Marek Pawlicki

dblp:224/4630 · DBLP profile ↗
← Back
48ranked-venue papers
15as first author
38since 2021 · last 2026
0000-0001-5881-6406ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 22 · 9 first-author · 20 since 2021Security and privacy · 14 · 3 first-author · 9 since 2021Databases, data management, data science and information retrieval · 10 · 2 first-author · 10 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 2 first-author · 5 since 2021Theory of computation · 4 · 1 first-author · 4 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author
YearPublicationVenuePosition
2026 Survey on Explainability-Weaponising Adversarial Attack Vectors against Deep Neural Networks and Artificial Intelligence
Marek Pawlicki, Ryszard S. Choras, Rafal Kozik, Michal Choras
ICAART (2)1
2025 Application of Selected Machine Learning Models in Leaf-Based Plant Health Assessment
Jakub Filipek, Marek Pawlicki, Ryszard S. Choras, Rafal Kozik, Aleksandra Pawlicka, Michal Choras
AINA (6)2
2025 Evaluation of Selected Few-Shot Learning Methods in Network Intrusion Detection
Eryk Winiecki, Marek Pawlicki, Aleksandra Pawlicka, Rafal Kozik, Michal Choras
AINA (6)2
2025 In depth analysis for securing the truth: Addressing the fake news challenge with graph neural networks
abstract
The fake news phenomenon has a significant impact on societies, homeland security, democracy and the functioning of the public space. The spread of false information is becoming an increasing challenge in the context of the dynamic growth of the volume of content shared by news outlets and social media. The overwhelming amount of this information makes manual verification of every news item or press release practically impossible. The current development of technology in the field of natural language processing (NLP) opens up new possibilities for the development of automatic content verification systems. The automation of this process not only improves but also significantly speeds up the detection of unreliable information, which is a key tool in the fight against fake news. In this article, we propose an innovative approach that involves a multi-factor assessment of the content of documents, as opposed to the frequently used approach of binary classification into fake and non-fake. Our classification system is based on analysis using graph neural networks, which allows for a more complex and contextual understanding of the data. The obtained results indicate a significant improvement in effectiveness compared to the baseline approaches, which suggests a potential for enhanced mitigation of misinformation dissemination.
Gracjan Katek, Rafal Kozik, Aleksandra Pawlicka, Marek Pawlicki, Michal Choras
Neurocomputing4
2025 A meta-survey of adversarial attacks against artificial intelligence algorithms, including diffusion models
abstract
Deep neural networks have revolutionized artificial intelligence, solving complex issues in areas like healthcare or law enforcement and security. However, they are susceptible to adversarial attacks where small data manipulations can compromise system reliability and security. This paper conducts an umbrella review of the literature on these attacks, synthesizing results from various systematic reviews to assess attack strategies, defense effectiveness, and research gaps. Guided by the PICO framework, this review categorizes and examines adversarial attacks, identifying key challenges in the field. The review finds that even though adversarial vulnerabilities were first explored in computer vision, analogous threats have expanded to domains like graph neural networks, natural language processing, federated learning, and text-to-image models. Despite varied attack surfaces, commonalities can be found. • First umbrella review synthesising systematic reviews and meta-analyses of adversarial attacks on deep neural networks, including the emerging threat to diffusion-based generative models. • PICO-driven framework addressing three research questions: (1) mapping survey themes and methods, (2) comparing domain-specific attack strategies, (3) identifying universal adversarial characteristics. • Comprehensive taxonomy covering gradient-based, transfer-based, score-based, decision-based, black-box, poisoning, privacy, and universal adversarial attacks. • Domain-specific analysis across computer vision, natural language processing, graph neural networks, intrusion detection systems, federated learning, GANs/VAEs, and text-to-image models like Stable Diffusion.
Marek Pawlicki, Aleksandra Pawlicka, Rafal Kozik, Michal Choras
Neurocomputing1
2024 Enhancing Network Security Through Granular Computing: A Clustering-by-Time Approach to NetFlow Traffic Analysis
abstract
This paper presents a study of the effect of the size of the time window from which network features are derived on the predictive ability of a Random Forest classifier implemented as a network intrusion detection component. The network data is processed using granular computing principles, gradually increasing the time windows to allow the detection algorithm to find patterns in the data at different levels of granularity. Experiments were conducted iteratively with time windows ranging in size from 2 to 1024 seconds. Each iteration involved time-based clustering of the data, followed by splitting into training and test sets at a ratio of 67% - 33%. The Random Forest algorithm was applied as part of a 10-fold cross-validation. Assessments included standard detection metrics: accuracy, precision, F1 score, BCC, MCC and recall. The results show a statistically significant improvement in the detection of cyber attacks in network traffic with a larger time window size (p-value 0.001953125). These results highlight the effectiveness of using longer time intervals in network data analysis, resulting in increased anomaly detection.
