<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>adaptive cybersecurity systems &#8211; Science</title>
	<atom:link href="https://scienmag.com/tag/adaptive-cybersecurity-systems/feed/" rel="self" type="application/rss+xml" />
	<link>https://scienmag.com</link>
	<description></description>
	<lastBuildDate>Sat, 12 Sep 2026 15:53:30 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1.1</generator>

<image>
	<url>https://scienmag.com/wp-content/uploads/2024/07/cropped-scienmag_ico-32x32.jpg</url>
	<title>adaptive cybersecurity systems &#8211; Science</title>
	<link>https://scienmag.com</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">73899611</site>	<item>
		<title>Calibrated Prototypes Help AI Spot New Cyberattacks Without Forgetting Old Ones</title>
		<link>https://scienmag.com/calibrated-prototypes-help-ai-spot-new-cyberattacks-without-forgetting-old-ones/</link>
		
		<dc:creator><![CDATA[Hailey Crawford]]></dc:creator>
		<pubDate>Sat, 12 Sep 2026 15:53:30 +0000</pubDate>
				<category><![CDATA[Technology and Engineering]]></category>
		<category><![CDATA[adaptive cybersecurity systems]]></category>
		<category><![CDATA[catastrophic forgetting]]></category>
		<category><![CDATA[catastrophic forgetting in neural networks]]></category>
		<category><![CDATA[CICIDS2017]]></category>
		<category><![CDATA[continual learning]]></category>
		<category><![CDATA[continuous learning in intrusion detection systems]]></category>
		<category><![CDATA[cyberattack detection]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[few-shot class-incremental learning]]></category>
		<category><![CDATA[few-shot learning for cyber threats]]></category>
		<category><![CDATA[incremental machine learning for cybersecurity]]></category>
		<category><![CDATA[intrusion detection]]></category>
		<category><![CDATA[Machine learning]]></category>
		<category><![CDATA[network security]]></category>
		<category><![CDATA[neural network stability in cybersecurity]]></category>
		<category><![CDATA[neural networks]]></category>
		<category><![CDATA[new methods for detecting evolving cyberattacks]]></category>
		<category><![CDATA[overcoming knowledge loss in AI security models]]></category>
		<category><![CDATA[preserving knowledge in AI-based threat detection]]></category>
		<category><![CDATA[prototype calibration]]></category>
		<category><![CDATA[prototype calibration for intrusion detection]]></category>
		<category><![CDATA[scalable cyberattack classification techniques]]></category>
		<category><![CDATA[semantic similarity]]></category>
		<category><![CDATA[UNSW-NB15]]></category>
		<guid isPermaLink="false">https://scienmag.com/?p=196043</guid>

					<description><![CDATA[Researchers in India have developed BiPC-IFS, a few-shot class-incremental learning framework that lets intrusion detection systems learn new cyberattacks from minimal samples without catastrophically forgetting previous ones.]]></description>
										<content:encoded><![CDATA[<p>Cybersecurity has long suffered from a paradox at the heart of machine learning: the models that defend our networks are often the slowest to adapt to the very threats they are meant to stop. When attackers deploy a new form of intrusion, defenders must retrain their detection systems, and in doing so they frequently erase the knowledge those systems already hold about earlier attacks. Researchers at Malaviya National Institute of Technology Jaipur in India have now unveiled a framework designed to break this cycle. Their approach, called BiPC-IFS, short for Biased Prototype Calibration For Incremental Few Shot Intrusion Detection, allows an intrusion detection system to learn brand-new attack types from only a handful of examples while preserving, rather than overwriting, what it has already learned about older threats.</p>
<p>The work, published in the journal Neural Computing and Applications by Parvati Bhurani, Satyendra Singh Chouhan and Namita Mittal, addresses one of the most stubborn problems in applied machine learning, known formally as catastrophic forgetting. First documented in the late 1980s by psychologists studying connectionist networks, the phenomenon describes what happens when a neural network trained sequentially on multiple tasks loses proficiency on earlier tasks as it absorbs new ones. In the context of network security, this is not an academic curiosity. An intrusion detection system that forgets how to recognize a denial-of-service flood because it has just been taught to spot a novel botnet signature is a system that has become a liability, not a safeguard.</p>
