
International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072
![]()

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072
Vaibhav Mishra¹, Abhinav Yadav², Adnan Siddiqui³, Devesh Katiyar´, Gaurav Goelµ
¹ ² ³ Students, ´ µ Assistant Professors Department of Computer Science Dr. Shakuntala Misra National Rehabilitation University, Lucknow, Uttar Pradesh, India.
Abstract - Honestly, we came into this expecting to write a fairly standard paper about AI improving cybersecurity. What ended up in front of us was a lot more complicated than that. The same ML tools defenders use to identify and counter attacks are, structurally, the exact same tools attackers use to build attacks that slip past detection. We trace that this uncomfortable reality start from Sommer and Paxson’s 2010 critique [1] three problems they identified, that bafflingly are still unresolved through the threats that are active right now: adversarial examples defeating production scanners, data poisoning baked invisibly into models before they ever deploy, Emotet running for seven years without ever being technically beaten, voice cloning that took €220,000 from a CEO who did everything right, and LLMs that have essentially destroyed the economic barrier that kept targeted phishing in check. We look at four cases that stuck with us: UK Energy CEO fraud, the Microsoft Tay bot disaster, Emotet, and Pegasus, and then we try to make an honest argument about what the path forward looks like which, we would argue, is less about better algorithms and more about better governance, smarter human-AI collaboration, and institutions that have finally caught up to the technology they have deployed.
KEYWORD: Cybersecurity, Artificial Intelligence, Machine Learning, Adversarial Attacks, Deepfakes, Data Poisoning, Phishing, AI Governance.
Wewillbeupfrontaboutsomething:thispaperdidnotgo where we thought it would. We started with the reasonable expectation that AI in cybersecurity meant defenders were finallygettingthetoolstopullahead.Whatwe foundduring our research, was tracing how things that are attack and defence, actually played out in real scenarios and it was messierand,inaway,moreinterestingthananticipated.The technologyarrivedandbothsidespickeditupatroughlythe sametime.Thatisthesituationthefieldisactuallyin,anda lotofthecommentaryhasnotfullyreckonedwithit.
For most of computing history, there was at least a practicalseparationbetweenoffenseanddefense.Buildinga detection system took one kind of expertise; finding gaps in
it took another. The barrier to mounting a sophisticated attack was genuinely high. Organizations could invest in commercialtoolsandareasonablystaffedsecurityteamand feel like they were keeping pace. That was not a perfect situation, but the asymmetry mostly favoured defense, and thatmattered.
Machinelearningchangedthatdynamicinaveryspecific way.Takeaphishingdetectionmodelasanexampleitreads emails, learns what malicious ones look like, and flags new ones accordingly. Now take a phishing generation model it learnswhatconvincingemailslooklikeandwritesnewones that dodge those flags. Architecturally, those are the same system. You flip the training objective and the shield becomes the weapon. With both the offense and defense having same code and same model. The cost of building the attack version, once you have the defensive version, is close tonothing[12].
Forafewyears,defendersdidgetthebetterofit.Around 2015to2018orso,somethingreal washappening:security operations teams that were completely buried in alerts ten thousanda day,ninetypercent noise finallyhadtooling that could sort through the pile intelligently. Investigations that tooka week werefinishing ina day. People werestartingto feel like they were actually gaining ground. We think that periodwasreal,notimagined.ThisAI technologywasreally working.
Then the same capabilities showed up on the attacker side, and things got complicated again. Phishing quality jumped dramatically, and the cost to produce it dropped. MalwaressuchasEmotetandStormWormstartedrewriting its own signatures between infections, which made signature-baseddetectionlookincreasinglybesidethepoint. Voice synthesis crossed a threshold where it could fool a carefulpersoninalivephonecallnotinalabbutinanactual fraud. Both sides are now running on the same fuel, and there’snoversionofthatwheretheadvantagestaysfixedon oneside[12].