Mikolaj Komisarek, Marek Pawlicki, Salvatore D'Antonio, Rafal Kozik, Aleksandra Pawlicka, Michal Choras
ARES2
2024 Introducing a Multi-Perspective xAI Tool for Better Model Explainability
abstract
This paper introduces an innovative tool equipped with a multi-perspective, user-friendly dashboard designed to enhance the explainability of AI models, particularly in cybersecurity. By enabling users to select data samples and apply various xAI methods, the tool provides insightful views into the decision-making processes of AI systems. These methods offer diverse perspectives and deepen the understanding of how models derive their conclusions, thus demystifying the "black box" of AI. The tool’s architecture facilitates easy integration with existing ML models, making it accessible to users regardless of their technical expertise. This approach promotes transparency and fosters trust in AI applications by aligning decision-making with domain knowledge and mitigating potential biases.
Marek Pawlicki, Damian Puchalski, Sebastian Szelest, Aleksandra Pawlicka, Rafal Kozik, Michal Choras
ARES1
2024 Trustworthy AI-based Cyber-Attack Detector for Network Cyber Crime Forensics
abstract
In recent years, the increasing sophistication and proliferation of cyberthreats have underscored the necessity for robust network security measures, as well as a comprehensive approach to cyberprotection at large. As cyberthreats are continuously more and more complex, and their detection, response and mitigation often involve dealing with big data, the need for novel solutions is present also in cyber-criminal law enforcement (LEA) and network forensics contexts. Traditional, anomaly-based or signature-based intrusion detection systems (IDS) often face challenges in adapting to the evolving cyberattack landscape. On the other hand, Machine Learning (ML) has emerged as a promising approach, proving its ability to detect complex patterns in big data, including applications such as intrusion detection and classification of threats in the network environment, with high accuracy and precision (reduced rate of false positives). In this paper we present the Trustworthy Cyberattack Detector tool (TCAD), benefiting from the machine learning algorithms for the detection and classification of cyberattacks. TCAD can be used for monitoring the network in real-time and for offline analysis of collected network data. We believe that the TCAD can be successfully applied for the task of detecting and classifying evidence during criminal investigations related to network cyber attacks, but also can be helpful for the correlation of discovered network-based events over time with other collected non-network evidence.
Damian Puchalski, Marek Pawlicki, Rafal Kozik, Rafal Renk, Michal Choras
ARES2
2024 Involving Society to Protect Society from Fake News and Disinformation: Crowdsourced Datasets and Text Reliability Assessment
Gracjan Katek, Marta Gackowska, Joanna Komorniczak, Pawel Ksieniewicz, Rafal Kozik, Marek Pawlicki, Michal Choras
ACIIDS (2)6
2024 ULTIMATE Project Toolkit for Robotic AI-Based Data Analysis and Visualization
Rafal Kozik, Damian Puchalski, Aleksandra Pawlicka, Szymon Bus, Jakub Glówka, Krishna Chandramouli, Marco Tiemann, Marek Pawlicki, Rafal Renk, Michal Choras
ACIIDS (2)8
2024 A Novel Approach to the Use of Explainability to Mine Network Intrusion Detection Rules
Federica Uccello, Marek Pawlicki, Salvatore D'Antonio, Rafal Kozik, Michal Choras
ACIIDS (1)2
2024 When an Old Telecommunication Law Meets Generative AI: the Manifesto to Unbundle AI
abstract
The emergence and consecutive entrance of Generative AI (particularly ChatGPT) into the mainstream has provoked all kinds of reactions, from excitement to apprehension, but it has not been definitely decided whether it is a boon or a bane yet. We wish to voice the still unmentioned relation between AI accessibility and social injustice. So far, the initial access to tools such as ChatGPT has been free or low-cost. This is predicated on the availability of open-source or inexpensively sourced data. As the value of models hinges upon high quality, diverse data, the demand for it will increase, resulting in the rising costs of its procuration. We worry that the free models will then turn into expensive commodities, limiting their use only to the privileged entities. This potential shift causes major concerns about ethics and social equity, with the concept of unbundling being one of the potential solutions.