<p>The framework the Indian team proposes falls under an emerging learning paradigm known as few-shot class-incremental learning, or FSCIL. The idea is to structure the learning problem so that a model first learns a broad set of base classes from a fully labeled dataset, and then progressively incorporates novel classes from just a few labeled samples per class, all without revisiting the original training data. This mirrors the operational reality of cybersecurity. Organizations typically possess abundant examples of well-known attacks, but when a new exploit appears in the wild, security teams may have only a few confirmed instances of it before the next wave of probes arrives. A detection model suited to this environment must therefore extract maximum information from minimal new evidence while keeping its existing knowledge intact.</p>
<p>BiPC-IFS achieves this balance through two core components: a fixed feature extractor and a prototype calibration module. The feature extractor is trained only during the base session, on the well-populated set of established attack classes, and is then frozen for the remainder of the system&#8217;s operational life. Although this might seem restrictive, the researchers found that the frozen extractor still captures meaningful similarity relationships between the base classes and the novel classes that arrive later. Because the extractor encodes the geometry of network traffic in a stable feature space, new attack types can be located within that space even when only a handful of examples exist, simply by measuring where their feature representations fall relative to everything the model already knows.</p>
<p>The second component, prototype calibration, is where the approach earns its distinctive name. In prototype-based classification, each class is represented by a single representative vector, or prototype, typically computed as the mean of the feature vectors of its training samples. With only a few samples, these novel-class prototypes are biased, pulled away from their true class centers by sampling noise and by the tendency of a model trained on base classes to interpret everything through the lens of what it already knows. Calibration corrects this bias by adjusting the prototypes before classification. The crucial design question, the authors note, is determining how much to adjust: a calibration factor that is too high can distort the original representation of the novel class, effectively overcorrecting and making the system worse than it would have been with no calibration at all.</p>
<p>What sets BiPC-IFS apart from earlier calibration techniques is the way it computes that correction. Rather than relying solely on distances in feature space, the proposed calibrated class prototype aggregates both feature-based similarity and semantic similarity among different classes. In practical terms, this means the system considers not only how close a novel attack&#8217;s samples sit to the prototypes of known attacks in the learned feature space, but also how conceptually related the classes are. Two attack types that share characteristics, for example variants of the same malware family, can inform each other&#8217;s prototypes in a way that purely geometric calibration cannot achieve. This dual-source aggregation allows the model to draw richer inferences from the sparse evidence available in each incremental session, producing prototypes that better represent the true structure of the new classes.</p>
<p>To test whether these design choices translate into real-world performance, the researchers evaluated BiPC-IFS on two of the most widely used benchmark datasets in intrusion detection research: UNSW-NB15 and CICIDS2017. The UNSW-NB15 dataset, created at the Australian Centre for Cyber Security, combines real normal traffic with nine categories of synthesized modern attacks, including backdoors, exploits, and reconnaissance activity. CICIDS2017, produced by the Canadian Institute for Cybersecurity, captures several days of benign and attack traffic covering brute-force assaults, heartbleed exploits, botnets, denial-of-service attacks, web attacks, and infiltration attempts. Together, these benchmarks provide a demanding testbed, with realistic class distributions and attack behaviors that differ substantially across categories, exactly the conditions under which incremental learning systems tend to falter.</p>
<p>The results were striking. BiPC-IFS surpassed the baseline methods it was compared against and achieved the strongest performance metrics for novel classes across both datasets. The system recorded an average accuracy of 94.91 percent across all incremental sessions, a novel class accuracy of 74.25 percent, and a performance drop, measured as the decline in accuracy over the course of learning new classes, of just 8.67 percent. That final figure is the one that matters most to security practitioners, because it quantifies how much the system forgets as it learns. A small drop means that the model&#8217;s knowledge of old attacks remains largely intact even as it absorbs new ones, which is precisely the property that conventional retraining pipelines fail to deliver.</p>