To be clear about what we are and are not arguing here: wearenotsayingAIhasmadecyber securityalostcause.It

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072
has no, at least not yet. The argument is more specific than that.TheframingthatAIgivesdefendersadecisiveedgewas always too simple and the reason it has not lived up to that framinghaslesstodowiththequalityofthealgorithmsthan with structural problems that algorithms cannot fix. The most important work the field needs to do right now is institutional more than it is technical, and that is an uncomfortable conclusion for a field that tends to reach for technicalsolutionsfirst.
Reading the early ML-in-security literature is genuinely strange if you know how things turned out. There is this confident energy to these papers moving from benchmark results to sweeping conclusions without much friction, a sharedassumptionthattechniquesworkingsowellinimage recognition and spam filtering would port cleanly to intrusion detection. Looking back, the accuracy numbers look impressive right up until you ask what they were actuallymeasuring.
Sommer and Paxson [1] published “Outside the Closed World” in 2010 and it remains the most honest piece of writing in the field. They were not arguing that ML was the wrong approach. They were arguing that three specific properties of the security domain break the assumptions that make supervised learning reliable elsewhere, and that thefieldhadbeenquietlyignoringallthree.
Thefirstisclassimbalance,anditisbrutalonceyouseeit. Real network attacks are a tiny fraction of real traffic sometimesoneina million events.Aclassifierthatjust calls everything normal gets 99.9% accuracy on any realistic test set, catches nothing, and looks great on paper. Standard evaluation metrics do not flag this because they were not designed with this kind of imbalance in mind, and researcherskeptpublishingresultsthatlookedlikeprogress andwouldhavebeenoperationallyuseless.
The second is concept drift [11]. Most ML domains are stable cats keep looking like cats, handwritten digits do not change to fool scanners. Adversaries are not like that. They read the same threat intelligence that defenders publish, watch what gets detected, and update their techniques. A model trained on last quarter’s attacks is already partially blind to whatis happening this quarter,and themodel does notknowitisblinditkeepsoutputtingconfidentpredictions eitherway.
Thethirdonetookusthelongesttoreallysitwith. Andit was false positives and false negatives, in most ML applications, are roughly equivalent mistakes. In security
they are not even close. A false positive means an analyst spends half an hour chasing a non-event. A false negative means a breach goes undetected, maybe for days or weeks, evenmonths,withconsequencesthatcandefineacompany’s year. Evaluation frameworks that treat these as equivalent arequietlyoptimizingforthewrongoutcome.
Here is the thing that genuinely surprised us: we went looking for solution to those three problems in papers from 2015 but did not find them. Then checked 2019 papers, but same issues are still there. Read 2023 papers, and still no closure regarding these three issues. All three, essentially unaddressed, described in almost the same terms Sommer and Paxson used over a decade earlier. That is either a sign ofunusuallydeepstructuralproblemsorasignthatthefield has not asked hard enough questions about its own assumptions.Wecametoaconclusionbasedonourresearch thatitisacocktailofboth.
The other piece of foundational work we kept returning to is Goodfellow et al. [2] from 2015. They showed that carefully crafted, imperceptibly small perturbations to an input can flip a neural network’s output entirely and with high confidence the famous panda-that-a-classifier-calls-agibbon (a kind of ape) result. The security version is direct: modify a malicious file at the byte level in ways that do not affect what it does at runtime, and watch it clear a trained scanner. Anderson [5] and Demetrio et al. [7] confirmed this works against actual production endpoint security products that real organizations are running and not just researchprototypes.
Ofall the threatswecovered, voice cloningis the one we kept coming back to not because it is technically the most sophisticated edit, not really but because it attacks something so basic that nobody thought to build a defense against it. We trust familiar voices. We have done it our entire lives because there was never a reason not to. That lifetime of completely reasonable, automatic trust is now an attacksurface.
Building a convincing deepfake video takes real resources: footage, compute, editing work. Building a voice clone that holds up in a live phone call takes maybe five minutesoftargetaudio,andforanyexecutivewhohasgiven atalk,doneapodcast,orbeenonrecordedearningscallthat audioison theinternet rightnow availablefreeofcost. The barriertomountingthisattackisessentiallyzeroforanyone motivatedtotry[13].