Aleksandra Pawlicka, Marek Pawlicki, Dagmara Jaroszewska-Choras, Damian Puchalski, Rafal Kozik, Michal Choras
IEEE Big Data2
2024 When explainability turns into a threat - using xAI to fool a fake news detection method
abstract
The inclusion of Explainability of Artificial Intelligence (xAI) has become a mandatory requirement for designing and implementing reliable, interpretable and ethical AI solutions in numerous domains. xAI is now the subject of extensive research, from both the technical and social science perspectives. It is being received enthusiastically by legislative bodies and regular users of machine-learning-boosted applications alike. However, opening the black box of AI comes at a cost. This paper presents the results of the first study proving that xAI can enable successful adversarial attacks in the domain of fake news detection and lead to a decrease in AI security. We postulate the novel concept that xAI and security should strike a balance, especially in critical applications, such as fake news detection. An attack scheme against fake news detection methods is presented that employs an explainable solution. The described experiment demonstrates that the well-established SHAP explainer can be used to reshape the structure of the original message in such a way that the value of the model's prediction could be arbitrarily forced, whilst the meaning of the message stays the same. The paper presents various examples for which the SHAP values are used to point the adversary to the words and phrases that have to be changed to flip the label on the model prediction. To the best of the authors' knowledge, it has been the first research work to experimentally demonstrate the sinister side of xAI. As the generation and spreading of fake news has become a tool of modern warfare and a grave threat to democracy, the potential impact of explainable AI should be addressed as soon as possible.
Rafal Kozik, Massimo Ficco, Aleksandra Pawlicka, Marek Pawlicki, Francesco Palmieri 0002, Michal Choras
Comput. Secur.4
2024 Towards explainable fake news detection and automated content credibility assessment: Polish internet and digital media use-case
Rafal Kozik, Gracjan Katek, Marta Gackowska, Sebastian Kula, Joanna Komorniczak, Pawel Ksieniewicz, Aleksandra Pawlicka, Marek Pawlicki, Michal Choras
Neurocomputing8
2024 Advanced insights through systematic analysis: Mapping future research directions and opportunities for xAI in deep learning and artificial intelligence used in cybersecurity
abstract
This paper engages in a comprehensive investigation concerning the application of Explainable Artificial Intelligence (xAI) within the context of deep learning and Artificial Intelligence, with a specific focus on its implications for cybersecurity. Firstly, the paper gives an overview of xAI techniques and their significance and benefits when applied in cybersecurity. Subsequently, the authors methodically delineate their systematic mapping study, which serves as an investigative tool for discerning the potential trajectory of the field. This strategic methodological framework lets one identify the future research directions and opportunities that underlie the integration of xAI within the realm of Deep Learning, Artificial Intelligence, and cybersecurity, which are described in-depth. Then, the paper brings together all the gathered insights from this extensive investigation and closes with final conclusions.
Marek Pawlicki, Aleksandra Pawlicka, Rafal Kozik, Michal Choras
Neurocomputing1
2024 Evaluating the necessity of the multiple metrics for assessing explainable AI: A critical examination
abstract
This paper investigates the specific properties of Explainable Artificial Intelligence (xAI), particularly when implemented in AI/ML models across high-stakes sectors, in this case cybersecurity. The authors execute a comprehensive systematic review of xAI properties, various evaluation metrics, and existing frameworks to assess their utility and relevance. Subsequently, the experimental sections evaluate selected xAI techniques against these metrics, delivering key insights into their practical utility and effectiveness. The findings highlight that the proliferation of metrics enhances the understanding of xAI systems but simultaneously exposes challenges such as metric duplication, inefficacy, and confusion. These issues underscore the pressing need for standardized evaluation frameworks to streamline their application and strengthen their effectiveness, thereby improving the overall utility of xAI in critical domains.
Marek Pawlicki, Aleksandra Pawlicka, Federica Uccello, Sebastian Szelest, Salvatore D'Antonio, Rafal Kozik, Michal Choras
Neurocomputing1
2024 AI vs linguistic-based human judgement: Bridging the gap in pursuit of truth for fake news detection
Aleksandra Pawlicka, Marek Pawlicki, Rafal Kozik, Agnieszka Andrychowicz-Trojanowska, Michal Choras
Inf. Sci.2
2024 A Meta-Analysis of State-of-the-Art Automated Fake News Detection Methods
abstract
Recently, various artificial intelligence (AI)-based methods have been proposed to support humans in detecting disinformation and fake news. The goal of this article is to provide a meta-analysis, and formally evaluate, compare, and benchmark various classes of fake news detection approaches. To this end, the following paper performs a comprehensive analysis of the performance-related results of different models using a range of benchmark datasets. The performed and disclosed meta-analysis compares the statistical significance of differences in a range of performance metrics, including precision,$F1$-score, recall, and balanced accuracy (BACC). The utilized approach features the$5$$\times$$2$cross-validation methodology. The models undergoing the formal evaluation constitute state-of-the-art (SOTA) solutions meeting acceptance criteria. The evaluated approaches draw from the most recent advancements in natural language processing (NLP). The outcome of this work is the formal benchmarking and meta-analysis of fake news detection methods that can be further utilized by the research community, but more importantly by the practitioners and decision-makers that counter fake news on a daily basis, e.g., in press agencies, homeland security agencies, fact-checkers, and so on. This work is the natural extension of the authors’ previous systematic analysis of fake news detection methods and authors’ own fake news detection methods based on machine learning (ML)/artificial intelligence (AI) techniques.