<p>The implications extend well beyond one laboratory result. Networks today face an adversary that evolves continuously, probing for unpatched vulnerabilities and mutating attack tooling faster than human analysts can label large datasets. Systems like BiPC-IFS point toward a generation of defenses that can be updated on the fly, in operational settings, without the downtime and cost of full retraining and without the silent erosion of previously learned protections. Because the feature extractor remains frozen, the computational cost of incorporating a new attack class is minimal, and the approach avoids the need to store sensitive raw traffic data from past sessions. The researchers also note that the datasets used in the study are publicly available, which should make it straightforward for other teams to reproduce the results and build on them.</p>
<p>There remain, of course, open questions. The frozen feature extractor, though shown to capture useful base-novel similarity, was never trained to see the novel classes, and future work may explore how well this holds as threat landscapes diverge further from historical attack patterns. The authors&#8217; own framing acknowledges the delicate trade-off at the center of the method: the calibration factor must be chosen carefully, since too aggressive a correction distorts the very representations it is meant to refine. Even so, the demonstration that biased prototype calibration, informed jointly by feature and semantic similarity, can push novel-class detection to over 74 percent accuracy from just a few examples marks a meaningful advance. As artificial intelligence becomes the front line of network defense, techniques that let models learn like analysts do, quickly, from limited evidence, and without forgetting hard-won lessons, may prove indispensable.</p>
<p><strong>Subject of Research:</strong> A biased prototype calibration framework for incremental few-shot learning in network intrusion detection systems.</p>
<p><strong>Article Title:</strong> BiPC-IFS: Biased Prototype Calibration For Incremental Few Shot Intrusion Detection</p>
<p><strong>Article References:</strong> Bhurani, P., Chouhan, S. S., &amp; Mittal, N. (2026). BiPC-IFS: Biased Prototype Calibration For Incremental Few Shot Intrusion Detection. <em>Neural Computing and Applications, 38</em>(17), Article 736. <a href="https://doi.org/10.1007/s00521-026-12455-8" rel="noopener noreferrer">https://doi.org/10.1007/s00521-026-12455-8</a></p>
<p><strong>Image Credits:</strong> AI Generated</p>
<p><strong>DOI:</strong> <a href="https://doi.org/10.1007/s00521-026-12455-8" rel="noopener noreferrer">10.1007/s00521-026-12455-8</a></p>
<p><strong>Keywords:</strong> intrusion detection, few-shot class-incremental learning, catastrophic forgetting, prototype calibration, machine learning, cybersecurity, network security, semantic similarity, UNSW-NB15, CICIDS2017, neural networks, continual learning</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">196043</post-id>	</item>
		<item>
		<title>Federated Learning and AI-Driven Zero-Trust Architecture for Cybersecurity: An In-Depth Review</title>
		<link>https://scienmag.com/federated-learning-and-ai-driven-zero-trust-architecture-for-cybersecurity-an-in-depth-review/</link>
		
		<dc:creator><![CDATA[Veronica Carney]]></dc:creator>
		<pubDate>Wed, 26 Aug 2026 21:24:25 +0000</pubDate>
				<category><![CDATA[Technology and Engineering]]></category>
		<category><![CDATA[adaptive cybersecurity systems]]></category>
		<category><![CDATA[AI-based threat response]]></category>
		<category><![CDATA[AI-driven zero-trust architecture]]></category>
		<category><![CDATA[continuous access privilege reassessment]]></category>
		<category><![CDATA[cybersecurity for enterprise networks]]></category>
		<category><![CDATA[detection of fileless malware]]></category>
		<category><![CDATA[federated learning in cybersecurity]]></category>
		<category><![CDATA[next-generation cybersecurity technologies]]></category>
		<category><![CDATA[protecting critical infrastructure]]></category>
		<category><![CDATA[protection of sensitive data using AI]]></category>
		<category><![CDATA[securing internet-connected devices]]></category>
		<category><![CDATA[threat detection in cloud services]]></category>
		<category><![CDATA[zero-trust security models]]></category>
		<guid isPermaLink="false">https://scienmag.com/federated-learning-and-ai-driven-zero-trust-architecture-for-cybersecurity-an-in-depth-review/</guid>

