Yisroel Mirsky

dblp:160/6851 · also Yisroel Mirski · DBLP profile ↗
← Back
35ranked-venue papers
13as first author
18since 2021 · last 2026
0000-0001-6367-2734ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 22 · 8 first-author · 13 since 2021Databases, data management, data science and information retrieval · 7 · 1 first-author · 4 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-authorSystems, architecture and hardware · 1 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 FLux: Covert Channels in FL through Transposed Training
abstract
Federated learning (FL) routinely exchanges model-derived signals (e.g., logits or updates) between clients and a server, creating an attractive substrate for covert communication — especially in settings where adversaries cannot rely on direct, out-of-band coordination. Existing FL covert channels often trade off capacity, reliability under aggregation, setup requirements, or operational stealth (e.g., needing extensive pre-shared state, warm-up rounds, or leaving persistent artifacts).
Alexandra Dmitrienko, Torsten Krauß, Yisroel Mirsky
AsiaCCS3
2026 Trust Me, I Know This Function: Hijacking LLM Static Analysis using Bias
Shir Bernstein, David Beste, Daniel Ayzenshteyn, Lea Schönherr, Yisroel Mirsky
NDSS5
2026 Memory Backdoor Attacks on Neural Networks
Eden Luzon, Guy Amit, Roy Weiss, Torsten Krauß, Alexandra Dmitrienko, Yisroel Mirsky
NDSS6
2025 ProxyPrints: From Database Breach to Spoof, A Plug-and-Play Defense for Biometric Systems
abstract
Fingerprint recognition systems are widely deployed for authentication and forensic applications, but the security of stored fingerprint data remains a critical vulnerability. While many systems avoid storing raw fingerprint images in favor of minutiae-based templates, recent research shows that these templates can be reverse-engineered to reconstruct realistic fingerprint images, enabling physical spoofing attacks that compromise user identities with no means of remediation. We present ProxyPrints, the first practical defense that brings cancellable biometrics to existing fingerprint recognition systems without requiring modifications to proprietary matching software. ProxyPrints acts as a transparent middleware layer between the fingerprint scanner and the matching algorithm, transforming each scanned fingerprint into a consistent, unlinkable alias. This transformation allows biometric identities to be revoked and replaced in the event of a breach, without affecting authentication accuracy. Additionally, ProxyPrints provides organizations with breach detection capabilities by enabling the identification of out-of-band spoofing attempts involving compromised aliases. We evaluate ProxyPrints on standard benchmark datasets and commercial fingerprint recognition systems, demonstrating that it preserves matching performance while offering strong security and revocability. Our open-source implementation includes tools for alias generation and deployment in real-world pipelines, making ProxyPrints a drop-in, scalable solution for fingerprint data protection.
Yaniv Hacmon, Keren Gorelik, Gilad Gressel, Yisroel Mirsky
ACSAC4
2025 Cloak, Honey, Trap: Proactive Defenses Against LLM Agents
Daniel Ayzenshteyn, Roy Weiss, Yisroel Mirsky
USENIX Security Symposium3
2025 PEAS: A Strategy for Crafting Transferable Adversarial Examples
abstract
Black box attacks, where adversaries have limited knowledge of the target model, pose a significant threat to machine learning systems. Adversarial examples generated with a substitute model often suffer from limited transferability to the target model. While recent work explores ranking perturbations for improved success rates, these methods see only modest gains. We propose a novel strategy called PEAS that can boost the transferability of existing black box attacks. PEAS leverages the insight that samples which are perceptually equivalent exhibit significant variability in their adversarial transferability. Our approach first generates a set of images from an initial sample via subtle augmentations. We then evaluate the transferability of adversarial perturbations on these images using a set of substitute models. Finally, the most transferable adversarial example is selected and used for the attack. Our experiments show that PEAS can double the performance of existing attacks, achieving a 2.5× improvement in attack success rates on average over current ranking methods. We thoroughly evaluate PEAS on ImageNet and CIFAR-10, analyze hyperparameter impacts, and provide an ablation study to isolate each component’s importance. Beyond performance, PEAS also introduces a novel perceptual equivalence-based search space that challenges the common \(\epsilon\) -ball constraint used in adversarial machine learning, and reveals that natural augmentations alone can induce adversarial failures.