Rafal Kozik, Aleksandra Pawlicka, Marek Pawlicki, Michal Choras, Wojciech Mazurczyk, Krzysztof Cabaj
IEEE Trans. Comput. Soc. Syst.3
2023 Modern NetFlow network dataset with labeled attacks and detection methods
abstract
Network Intrusion Detection Systems are an important part of cyber-defensive inventory. Currently, Machine-Learning-Based Network Intrusion Detection Systems are being researched as an effective security measure. This paper introduces a novel NetFlow-based dataset geared for the training of machine-learning-based detection systems. The dataset incorporates common cyberattacks such as Denial-of-Service, Port Scanning, and brute-force attacks, which represent significant threats to network security. The efficacy of the dataset is evaluated with the use of four machine learning algorithms, with the detection metrics reported. The dataset is an attempt to fill the vacuum for current, realistic datasets in cybersecurity research. The traffic was collected in a real network in the BTC complex in Ljubljana. The dataset can significantly contribute to enhancing the effectiveness of machine learning-based Network Intrusion Detection Systems.
Mikolaj Komisarek, Marek Pawlicki, Tomi Simic, David Kavcnik, Rafal Kozik, Michal Choras
ARES2
2023 Combating Disinformation with Holistic Architecture, Neuro-symbolic AI and NLU Models
abstract
It is important to realize that false news is more than just a deception. Sadly, it is impossible to confirm every bit of information we come across. A normal human impulse is to accept any information that looks sufficiently convincing, relevant, or exciting. In doing so, we often do not realize that we have just contributed to the misinformation of the community to which we belong. As a result, fake news happens to be our collective error. In this paper, we propose an architecture for combating the disinformation problem using a hybrid-based approach. We demonstrate our preliminary results on the health-related fake news dataset.
Rafal Kozik, Wojciech Mazurczyk, Krzysztof Cabaj, Aleksandra Pawlicka, Marek Pawlicki, Michal Choras
DSAA5
2023 Model Stitching Algorithm for Fake News Detection Problem
abstract
Nowadays, we can see how social media networks are developing. We must accept the fact that the opinion of an expert is frequently just as valuable and crucial as that of a non-expert. It is feasible to see how traditional media is undergoing changes and processes that diminish the importance of the traditional ”editing office” and place a growing focus on journalists’ remote labour.As a result, social media has evolved into a component of national security since fake news and disinformation spread by nefarious individuals can influence readers and spark pointless debates on social issues that are inherently unimportant. This has a domino effect, instils dread in the populace, and eventually puts the security of the state in jeopardy.Recently, deep machine learning techniques have proven to be one of the technologies thought to be an effective way to combat the false news problem. However, due to shortages of labelled data, these methods often have poor model generalization capabilities when applied in real-world cases.In this paper, we address this problem by utilizing lightweight model stitching, which serves as a foundation for a hybrid method for fake news detection. Six distinct benchmark datasets have been used in our varied experiments. The outcomes are promising and pave the way for additional studies.
Rafal Kozik, Aleksandra Pawlicka, Marek Pawlicki, Michal Choras
DSAA3
2023 Towards Quality Measures for xAI algorithms: Explanation Stability
abstract
The domain of Artificial Intelligence has become ubiquitous across a wide plethora of domains and is now an integral part of the daily life of the ordinary citizen. While the need for increased transparency of the highly accurate black-box model is an important and very active area of research, the produced explanations themselves might not always be accurate. The measures to assess the quality of explanations are an important research topic. In this paper, a set of extensive experiments is performed to evaluate the stability of SHAP explanations under conditions of different noise types and different noise intensities as an effort to build a formal way of assessing the quality of explanations provided by the SHAP algorithm. The experiments are performed on four different datasets, with three different noise types at four different strength levels. The impact of the scenarios on SHAP explanations is reported, the implications for the evaluation of explainability methods are elaborated upon, along with the significance of the results for the SHAP method of explanations. The future directions are laid out thereafter.