					<description><![CDATA[A new review argues that the next generation of cybersecurity could emerge from combining three technologies that are usually deployed separately: federated learning, artificial intelligence and zero-trust architecture. The proposed combination is designed to help organizations detect threats, protect sensitive data, continuously reassess access privileges and identify fileless malware—malicious software that can operate without leaving [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>A new review argues that the next generation of cybersecurity could emerge from combining three technologies that are usually deployed separately: federated learning, artificial intelligence and zero-trust architecture. The proposed combination is designed to help organizations detect threats, protect sensitive data, continuously reassess access privileges and identify fileless malware—malicious software that can operate without leaving a conventional executable on a hard drive. Writing in the <em>International Journal of Data Science and Analytics</em>, Md. Mushfiqur Rahman and Sazzad Hossain of Samarkand State University describe how these systems could form a continuously adapting defense for cloud services, enterprise networks, internet-connected devices and critical infrastructure.</p>
<p>The appeal of the approach lies in the changing nature of cyberattacks. Traditional security systems often rely on known signatures, fixed rules or a perimeter separating a supposedly safe internal network from an untrusted outside world. That model becomes fragile when employees work remotely, applications run across multiple clouds and billions of devices exchange data. Attackers can also exploit stolen credentials, compromised endpoints or trusted connections that remain active long after a user’s behavior has changed. Zero-trust architecture, commonly summarized as “never trust, always verify,” responds by treating every access request as potentially risky. Rather than granting broad, permanent privileges, it evaluates identity, device condition, location, behavior and the sensitivity of the requested resource.</p>
<p>Artificial intelligence could make those evaluations faster and more dynamic. Machine-learning models can analyze network flows, login patterns, system calls, file access, process activity and other telemetry to identify behavior that differs from an established baseline. In a zero-trust environment, an anomaly might trigger stronger authentication, reduce a user’s permissions, isolate a device or block a connection. The technical challenge is that the most useful evidence is distributed across many organizations and devices. A hospital may observe one kind of attack, a bank another and an industrial facility a third. Sharing raw logs could expose personal information, trade secrets or security weaknesses, but keeping them isolated limits the data available for training robust detection models.</p>
<p>Federated learning is intended to solve part of that problem by moving the model rather than the data. In a typical federated-learning process, participating devices or organizations train a local copy of a machine-learning model using their own telemetry. They then send model updates—such as changes to neural-network weights—to a coordinating service, which aggregates the updates into a new global model. The raw data remains at its original location. The updated model can subsequently be distributed back to participants, allowing systems in different environments to learn from one another without creating a central warehouse of sensitive logs. This arrangement can support near-real-time threat intelligence while reducing some privacy risks associated with conventional centralized training.</p>
<p>Keeping data local, however, does not make federated learning automatically secure. Model updates can leak information, especially when an attacker analyzes repeated contributions or deliberately manipulates the training process. A compromised participant might send poisoned updates designed to make malware appear benign, while a malicious coordinator could attempt to reconstruct characteristics of local data. The review therefore places federated learning inside a broader security framework involving secure communication, participant authentication, anomaly checks on updates and, where appropriate, privacy-enhancing methods such as differential privacy or secure aggregation. Secure aggregation allows a coordinator to combine contributions without directly inspecting each individual update, although these protections can add computational overhead and may reduce model accuracy.</p>
<p>The proposed integration also extends to identity and access management, or IAM. IAM systems determine who can access which resources, under what conditions and for how long. AI-based IAM could use behavioral signals to supplement passwords, tokens and multifactor authentication. For example, an access request from a familiar account might still be treated as suspicious if it arrives from an unusual device, at an abnormal time, with an unfamiliar sequence of commands or alongside a sudden attempt to retrieve large quantities of data. Federated models could learn these patterns across distributed environments, while zero-trust controls could convert the resulting risk assessment into an immediate decision. In principle, this would allow access permissions to change continuously rather than remaining fixed until an administrator reviews them.</p>