Bar Avraham, Yisroel Mirsky
ACM Trans. Intell. Syst. Technol.2
2025 Counter-Samples: A Stateless Strategy to Neutralize Black-Box Adversarial Attacks
abstract
Our article introduces a novel defense mechanism against black-box attacks, where attackers exploit the victim model as an oracle to craft adversarial examples. Unlike traditional pre-processing defenses that rely on sanitizing input samples, our stateless strategy directly counters the attack process itself. For each query, we evaluate a counter-sample, an optimized version of the original sample, designed to thwart the attacker’s objective. By responding to every black-box query with a targeted white-box optimization, our strategy introduces a strategic asymmetry that significantly advantages the defender. Our approach proves to be highly effective against state-of-the-art black-box attacks, outperforming existing defenses on both CIFAR-10 and ImageNet datasets. Specifically, our method achieves an average Attack Failure Rate (AFR) of 74.7% (up from 13%) on ImageNet and 67.7% (up from 3.5%) on CIFAR-10 when tested against 10 state-of-the-art query-based black-box attacks. Moreover, it maintains the model’s performance on legitimate inputs, with accuracy (ACC) reduced by only 0.7% on ImageNet and 0.9% on CIFAR-10. This is in stark contrast to other defenses tested, which can cause accuracy drops of up to 50%. Such a modest decrease ensures negligible performance degradation on legitimate tasks. Furthermore, we demonstrate that our defense exhibits superior robustness across datasets and attack scenarios, including adaptive attacks specifically designed to try to bypass our method. This robustness highlights the strength and adaptability of our approach in countering adversarial threats.
Roey Bokobza, Yisroel Mirsky
ACM Trans. Intell. Syst. Technol.2
2025 Back-in-Time Diffusion: Unsupervised Detection of Medical Deepfakes
abstract
Recent progress in generative models has made it easier for a wide audience to edit and create image content, raising concerns about the proliferation of deepfakes, especially in healthcare. Despite the availability of numerous techniques for detecting manipulated images captured by conventional cameras, their applicability to medical images is limited. This limitation stems from the distinctive forensic characteristics of medical images, a result of their imaging process. In this work, we propose a novel anomaly detector for medical imagery based on diffusion models. Normally, diffusion models are used to generate images. However, we show how a similar process can be used to detect synthetic content by making a model reverse the diffusion on a suspected image. We evaluate our method on the task of detecting fake tumors injected and removed from CT and MRI scans. Our method significantly outperforms other state-of-the-art unsupervised detectors with an increased AUC of 0.9 from 0.79 for injection and of 0.96 from 0.91 for removal on average. We also explore our hypothesis using AI explainability tools and publish both our code and new medical deepfake datasets to encourage further research into this domain.
Fred Matanel Grabovski, Lior Yasur, Guy Amit, Yisroel Mirsky
ACM Trans. Intell. Syst. Technol.4
2024 TTTS: Tree Test Time Simulation for Enhancing Decision Tree Robustness against Adversarial Examples
abstract
Decision trees are widely used for addressing learning tasks involving tabular data. Yet, they are susceptible to adversarial attacks. In this paper, we present Tree Test Time Simulation (TTTS), a novel inference-time methodology that incorporates Monte Carlo simulations into decision trees to enhance their robustness. TTTS introduces a probabilistic modification to the decision path, without altering the underlying tree structure. Our comprehensive empirical analysis of 50 datasets yields promising results. Without the presence of any attacks, TTTS has successfully improved model performance from an AUC of 0.714 to 0.773. Under the challenging conditions of white-box attacks, TTTS demonstrated its robustness by boosting performance from an AUC of 0.337 to 0.680. Even when subjected to black-box attacks, TTTS maintains high accuracy and enhances the model's performance from an AUC of 0.628 to 0.719. Compared to defenses such as Feature Squeezing, TTTS proves to be much more effective. We also found that TTTS exhibits similar robustness in decision forest settings across different attacks.