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072
Security awareness training has spent years teaching people to scrutinize emails because malicious emails carry detectable anomalies. A well-executed voice clone carries none [19]. There is nothing to scrutinize. The person receiving the call has no reason to question its credibility Their identity-verification instinct fires, concludes this sounds like my boss, and they act on it. The instinct is not broken.Itisjustbeenmadeexploitablebyatechnologythat arrivedfasterthananyinstitutionaldefenseforitdid.
The adversarial example finding does not stay politely in image classification. It transfers directly to malware detection. Small, targeted modifications to a malicious executableoperatingatthebytelevel,completelyinvisibleto a human reviewer can push the file across a scanner’s decision boundary from flagged to clean. The file still executesexactlywhatitwaswrittentoexecute.Itjustlooks, tothemodel,likeitdoesn’t[2],[4],[7].
Whatmakesthisparticularlyfrustratingfromadefensive standpoint: there’s often nothing to find on manual review. The scanner cleared it. An analyst looking at the file finds nothing unusual. The malicious behaviour only surfaces at runtime.Bythen,it’stoolatetohavehelped.
If voice cloning is the loudest attack on this list, data poisoning is the quietest and that quietness is most of what makes it dangerous. The attack does not look like an attack while it is happening. It happens upstream of everything, often months before deployment. An adversary who can influence the training pipeline, or who can affect how training labels get assigned, can build specific blind spots directlyintothemodelfromthestart[16].
Thefinishedmodelisfinebyeverymetricthedeployment team has. It passes validation. It performs correctly on test data. It handles the vast majority of production inputs without issue. It fails silently, predictably, and only on the exactscenariostheattackerdesignedittofailon.Bythetime someone figures out what happened, the poisoned model mayhavebeenmakingrealdecisionsfor months.Thisisthe attack that is hardest to catch because it does not announce itself.
We’d read about Emotet before this paper. Reading the actual timeline of it was still something. It ran from 2014 to 2021 about seven years. In that time, it got caught,
contained, and declared gone repeatedly. Security teams would write up how they’d stopped it, publish indicators of compromise, document the detection rules, and then it wouldcomebackafewweekslaterinaformthoserulesdid notcover.
Because Emotet was reading those writeups. It went dormant in sandbox environments to avoid automated analysis. It rewrote its signatures between infections. It monitored published threat intelligence from security vendors and updated its evasion logic in direct response treating the security industry’s own research as a real-time improvement service [6]. Teams documenting their containmentwork were,withoutknowingit,contributingto itsnextiteration.
What finally stopped it was Europol, in January 2021, coordinating a physical seizure of its server infrastructure. Not a detection breakthrough. Not a better model. Law enforcement seizing hardware. The technical problem was neversolved.Itwasbypassed.
Every phishing training programme ever designed rests ononeassumption:thatpersonalised,contextuallyaccurate, convincingly written phishing emails cost something to produce. That cost created the detectable artifacts people were trained to spot slightly off phrasing, generic greetings, implausible urgency. The expense was the constraint, and theartifactswerethetells.
Largelanguagemodelserasedthatconstraint.Thecostof generatingaphishingemailthatreferencesarealprojectthe targetisworkingon,usesaccurateinternalterminology,and is written in fluent professional prose with none of the traditional red flags, that cost is now essentially zero [14]. We ran this ourselves during the research. Gave a widely available model a fake company, a job title, a plausible scenario. What came back would have given us pause if we had not written the prompt. The assumption the entire training infrastructure was built on is gone. Most programmeshavenotcaughtup.
InAugust2019,theCEOofaUKenergycompanyreceived aphonecallfromsomeonewhosoundedexactlylikehisboss at the German parent company. Same accent. Same rhythm. Same choices of words. Same particular register of urgency

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072
thatpersonusedwhensomethingneededtohappenquickly. He was told to transfer €220,000 to a Hungarian supplier thatday,partofanacquisition.Heassessedthecallcarefully. The voice sounded right. The story was plausible. He made thetransfer.
The money moved through Hungary to Mexico within hoursandwasgone.Thevoicewassynthetic[19].