Marek Pawlicki
DSAA1
2023 Explainable Artificial Intelligence 101: Techniques, Applications and Challenges
Wiktor Kurek, Marek Pawlicki, Aleksandra Pawlicka, Rafal Kozik, Michal Choras
ICIC (4)2
2023 Improving Siamese Neural Networks with Border Extraction Sampling for the use in Real-Time Network Intrusion Detection
abstract
Society reaps the benefits of networking technologies, with the number of connected citizens and devices constantly on the rise. The convenience and efficiency brought by connected technologies are adopted in normal households and industrial plants alike. As the proliferation of the technology expands, the incentives for malicious users to cause mischief are also getting stronger. This causes an influx in cyber incidents. To deal with the rising cyberthreats, a suite of defensive methods has been proposed. One prominent example is network intrusion detection systems. The Machine-Learning-based network intrusion detection systems utilised in critical infrastructure or soft target protection offer many benefits, but still, need improvements in numerous areas. This paper contains a proposition of an improved network intrusion detection system featuring a Siamese network as a few-shot learner. The used NetFlow features allow the system to perform real-time intrusion detection, the Siamese network allows spotting attacks from classes that were not used during the training of the network, and the used sampling method allows circumventing the over-counting problem when formulating sample pairs to train the Siamese networks. The results of the research are presented and show promise.
Marek Pawlicki, Rafal Kozik, Michal Choras
IJCNN1
2023 The survey and meta-analysis of the attacks, transgressions, countermeasures and security aspects common to the Cloud, Edge and IoT
Marek Pawlicki, Aleksandra Pawlicka, Rafal Kozik, Michal Choras
Neurocomputing1
2023 First broad and systematic horizon scanning campaign and study to detect societal and ethical dilemmas and emerging issues spanning over cybersecurity solutions
Aleksandra Pawlicka, Michal Choras, Rafal Kozik, Marek Pawlicki
Pers. Ubiquitous Comput.4
2022 A novel, refined dataset for real-time Network Intrusion Detection
abstract
In this day and age of widespread Internet access, more and more aspects of the economy are becoming dependent on various aspects of network technologies. Cybercrimes are on the rise and massive numbers of network security breaches occur every year. This paper presents network data collected in the Netflow format and its application to detect network attacks. The paper proposes a refined, real-world dataset collected from an academic network. The dataset is a direct result from the experience gained by working on and with the SIMARGL2021 dataset. The applicability of the new dataset is demonstrated on several machine learning algorithms. This novel dataset is open-sourced for researchers to download and use in scientific work.
Mikolaj Komisarek, Marek Pawlicki, Maria-Elena Mihailescu, Darius Mihai, Mihai Carabas, Rafal Kozik, Michal Choras
ARES2
2022 The cybersecurity-related ethical issues of cloud technology and how to avoid them
abstract
Nowadays, cloud technology is assuming immense significance, being treated as a critical infrastructure, and is also a buzzword. Nevertheless, the technology has also brought about a number of new adverse phenomena and threats; it has attracted criminals, as well. Whenever the questions of “good” and “bad” arise, the ethical issues arise alongside them; the cybersecurity of cloud technology is no exception. This paper deals with the ethical dilemmas of cloud technology. It discusses a collection of the ethical issues of the cloud technology presented from the perspective of cybersecurity, based on the state-of-the-art literature. The main contribution of this work is that it gathers, synthesizes and organises the cybersecurity-related ethical dilemmas of cloud technology, thus offering the most extensive collection thereof. In addition, the work presents a comprehensive list of recommendations and suggestions which may help solve or prevent these ethical issues, and are a good starting point for anyone designing an ethical cybersecurity strategy.
Aleksandra Pawlicka, Marek Pawlicki, Rafal Renk, Rafal Kozik, Michal Choras
ARES2
2022 Towards Deployment Shift Inhibition Through Transfer Learning in Network Intrusion Detection
abstract
Currently, machine learning sees growing adoption in numerous domains, including critical applications, like cybersecurity. However, to fully enjoy the benefits of artificial intelligence the end-user has some high barriers to entry to circumnavigate. The deployment of machine-learning-based Network Intrusion Detection Systems requires the collection of labelled data to train the intelligent components. This is an expensive and laborious process, which necessitates expert knowledge in cyberattacks and computer networks. Even when using data collected and labelled on premises, phenomena like concept drift can cause the model to underperform - a concept known as deployment shift. This paper evaluates the use of transfer learning techniques to curb the effects of deployment shift in machine-learning-based network intrusion detection.