Seffi Cohen, Ofir Arbili, Yisroel Mirsky, Lior Rokach
AAAI3
2024 Transpose Attack: Stealing Datasets with Bidirectional Training
Guy Amit, Moshe Levy, Yisroel Mirsky
NDSS3
2024 What Was Your Prompt? A Remote Keylogging Attack on AI Assistants
Roy Weiss, Daniel Ayzenshteyn, Guy Amit, Yisroel Mirsky
USENIX Security Symposium4
2024 Ranking the Transferability of Adversarial Examples
abstract
Adversarial transferability in blackbox scenarios presents a unique challenge: while attackers can employ surrogate models to craft adversarial examples, they lack assurance on whether these examples will successfully compromise the target model. Until now, the prevalent method to ascertain success has been trial and error—testing crafted samples directly on the victim model. This approach, however, risks detection with every attempt, forcing attackers to either perfect their first try or face exposure. Our article introduces a ranking strategy that refines the transfer attack process, enabling the attacker to estimate the likelihood of success without repeated trials on the victim’s system. By leveraging a set of diverse surrogate models, our method can predict transferability of adversarial examples. This strategy can be used to either select the best sample to use in an attack or the best perturbation to apply to a specific sample. Using our strategy, we were able to raise the transferability of adversarial examples from a mere 20%—akin to random selection—up to near upper-bound levels, with some scenarios even witnessing a 100% success rate. This substantial improvement not only sheds light on the shared susceptibilities across diverse architectures but also demonstrates that attackers can forego the detectable trial-and-error tactics raising increasing the threat of surrogate-based attacks.
Moshe Levy, Guy Amit, Yuval Elovici, Yisroel Mirsky
ACM Trans. Intell. Syst. Technol.4
2023 Deepfake CAPTCHA: A Method for Preventing Fake Calls
abstract
Deep learning technology has made it possible to generate realistic content of specific individuals. These ‘deepfakes’ can now be generated in real-time which enables attackers to impersonate people over audio and video calls. Moreover, some methods only need a few images or seconds of audio to steal an identity. Existing defenses perform passive analysis to detect fake content. However, with the rapid progress of deepfake quality, this may be a losing game.
Lior Yasur, Guy Frankovits, Fred Matanel Grabovski, Yisroel Mirsky
AsiaCCS4
2023 VulChecker: Graph-based Vulnerability Localization in Source Code
Yisroel Mirsky, George Macon, Michael D. Brown, Carter Yagemann, Matthew Pruett, Evan Downing, J. Sukarno Mertoguno, Wenke Lee
USENIX Security Symposium1
2023 The Threat of Offensive AI to Organizations
abstract
AI has provided us with the ability to automate tasks, extract information from vast amounts of data, and synthesize media that is nearly indistinguishable from the real thing. However, positive tools can also be used for negative purposes. In particular, cyber adversaries can use AI to enhance their attacks and expand their campaigns. Although offensive AI has been discussed in the past, there is a need to analyze and understand the threat in the context of organizations. For example, how does an AI-capable adversary impact the cyber kill chain? Does AI benefit the attacker more than the defender? What are the most significant AI threats facing organizations today and what will be their impact on the future? In this study, we explore the threat of offensive AI on organizations. First, we present the background and discuss how AI changes the adversary’s methods, strategies, goals, and overall attack model. Then, through a literature review, we identify 32 offensive AI capabilities which adversaries can use to enhance their attacks. Finally, through a panel survey spanning industry, government and academia, we rank the AI threats and provide insights on the adversaries.
Yisroel Mirsky, Ambra Demontis, Jaidip Kotak, Ram Shankar, Gelei Deng, Liu Yang 0003, Maura Pintor, Wenke Lee, Yuval Elovici, Battista Biggio
Comput. Secur.1
2023 IPatch: a remote adversarial patch
abstract
Abstract Applications such as autonomous vehicles and medical screening use deep learning models to localize and identify hundreds of objects in a single frame. In the past, it has been shown how an attacker can fool these models by placing an adversarial patch within a scene. However, these patches must be placed in the target location and do not explicitly alter the semantics elsewhere in the image. In this paper, we introduce a new type of adversarial patch which alters a model’s perception of an image’s semantics. These patches can be placed anywhere within an image to change the classification or semantics of locations far from the patch. We call this new class of adversarial examples ‘remote adversarial patches’ (RAP). We implement our own RAP called IPatch and perform an in-depth analysis on without pixel clipping on image segmentation RAP attacks using five state-of-the-art architectures with eight different encoders on the CamVid street view dataset. Moreover, we demonstrate that the attack can be extended to object recognition models with preliminary results on the popular YOLOv3 model. We found that the patch can change the classification of a remote target region with a success rate of up to 93% on average.