We want to be precise about what happened here. The CEO did not cut corners. He performed exactly the verification any reasonably cautious person would perform he assessed the available identity signal, which was the voice,and itchecked out. Theattack workednotbecausehe wascarelessbutbecausethecognitiveshortcutheused-this sounds like someone I know, so it probably was being exploited by a technology that arrived before any institutional defense for it did. That shortcut was perfectly reliable for all of human history until recently. It isn’t anymore.
Microsoft launched Tay in March 2016 as a chatbot that would learn and grow through conversations with Twitter users. The idea was a system that developed a genuine personalitythroughrealinteraction.Itlastedsixteenhours.
A coordinated group of users identified the feedback mechanism, how Tay updated its outputs based on what people said and they spent the afternoon methodically cycling harmful content through it until the model reproduced it confidently. Tay did exactly what it was built to do. The design had not considered adversarial users operating in coordination, which is to say it had not consideredtheinternetasitactuallyis.
People usually take a content moderation lesson from Tay. We think the deeper point is that what happened was real-timedatapoisoninginproduction.Noaccesstotraining infrastructure required. No technical sophistication beyond identifyingthefeedbackloop.Justcoordination.Anylearning system that updates on user interaction faces some version of this. This led to AI organizations introduce filters and safeguardstoprotecttheintegrityoftheirmodel.
NSO Group’s Pegasus is documented in careful detail by Citizen Lab at the University of Toronto, and the documentation is sobering [8]. The attack exploited a vulnerabilityinhowiMessageparsedaspecificfiletype.The result:completedevicecompromisesthemomentamessage
arrivedbeforethescreenwaslookedat,beforeanythingwas tapped, with nothing visible to indicate anything had happened.
Nolinktoavoidclicking.Noattachmenttodecideagainst opening. No action available to the target that would have changed the outcome [9]. The device was compromised at message delivery. This is a fundamentally different category of threat from anything user awareness training addresses, because user awareness training assumes the user has a decisiontomake.Atthezero-clicklevel,theydon’t.
The fair question at this point is: why not? Why do the exact problems Sommer and Paxson named in 2010 still showup in current papers? The researchersinthis field are good. The answer is not a lack of effort. The answer is that the most important barriers are not technical, and you can’t debugyourwaypastastructuralproblem.
Thedata-privacytensionisoneofthese.Effectivesecurity AI runs on large, longitudinal datasets of real behavioural data. Privacy law, for entirely legitimate reasons, pushes in the opposite direction: collect the minimum data, retain it briefly and limit the use of that data. Both positions are defensible. Together, they’re in direct conflict, and every security team is quietly making a judgment call somewhere inthemiddle,usuallywithoutdocumentingit,hopingitdoes notgettestedinawaythatmakesitvisible.
Embedded bias is the problem we suspect most organizationsarenotthinkingaboutatall.MLmodelsdonot just learn signal they learn the statistical patterns in their training data, including the biased ones. If historical data reflects patterns where certain behaviours or profiles got flagged more often for whatever historical reasons those patterns exist and the model learns to reproduce them. The system can be accurate to its training distribution and systematically unfair in ways that are hard to see without specifically looking. We’d be surprised if more than a small fractionoforganizationsareauditingtheirdeployedsecurity modelsforthis[17],[18].
The explainabilitygap bothersus mostonanoperational level. The models with the best detection performance are almost always the opaquest about why they produced a given output. An analyst who gets a high-confidence alert with no supporting reasoning has to decide whether to escalateordismisssolelyonthebasisofanumber.Whenthe model is wrong, nothing in the output suggests it might be. This drives alert fatigue in a direct, rational way: analysts

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072
learn to discount confident alerts because confident alerts aresometimeswrongandtheycannottellwhichones.That’s not an irrational response. It’s the correct update given the informationavailable[10],[15].
The economic asymmetry is probably the deepest problem and the furthest from any technical solution. Build one evasion technique, run it against thousands of organizations at near-zero marginal cost. Each of those organizationsindependentlyhastofindit,understandit,and respondusuallywithoutknowingtheothersaredealingwith the same thing. The total resource investment is on the defensivesideandscaleswiththenumberofdefenders.The attacker’s cost stays flat. Better AI on the defensive side helps at the margins. It does not change that fundamental math[1],[12].
