Score
Designs, builds, and evaluates detection systems and analyses that identify unintended leakage of information or material — covering both information-flow leaks in datasets and models and physical leaks such as coolant — by selecting sensors/features, constructing anomaly or pattern-difference detectors, defining thresholds and alerting rules, localizing leak sources, and measuring detection performance and robustness (sensitivity, specificity, false positive control) to support mitigation.
Naval systems frequently exhibit anomalous behaviors due to wear, misuse, or component failures—challenges that hinder timely detection and precise remediation. To address this, we propose a predictive-diagnostic closed-loop framework that tightly integrates the existing failure prediction system PREVENT with a newly designed responsive troubleshooting module, REACT. Methodologically, the framework synergizes multi-source time-series anomaly detection with domain-knowledge-driven fault-isolation process modeling, enabling end-to-end automation—from anomaly alerting and root-cause localization to actionable remediation recommendations. Evaluated on operational shipboard systems deployed by Fincantieri, the framework reduces mean time to fault localization by 42%, significantly improves operational response efficiency, and demonstrates strong generalizability across diverse industrial domains.
This study investigates the robustness of artificial intelligence in two critical security tasks: network intrusion detection and identification of side-channel information leakage in cryptographic implementations. To address performance degradation under distribution shifts and unknown traffic scenarios, we systematically evaluate multiple machine learning approaches on the NSL-KDD and CIC-IDS datasets. Our results demonstrate that models achieve near-perfect detection accuracy in stable environments but suffer significant performance drops under distributional shifts. Furthermore, AI methods effectively identify feature patterns consistent with side-channel leakage, confirming their potential for security analysis of cryptographic implementations. This work provides an empirical foundation and methodological insights for enhancing the generalization capabilities of AI-driven security systems.
This study addresses the reliability risks in automotive perception systems arising from unintended data leakage between training and evaluation datasets, revealing for the first time from an industrial practice perspective that such leakage is fundamentally a socio-technical coordination challenge across roles. Through semi-structured interviews with ten automotive perception engineers and reflexive thematic analysis, the research finds that industry awareness of data leakage remains fragmented across roles, with mitigation strategies largely relying on tacit knowledge transfer rather than systematic tooling. The work proposes establishing a unified definition of data leakage, implementing traceable data pipelines, and fostering continuous cross-functional communication to enhance the reliability engineering of automotive machine learning systems.
In industrial quality inspection, anomaly detection suffers from poor robustness due to high noise levels and sparse defective samples. To address this, we propose Iterative Refinement of Pseudo-labels (IRP), a self-supervised method that alternately evaluates sample credibility and removes misleading instances under feature-space consistency constraints—effectively purifying the training set dynamically without human annotations and generating high-fidelity self-supervised signals. IRP introduces the novel paradigm of “iterative data refinement,” significantly enhancing model robustness against label noise and cross-domain generalization capability. Evaluated on KSDD2 and MVTec AD benchmarks, IRP consistently outperforms existing unsupervised and self-supervised methods. Notably, under high-noise conditions, it achieves substantial improvements in detection accuracy and reduces false positive rates by over 25%.
This work addresses the confounding of physical process modeling capability and alarm thresholding effects in existing evaluations of cyber-physical system (CPS) anomaly detectors, which obscures the attribution of performance differences. To resolve this, the authors decouple detection into two stages—residual generation and threshold-based alarming—and propose a normalized residual energy–based evaluation metric. This metric independently quantifies a model’s ability to represent the underlying physical process without relying on specific decision rules or hyperparameter tuning. Furthermore, it connects to KL divergence to measure attack separability, training–testing stability, and model compactness. Evaluations across five detector families on the SWaT, WADI, and HAI benchmarks reveal that performance rankings are highly scenario-dependent and precisely identify failure causes—such as inadequate representation capacity, suboptimal thresholds, or weak physical manifestations of attacks.
This study addresses the challenge of detecting information leakage solely from a model’s predictive outputs, without access to training code, external data, or domain knowledge. Framed within decision theory, the approach models leakage diagnosis as a functional of predictive risk and outcome distribution, linking proper scoring rules with decision curve analysis via threshold-weighted associations to enable detection without prior assumptions. The work introduces a novel tripartite classification of information leakage—miscalibration, generalized calibration, and determinism—and theoretically establishes that generalized calibration leakage is fundamentally unidentifiable, whereas near-deterministic subgroups can be efficiently detected. Empirical validation on UK Biobank demonstrates detection of temporal-window comorbidity leakage down to Δc*≈0.007 in under one second, while also revealing inherent structural limitations of purely output-driven leakage detection.
This work addresses the performance gap between academic benchmarks and real-world deployment in unsupervised anomaly detection, where existing methods often exhibit instability, sensitivity to preprocessing, and inconsistent behavior in industrial settings. The authors conduct a systematic evaluation of 19 models on BowTie, a complex manufacturing dataset, revealing significant discrepancies between benchmark results and practical efficacy. To bridge this gap, they propose a human-in-the-loop unified detection framework that integrates SAM-generated refined candidate regions, heatmap-guided inspection, mask-based evaluation, and interactive verification. This framework enables quality inspectors to efficiently confirm defects, refine boundaries, and trace historical cases. Preliminary deployment demonstrates that the system substantially enhances both reliability and efficiency in industrial visual inspection.
This study addresses the inefficiency and error-proneness of manually translating threats identified by Breach and Attack Simulation (BAS) into SIEM detection rules. To overcome this limitation, the authors propose a deterministic synthesis method that automatically maps BAS outputs to Sigma rules using a fixed corpus of probes, while preserving a complete, typed provenance chain from alerts back to their original probes. The approach leverages only 23 templates categorized according to the OWASP LLM/Web Top 10 and annotated with MITRE ATT&CK identifiers to generate byte-level stable, verifiable Sigma rules compatible with both Splunk and Elasticsearch. Evaluated on LLM and web probe corpora, the method successfully produced valid rules for all probes; on subsets of AdvBench and HarmBench, these LLM-focused rules triggered detections for 30% and 14% of attacks, respectively, with a false positive rate of 7.7%.
This study addresses the limitations of manual hydrogen leak detection, which suffers from unstandardized probe trajectories, operator dependency, and sensor signal latency, resulting in low detection rates and significant safety risks. The authors develop a robot-guided gas sensing testbed integrating standardized leak sources (5% H₂/N₂), 3D geometric modeling, and dynamic concentration field measurements to systematically investigate the impact of scanning speed and probe orientation on detection performance in near-field environments. They reveal, for the first time, the critical role of trajectory dynamics in detecting small-scale pipeline leaks and propose a geometry-adapted scanning strategy alongside a dynamic signal attenuation correction model. Experiments demonstrate that geometry-specific trajectories encircling seal points substantially enhance detection reliability compared to conventional linear paths. A prototype software tool capable of automatically generating and validating 3D inspection trajectories is also developed, establishing a new paradigm for safe and effective hydrogen leak detection.