Yisroel Mirsky
Cybersecur.1
2021 DeepReflect: Discovering Malicious Functionality through Binary Reconstruction
Evan Downing, Yisroel Mirsky, Kyuhong Park, Wenke Lee
USENIX Security Symposium2
2021 DDoS Attacks on 9-1-1 Emergency Services
abstract
The 911 emergency service belongs to one of the 16 critical infrastructure sectors in the United States. Distributed denial of service (DDoS) attacks launched from a mobile phone botnet pose a significant threat to the availability of this vital service. In this article we show how attackers can launch several types of DDoS attacks from mobile phone botnets. In one of the attacks, which we demonstrate, the attacker has the botnet randomize all cellular identifiers while issuing emergency calls repeatedly. Since there exists legitimate unidentified emergency calls, and since the FCC requires such calls to be forwarded, the network and the emergency call centers cannot block these calls (technically and legally). To understand and verify the threat of DDoS attacks on 911, we explore the 911 infrastructure and implement different forms of the attack on a small cellular network. Finally, to quantify the threat, we simulate and analyze DDoS attacks on a model of current 911 infrastructure in the US. We found that with less than 6K bots (or $100K hardware), attackers can block emergency services in an entire state for days. We believe that this article will assist the respective organizations in preventing possible 911-DDoS attacks in the future.
Yisroel Mirsky, Mordechai Guri
IEEE Trans. Dependable Secur. Comput.1
2020 Phantom of the ADAS: Securing Advanced Driver-Assistance Systems from Split-Second Phantom Attacks
abstract
In this paper, we investigate "split-second phantom attacks," a scientific gap that causes two commercial advanced driver-assistance systems (ADASs), Telsa Model X (HW 2.5 and HW 3) and Mobileye 630, to treat a depthless object that appears for a few milliseconds as a real obstacle/object. We discuss the challenge that split-second phantom attacks create for ADASs. We demonstrate how attackers can apply split-second phantom attacks remotely by embedding phantom road signs into an advertisement presented on a digital billboard which causes Tesla's autopilot to suddenly stop the car in the middle of a road and Mobileye 630 to issue false notifications. We also demonstrate how attackers can use a projector in order to cause Tesla's autopilot to apply the brakes in response to a phantom of a pedestrian that was projected on the road and Mobileye 630 to issue false notifications in response to a projected road sign. To counter this threat, we propose a countermeasure which can determine whether a detected object is a phantom or real using just the camera sensor. The countermeasure (GhostBusters) uses a "committee of experts" approach and combines the results obtained from four lightweight deep convolutional neural networks that assess the authenticity of an object based on the object's light, context, surface, and depth. We demonstrate our countermeasure's effectiveness (it obtains a TPR of 0.994 with an FPR of zero) and test its robustness to adversarial machine learning attacks.
Ben Nassi, Yisroel Mirsky, Dudi Nassi, Raz Ben-Netanel, Oleg Drokin, Yuval Elovici
CCS2
2020 Helix: DGA Domain Embeddings for Tracking and Exploring Botnets
abstract
Botnets have been using domain generation algorithms (DGA) for over a decade to covertly and robustly identify the domain name of their command and control servers (C&C). Recent advancements in DGA detection has motivated botnet owners to rapidly alter the C&C domain and use adversarial techniques to evade detection. As a result, it has become increasingly difficult to track botnets in DNS traffic. In this paper, we present Helix, a method for tracking and exploring botnets. Helix uses a spatio-temporal deep neural network autoencoder to convert domains into numerical vectors (embeddings) which capture the DGA and seed used to create the domain. This is made possible by leveraging both convolutional (spatial) and recurrent (temporal) layers, and by using techniques such as attention mechanisms and highways. Furthermore, by using an autoencoder architecture, the network can be trained in an unsupervised manner (no labeling of data) which makes the system practical for real world deployments. In our evaluation, we found that Helix can track botnet campaigns, distinguish between DGA families and seeds, and can identify domains generated using the latest adversarial machine learning techniques. Helix is currently being used to track botnets in one of the world's largest Internet Service Providers (ISP), and we include some of the ISP's analysis work using our method.