Marek Pawlicki, Rafal Kozik, Michal Choras
ARES1
2022 Fast Hybrid Oracle-Explainer Approach to Explainability Using Optimized Search of Comprehensible Decision Trees
abstract
Explainability, Transparency, and Fairness are now recognized foundations that have altered the landscape of the artificial intelligence domain. Excellent performance is no longer enough if the decisions of a system can upset the life of a regular citizen. The stakeholders of a utilised system must know whether they can trust the results the system provides, for both ethical and legal reasons. This can be made possible with Explainable Artificial Intelligence (xAI). It helps detect errors that could compromise the effectiveness of an intelligent system. It can discover biases present in the data that could lead to unfair treatment. It also provides novel insights regarding the data and the investigated domain. The applicability and benefits of Explainable Artificial Intelligence are explicit; however, scalable and simple-to-use solutions are scarce. Therefore, this paper proposes a new approach to explainability called "Fast Hybrid Oracle-Explainer". This method is a significant extension and improvement over previous approaches utilizing Comprehensible Decision Trees, expanded with the Nearest Neighbors Search algorithm. Compared to its predecessors, the proposed method maintains a similar level of agreement while drastically reducing the time necessary to provide an explanation. Furthermore, it still offers concise and intuitive decision-tree-based explanations. This paper presents details of this new approach in the context of an Intrusion Detection System. The soundness, clarity, and performance of the proposed method are proven experimentally.
Mateusz Szczepanski, Marek Pawlicki, Rafal Kozik, Michal Choras
DSAA2
2022 Efficient Post Event Analysis and Cyber Incident Response in IoT and E-commerce Through Innovative Graphs and Cyberthreat Intelligence Employment
Rafal Kozik, Marek Pawlicki, Mateusz Szczepanski, Rafal Renk, Michal Choras
ICIC (3)2
2022 A survey on neural networks for (cyber-) security and (cyber-) security of neural networks
abstract
The goal of this systematic and broad survey is to present and discuss the main challenges that are posed by the implementation of Artificial Intelligence and Machine Learning in the form of Artificial Neural Networks in Cybersecurity, specifically in Intrusion Detection Systems. Based on the results of the state-of-the-art analysis with a number of bibliographic methods, as well as their own implementations, the authors provide a survey of the answers to the posed problems as well as effective, experimentally-found solutions to those key issues. The issues include hyperparameter tuning, dataset balancing, increasing the effectiveness of an ANN, securing the networks from adversarial attacks, and a range of non-technical challenges of applying ANNs for IDS, such as societal, ethical and legal dilemmas, and the question of explainability. Thus, it is a systematic review and a summary of the body of knowledge amassed around implementations of Artificial Neural Networks in Network Intrusion Detection, guided by an actual, real-world implementation.
Marek Pawlicki, Rafal Kozik, Michal Choras
Neurocomputing1
2021 Network Intrusion Detection in the Wild - the Orange use case in the SIMARGL project
abstract
There is a profuse abundance of network security incidents around the world every day. Increasingly, services and data stored on servers fall victim to sophisticated techniques that cause all sorts of damage. Hackers invent new ways to bypass security measures and modify the existing viruses in order to deceive defense systems. Therefore, in response to these illegal procedures, new ways to defend against them are being developed. In this paper, a method for anomaly detection based on machine learning technique is presented and a near real-time processing system architecture is proposed. The main contribution is a test-run of ML algorithms on real-world data coming from a world-class telecom operator. This work investigates the effectiveness of detecting malicious behaviour in network packets using several machine learning techniques. The results achieved are expressed with a set of metrics. For better clarity on the classifier performance, 10-fold cross-validation was used.
