 2023 C & S Journal Cybersecurity 5 Cybersecurity

  170. [179]

    2023 2023 C & S Journal Cybersecurity 35 Cybersecurity

  171. [180]

    2023 2023 ARES Conference Cybersecurity 9 Cybersecurity

  172. [181]

    2023 2023 JISA Journal Cybersecurity 17 Cybersecurity

  173. [182]

    2022 2023 ICML Conference AI & ML 14 General

  174. [183]

    2023 2024 NeurIPS Conference AI & ML 1 General

  175. [184]

    2024 2024 SP Conference Cybersecurity 0 General

  176. [185]

    2024 2024 TKDD Journal Big Data, Data Mining, & Knowledge Discovery 4 Other

  177. [186]

    2024 2024 ICMLC Conference AI & ML 1 General

  178. [187]

    2024 2024 NextGenAISafety Workshop AI & ML 1 General

  179. [188]

    2024 2024 TOPS Journal Cybersecurity 7 Cybersecurity

  180. [189]

    2024 2024 TNSM Journal Computer Networks & Communication 4 Cybersecurity

  181. [190]

    2024 2024 CVIDL Conference AI & ML 1 Cybersecurity

  182. [191]

    2022 2024 DTRAP Journal Cybersecurity 7 Cybersecurity

  183. [192]

    2024 2024 IPSA Conference Others 0 Other

  184. [193]

    Practical dimensions for evaluating adversarial attacks

    2024 2024 arXiv Pre-Print Others 0 General Manuscript submitted to ACM Insights on Adversarial Attacks for Tabular Machine Learning via a Systematic Literature Review 35 B Practical considerations Table 8. Practical dimensions for evaluating adversarial attacks. Dimension Cons...

  185. [2025]

    Accurate predictions on small data with a tabular foundation model.Nature

Pith tools

Reviewed August 15, 2026 · model on record in the stance chip above.