Lior Sidi, Yisroel Mirsky, Asaf Nadler, Yuval Elovici, Asaf Shabtai
CIKM2
2020 DANTE: A Framework for Mining and Monitoring Darknet Traffic
Dvir Cohen, Yisroel Mirsky, Manuel Kamp, Yuval Elovici, Rami Puzis, Asaf Shabtai
ESORICS (1)2
2020 An Encryption System for Securing Physical Signals
Yisroel Mirsky, Benjamin Fedidat, Yoram Haddad 0001
SecureComm (1)1
2020 Lightweight collaborative anomaly detection for the IoT using blockchain
Yisroel Mirsky, Tomer Golomb, Yuval Elovici
J. Parallel Distributed Comput.1
2019 CT-GAN: Malicious Tampering of 3D Medical Imagery using Deep Learning
Yisroel Mirsky, Tom Mahler, Ilan Shelef, Yuval Elovici
USENIX Security Symposium1
2019 Vesper: Using Echo Analysis to Detect Man-in-the-Middle Attacks in LANs
abstract
The man-in-the-middle (MitM) attack is a cyber attack in which an attacker intercepts traffic, thus harming the confidentiality, integrity, and availability of the network. It remains a popular attack vector due to its simplicity. However, existing solutions are either not portable, suffer from a high false positive rate, or simply not generic. In this paper, we propose Vesper: a novel plug-and-play MitM detector for local area networks. Vesper uses a technique inspired from impulse response analysis used in the domain of acoustic signal processing. Analogous to how echoes in a cave capture the shape and construction of the environment, so to can a short and intense pulse of ICMP echo requests model the link between two network hosts. Vesper uses neural networks called autoencoders to model the normal patterns of the echoed pulses and detect when the environment changes. Using this technique, Vesper is able to detect MitM attacks with high accuracy while incurring minimal network overhead. We evaluate Vesper on LANs consisting of video surveillance cameras, servers, and PC workstations. We also investigate several possible adversarial attacks against Vesper and demonstrate how Vesper mitigates these attacks.
Yisroel Mirsky, Naor Kalbo, Yuval Elovici, Asaf Shabtai
IEEE Trans. Inf. Forensics Secur.1
2018 Predicting wireless coverage maps using radial basis networks
abstract
Accurate assessment of the wireless coverage of a station is a critical step toward deploying more base stations in Ultra Dense Networks, and it is considered as one of the key features of the 5G networks. Quickly and efficiently determining the reception coverage of transmitters becomes a complicated problem when interfering transmitters are introduced to the scenario. It becomes increasingly more complicated when the transmission powers of those transmitters are not uniform. Artificial Neural Networks are the most suitable learning algorithms for recognizing and predicting non-linear patterns. In particular, a Radial Basis Network is a type of Artificial Neural Network which typically uses a Gaussian kernel as an activator as opposed to a sigmoid function. In this paper, we suggest using Radial Basis networks in order to predict coverage maps. We show how it is possible to train the Radial Basis Network to generate coverage maps based on samples and we check the accuracy level of the learning process on a test set. Using Radial Basis Network can improve the cellular coverage prediction and therefore it can enable a more efficient spectrum allocation.
Yisroel Mirsky, Yoram Haddad 0001, Orit Rozenblit, Rina Azoulay-Schwartz
CCNC1
2018 Kitsune: An Ensemble of Autoencoders for Online Network Intrusion Detection
Yisroel Mirsky, Tomer Doitshman, Yuval Elovici, Asaf Shabtai
NDSS1
2018 Utilizing Sequences of Touch Gestures for User Verification on Mobile Devices
Liron Ben Kimon, Yisroel Mirsky, Lior Rokach, Bracha Shapira
PAKDD (3)2
2017 9-1-1 DDoS: Attacks, Analysis and Mitigation
abstract
The 911 emergency service belongs to one of the 16 critical infrastructure sectors in the United States. Distributed denial of service (DDoS) attacks launched from a mobile phone botnet pose a significant threat to the availability of this vital service. In this paper we show how attackers can exploit the cellular network protocols in order to launch an anonymized DDoS attack on 911. The current FCC regulations require that all emergency calls be immediately routed regardless of the caller's identifiers (e.g., IMSI and IMEI). A rootkit placed within the baseband firmware of a mobile phone can mask and randomize all cellular identifiers, causing the device to have no genuine identification within the cellular network. Such anonymized phones can issue repeated emergency calls that cannot be blocked by the network or the emergency call centers, technically or legally. We explore the 911 infrastructure and discuss why it is susceptible to this kind of attack. We then implement different forms of the attack and test our implementation on a small cellular network. Finally, we simulate and analyze anonymous attacks on a model of current 911 infrastructure in order to measure the severity of their impact. We found that with less than 6K bots (or $100K hardware), attackers can block emergency services in an entire state (e.g., North Carolina) for days. We believe that this paper will assist the respective organizations, lawmakers, and security professionals in understanding the scope of this issue in order to prevent possible 911-DDoS attacks in the future.