Mikolaj Komisarek, Marek Pawlicki, Mikolaj Kowalski, Adrian Marzecki, Rafal Kozik, Michal Choras
ARES2
2021 Missing and Incomplete Data Handling in Cybersecurity Applications
Marek Pawlicki, Michal Choras, Rafal Kozik, Witold Holubowicz
ACIIDS1
2021 Towards AI-Based Reaction and Mitigation for e-Commerce - the ENSURESEC Engine
Marek Pawlicki, Rafal Kozik, Damian Puchalski, Michal Choras
ICIC (3)1
2021 Intrusion detection approach based on optimised artificial neural network
Michal Choras, Marek Pawlicki
Neurocomputing2
2021 A new method of hybrid time window embedding with transformer-based traffic data classification in IoT-networked environment
abstract
Abstract The Internet of Things (IoT) appliances often expose sensitive data, either directly or indirectly. They may, for instance, tell whether you are at home right now or what your long or short-term habits are. Therefore, it is crucial to protect such devices against adversaries and has in place an early warning system which indicates compromised devices in a quick and efficient manner. In this paper, we propose time window embedding solutions that efficiently process a massive amount of data and have a low-memory-footprint at the same time. On top of the proposed embedding vectors, we use the core anomaly detection unit. It is a classifier that is based on the transformer’s encoder component followed by a feed-forward neural network. We have compared the proposed method with other classical machine-learning algorithms. Therefore, in the paper, we formally evaluate various machine-learning schemes and discuss their effectiveness in the IoT-related context. Our proposal is supported by detailed experiments that have been conducted on the recently published Aposemat IoT-23 dataset.
Rafal Kozik, Marek Pawlicki, Michal Choras
Pattern Anal. Appl.2
2021 The stray sheep of cyberspace a.k.a. the actors who claim they break the law for the greater good
abstract
Abstract The development of cyberspace has brought about innumerable advantages for the mankind. However, it also came with several serious drawbacks; as cyberspace evolves, so does cybercrime. Since the birth of cyberspace, individuals, groups and whole nations have been engaging in computer-related offences of various significance and impact, trying to exploit systems’ vulnerabilities, disseminate malicious software and steal data or funds. The concept of a hacker has entered the collective consciousness and become an intrinsic element of popular culture. However, there are hackers, or rather, cyberspace actors, who challenge this common view. This paper presents three types of such people, namely hacktivists, members of cyber militias and Internet trolls. Although they all use the Internet to break the laws or rules, their internal motivations are not always utterly sinister; actually, some of them firmly believe that their actions are for the greater good. This paper is structured as follows: Firstly, the general profile of a hacker is presented. Then, the state of the art is outlined, concerning other papers dealing with the motivations behind cyber threat actors. Following that, the three aforementioned groups of cyberspace actors are contrasted with the profile of a ‘typical’ hacker. Then, the profiles of a typical representative for each of the group and their motivations are indicated, followed by the final conclusions.
Aleksandra Pawlicka, Michal Choras, Marek Pawlicki
Pers. Ubiquitous Comput.3
2020 Real-time stream processing tool for detecting suspicious network patterns using machine learning
abstract
In this paper, the performance of stream processing and accuracy in the prediction of suspicious flows in simulated network traffic is investigated. In addition, concepts of an engine that integrates with novel solutions like the Elastic-search database and Apache Kafka that allows easy definition of streams and implementation of any machine learning algorithm are presented.
Mikolaj Komisarek, Michal Choras, Rafal Kozik, Marek Pawlicki
ARES4
2020 Cyberspace threats: not only hackers and criminals. Raising the awareness of selected unusual cyberspace actors - cybersecurity researchers' perspective
abstract
Despite its development having changed and improved citizens' lives, cyberspace has also become a new arena for competition among states, organizations and individuals, and various cyber threats to people's security are becoming more prevalent, damaging and complex. Although it is rather commonly known that cyberspace is a battlefield, and almost every individual, organization or even state may fall victim to malicious hackers or greedy cybercriminals, the members of the public rarely seem to think of other sources of threat. Thus, in an attempt to raise the general awareness, this paper presents an additional number of selected, often unsuspected actors that shape and influence the cyberspace of today: nation-state actors, cyberterrorists, hacktivists and trolls. The motives of each actor, their modus operandi and the most significant representatives have also been discussed. Being aware of the existence and nature of each actor helps one better understand the threat they pose, as well as grasp the significance of the cybersecurity measures.
Aleksandra Pawlicka, Michal Choras, Marek Pawlicki
ARES3
2020 Achieving Explainability of Intrusion Detection System by Hybrid Oracle-Explainer Approach
abstract
With the progressing development and ubiquitousness of Artificial Intelligence (AI) observed in last decade, the need for creating methods which are explainable and/or interpretable for humans has become a pressing matter. The ability to understand how a system makes a decision is necessary to help develop trust, settle issues of fairness and perform the debugging of a model. Although there are many different techniques allowing to get insights into models' inner workings, they often come with a trade off in the form of decreased accuracy. In the context of cybersecurity, where a single false negative can lead to a breach and compromise of the whole system, such a price is unacceptable. Therefore, there is a need for a solution which allows for the maximum possible model performance, and at the same time delivers human understandable interpretations. The hybrid approaches to Explainable Artificial Intelligence (XAI) have the potential to achieve this goal. In this work, we present the fundamental concepts and a prototype of a system using such an architecture.