<p>One of the most difficult targets described in the review is fileless malware. Unlike conventional malware, which may install a recognizable program on disk, fileless attacks can use legitimate tools already present on a system. Malicious instructions may be injected into memory, delivered through scripts, hidden in registry entries or executed through administrative utilities such as PowerShell. Because there may be little or no malicious file to scan, signature-based antivirus software can miss the attack. Detection instead requires behavioral analysis: monitoring parent-child process relationships, command sequences, memory activity, script execution, privilege changes, network connections and other events that, taken together, suggest abuse of a trusted tool.</p>
<p>Machine-learning systems can search this high-dimensional stream of endpoint and network telemetry for combinations of events associated with compromise. Supervised models learn from labeled examples of benign and malicious activity, whereas unsupervised or semi-supervised models identify unusual patterns when labeled attacks are scarce. Deep-learning systems can capture complex relationships across sequences of events, but they may be difficult to interpret and vulnerable to changes in the operating environment. A zero-trust response could limit the suspicious process, revoke a token, require fresh authentication or quarantine the endpoint while an incident-response team investigates. The review emphasizes that automated prevention must be carefully governed: an incorrect decision could interrupt a hospital system, halt an industrial process or lock out legitimate users.</p>
<p>The authors frame telemetry as the connective tissue linking detection and enforcement. Telemetry includes the continuously generated records of what devices, users, applications and services are doing. In a distributed architecture, these signals may be produced at endpoints, gateways, cloud workloads, containers and edge devices. AI can transform them into risk scores, while federated learning can help models improve across organizational boundaries without routinely exporting the underlying records. Zero-trust policy engines can then use the scores to make granular decisions about access. Such a system could be particularly valuable in industrial internet-of-things networks, healthcare platforms, financial services and other settings where systems are geographically distributed and the consequences of delayed detection are high.</p>
<p>The review is not a report of a completed deployment or a benchmark showing that the combined approach outperforms existing security products. No datasets were generated or analyzed, and the paper instead synthesizes prior research, compares the roles of AI, federated learning, zero trust and IAM, and identifies unresolved obstacles. These include communication costs between participants, inconsistent data quality, model drift as attacks evolve, false alarms, limited computing power on edge devices and the difficulty of explaining automated access decisions. Attackers may also target the learning process itself through poisoning, evasion or adversarial examples. Future systems will need stronger defenses against these attacks, standardized evaluation datasets, transparent policies, human oversight and tests in realistic operational environments. The central message is that privacy-preserving collaboration could make AI-driven zero trust more responsive, but the combination should be treated as a security research direction—not yet as a universal cure for cybercrime.</p>
<p><strong>Subject of Research:</strong> Integration of federated learning and AI-based zero-trust architecture for cybersecurity, privacy, telemetry, identity and access management, and fileless-malware detection and prevention</p>
<p><strong>Article Title:</strong> Federated learning and AI-based ZTA for security, privacy, telemetry, IAM and fileless malware detection and prevention framework: an in-depth review</p>
<p><strong>Article References:</strong> Rahman, M.M., Hossain, S. “Federated learning and AI-based ZTA for security, privacy, telemetry, IAM and fileless malware detection and prevention framework: an in-depth review.” <i>International Journal of Data Science and Analytics</i> 22, 283 (2026). <a href="https://link.springer.com/article/10.1007/s41060-026-01254-y">Original research page</a></p>
<p><strong>Image Credits:</strong> AI Generated</p>
<p><strong>DOI:</strong> 10.1007/s41060-026-01254-y</p>
<p><strong>Keywords:</strong> federated learning, zero-trust architecture, artificial intelligence, identity and access management, fileless malware, cybersecurity, privacy-preserving machine learning, network telemetry</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">182501</post-id>	</item>
	</channel>
</rss>