Mordechai Guri, Yisroel Mirsky, Yuval Elovici
EuroS&P2
2017 User Verification on Mobile Devices Using Sequences of Touch Gestures
abstract
Smartphones have become ubiquitous in our daily lives; they are used for a wide range of tasks and store increasing amounts of personal data. To minimize risk and prevent misuse of this data by unauthorized users, access must be restricted to verified users. Current classification-based methods for gesture-based user verification only consider single gestures, and not sequences. In this paper, we present a method which utilizes information from sequences of touchscreen gestures, and the context in which the gestures were made. To evaluate our approach, we built an application which records all the necessary data from the device (touch and contextual sensors which do not consume significant battery life), and installed it on several Galaxy S4 smartphones. The smartphones were given to 20 volunteers to use as their personal phones for two-weeks. Using XGBoost on the collected data, we were able to classify between a legitimate user and the population of illegitimate users (imposters) with an average equal error rate (EER) of 4.78% and an average area under the curve (AUC) of 98.15%. Our method demonstrates that by considering sequences of gestures, as opposed to individual gestures, the accuracy of the verification process improves significantly.
Liron Ben Kimon, Yisroel Mirsky, Lior Rokach, Bracha Shapira
UMAP2
2017 Anomaly detection for smartphone data streams
Yisroel Mirsky, Asaf Shabtai, Bracha Shapira, Yuval Elovici, Lior Rokach
Pervasive Mob. Comput.1
2015 BitWhisper: Covert Signaling Channel between Air-Gapped Computers Using Thermal Manipulations
abstract
It has been assumed that the physical separation ('air-gap') of computers provides a reliable level of security, such that should two adjacent computers become compromised, the covert exchange of data between them would be impossible. In this paper, we demonstrate BitWhisper, a method of bridging the air-gap between adjacent compromised computers by using their heat emissions and built-in thermal sensors to create a covert communication channel. Our method is unique in two respects: it supports bidirectional communication, and it requires no additional dedicated peripheral hardware. We provide experimental results based on the implementation of the Bit-Whisper prototype, and examine the channel's properties and limitations. Our experiments included different layouts, with computers positioned at varying distances from one another, and several sensor types and CPU configurations (e.g., Virtual Machines). We also discuss signal modulation and communication protocols, showing how BitWhisper can be used for the exchange of data between two computers in a close proximity (positioned 0-40 cm apart) at an effective rate of 1-8 bits per hour, a rate which makes it possible to infiltrate brief commands and exfiltrate small amount of data (e.g., passwords) over the covert channel.
Mordechai Guri, Matan Monitz, Yisroel Mirsky, Yuval Elovici
CSF3
2015 pcStream: A Stream Clustering Algorithm for Dynamically Detecting and Managing Temporal Contexts
Yisroel Mirsky, Bracha Shapira, Lior Rokach, Yuval Elovici
PAKDD (2)1
2015 Search Problems in the Domain of Multiplication: Case Study on Anomaly Detection Using Markov Chains
abstract
Most work in heuristic search focused on path finding problems in which the cost of a path in the state space is the sum of its edges' weights. This paper addresses a different class of path finding problems in which the cost of a path is the product of its weights. We present reductions from different classes of multiplicative path finding problems to suitable classes of additive path finding problems. As a case study, we consider the problem of finding least and most probable paths in a Markov Chain, where path cost corresponds to the probability of traversing it. The importance of this problem is demonstrated in an anomaly detection application for cyberspace security. Three novel anomaly detection metrics for Markov Chains are presented, where computing these metrics require finding least and most probable paths. The underlying Markov Chain is dynamically changing, and so fast methods for computing least and most probable paths are needed. We propose such methods based on the proposed reductions and using heuristic search algorithms.
Yisroel Mirsky, Aviad Cohen 0002, Roni Stern, Ariel Felner, Lior Rokach, Yuval Elovici, Bracha Shapira
SOCS1
2015 GSMem: Data Exfiltration from Air-Gapped Computers over GSM Frequencies
Mordechai Guri, Assaf Kachlon, Ofer Hasson, Gabi Kedma, Yisroel Mirsky, Yuval Elovici
USENIX Security Symposium5