Mateusz Szczepanski, Michal Choras, Marek Pawlicki, Rafal Kozik
IJCNN3
2020 Defending network intrusion detection systems against adversarial evasion attacks
Marek Pawlicki, Michal Choras, Rafal Kozik
Future Gener. Comput. Syst.1
2019 SocialTruth Project Approach to Online Disinformation (Fake News) Detection and Mitigation
abstract
The extreme growth and adoption of Social Media, in combination with their poor governance and the lack of quality control over the digital content being published and shared, has led information veracity to a continuous deterioration. Current approaches entrust content verification to a single centralised authority, lack resilience towards attempts to successfully "game" verification checks, and make content verification difficult to access and use. In response, our ambition is to create an open, democratic, pluralistic and distributed ecosystem that allows easy access to various verification services (both internal and third-party), ensuring scalability and establishing trust in a completely decentralized environment. In fact, this is the ambition of the EU H2020 SocialTruth project. In this paper, we present the innovative project approach and the vision of effective online disinformation detection for various practical use-cases.
Michal Choras, Marek Pawlicki, Rafal Kozik, Konstantinos P. Demestichas, Pavlos Kosmides, Manik Gupta
ARES2
2019 The Identification and Creation of Ontologies for the Use in Law Enforcement AI Solutions - MAGNETO Platform Use Case
Rafal Kozik, Michal Choras, Marek Pawlicki, Witold Holubowicz, Dirk Pallmer, Wilmuth Müller, Ernst-Josef Behmer, Ioannis V. Loumiotis, Konstantinos P. Demestichas, Roxana Horincar, Claire Laudy, David Faure
ICCCI (2)3
2019 Artificial Neural Network Hyperparameter Optimisation for Network Intrusion Detection
Marek Pawlicki, Rafal Kozik, Michal Choras
ICIC (1)1
2019 The Feasibility of Deep Learning Use for Adversarial Model Extraction in the Cybersecurity Domain
Michal Choras, Marek Pawlicki, Rafal Kozik
IDEAL (2)2
2018 Recent Granular Computing Implementations and its Feasibility in Cybersecurity Domain
abstract
As the importance of data stored in daily-use information system grows, so does the damage a malicious user could inflict. Network traffic can be notoriously complicated and prone to fluctuations. With the prevailing risk of cybersecurity breaches, improving the detection algorithms is of utmost importance. Advanced systems using various facets of artificial intelligence and machine learning exist. We look forward to Granular Computing (GrC) as a novel, promising way to improve network traffic classification, intrusion detection and reduction in the computational cost of real time traffic analysis. In this paper, aquick primer on granular computing is offered, its properties of abstracting data into meaningful, compact packages named granules are looked into. The basic principles of granule creation are explained. Consecutively, a survey of the most recent Granular Computing implementations is presented, with analysis of how certain aspects of Granular Computing are utilized to solve particular real-world problems. In multiple cases, the techniques of GrC allow for an increase in efficiency and calculating speed, better data legibility and improvements in the performance of classifier algorithms the granulated data is supplied to. The examined approaches are then taxonomised with regard to the purpose of granulation, and with regard to the utilized aspect of Granular Computing.
Marek Pawlicki, Michal Choras, Rafal Kozik
ARES1
2018 Cost-Sensitive Distributed Machine Learning for NetFlow-Based Botnet Activity Detection
abstract
The recent advancements of malevolent techniques have caused a situation where the traditional signature-based approach to cyberattack detection is rendered ineffective. Currently, new, improved, potent solutions incorporating Big Data technologies, effective distributed machine learning, and algorithms countering data imbalance problem are needed. Therefore, the major contribution of this paper is the proposal of the cost-sensitive distributed machine learning approach for cybersecurity. In particular, we proposed to use and implemented cost-sensitive distributed machine learning by means of distributed Extreme Learning Machines (ELM), distributed Random Forest, and Distributed Random Boosted-Trees to detect botnets. The system’s concept and architecture are based on the Big Data processing framework with data mining and machine learning techniques. In practical terms in this paper, as a use case, we consider the problem of botnet detection by means of analysing the data in form of NetFlows. The reported results are promising and show that the proposed system can be considered as a useful tool for the improvement of cybersecurity.
Rafal Kozik, Marek Pawlicki, Michal Choras
Secur. Commun. Networks2