We want to be honest that there are genuine advances here, because a paper that only catalogues problems isn’t beingfullyaccurateeither.Somethingsareworking.
SHAP (SHapley Additive exPlanations) and LIME (Local Interpretable Model-agnostic Explanations) are the tools which explain why a ML model took that specific decision whentheytakeitandtheydonotrevealtheentireprocessit takes to generate that response as it is lengthy and complex instead, they provide the list of inputs used and how the model’s reasoning worked to reach this output. They have reached real practical utility in security operations. Not because they make models transparent in any deep sense, but because they provide feature-level reasoning for specific outputs. The shift from “94% confidence: threat” to “94% confidence: threat, driven primarily by features X and Y” is a small technical change and a meaningful operational one. It gives the analyst something to verify, something to investigate, a reason that can be written up and explained [10],[15].
The human-AI pairing that actually works is not the one that gets most of the marketing. The usual pitch is autonomous detection, AI that removes human judgment from the loop in the interest of speed. But what we see workingismorelikeasensibledivisionoflabour:AIhandles what it is genuinely better at: continuous monitoring, consistentpatternmatching,maintainingdetectionlibraries, never getting tired at 3 am while humans handle what they’re genuinely better at understanding what a pattern means in this specific environment, judging how serious it actuallyis,decidingwhatresponseisproportionate.Remove theAIanddefendersgetburied.Removethehumansandthe
system makes confident errors with nobody to catch them [21].
TheEUAIAct(2024)[20]mattersnotbecauseregulation automaticallyproducesgoodsecurity outcomes but because itconvertscompliancefrom optional tomandatory,creating legalaccountabilityforhighriskAI.Thevoluntarybest-practice frameworks that preceded it were useful for organizations already motivated to act. For the ones that were not, voluntary meant ignored. When real consequences attach to non-compliance,thecalculuschanges.
Post-quantum cryptography is the issue that worries us most relative to how much attention it is getting. NIST finalised its post-quantum standards in 2024. Most organizationshavenotstartedmigrationinanyseriousway. The threat is not immediate in the short term, probably but migration takes years even when it’s prioritised, and data encrypted today can be stored and decrypted later when quantum hardware arrives. Being wrong about the timeline isnotrecoverable.
Autonomous response is the open problem we genuinely could not resolve. The speed argument is real but some attackcategoriesmovefasterthanhumanresponsetimeand automated action is necessary. But automated systems behavepredictably,andpredictablebehaviourisexploitable. If an attacker can predict that a specific input triggers a specific automated response, they can trigger that response deliberatelyasanattack.We’vespenttimeonthisanddonot have a satisfying answer. As far as we can tell, neither does thecurrentliterature.
The accountability question is the one we think will produce the most visible crisis the soonest. AI-driven security systems are already making decisions about real people- blocking access, flagging accounts, triggering incident response processes that affect careers. When something goes significantly wrong, the question of who is responsible is legally unclear in most jurisdictions. That ambiguity diffuses accountability in ways that make no one actually responsible for systematic errors. That gap will be tested.
We set out to write about technology and ended up writing mostly about institutions. That probably reflects wherethefieldactuallyismoreaccuratelythanweexpected goingin.
The algorithms are good. They have improved substantially over the fifteen years this paper covers. SHAP,

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072
LIME, human-AI collaboration frameworks, and the movement toward enforceable governance represent real progress.Wedonotwanttoundersellthat.
What has not kept pace is the infrastructure around the algorithms. Governance that matches the speed of deployment.Accountabilityframeworksthatcoverdecisions these systems are already making about real people. Postquantum readiness treated as a current priority rather than a future problem. The organizational capacity to audit deployedmodelsforbias.Actualanswerstoquestionsabout autonomousresponsethatcurrentlydonotexist.
AIhasmadecyber security morepowerful onbothsides, more consequential when things go wrong, and fastermoving than any institutional process was designed to handle. It has not made defence easier. The organizations navigating AI-era threats best are not necessarily the ones with the most capable models they are the ones that pair technical capability with genuine governance, invest in human judgment alongside automated detection, and treat institutionalreadinessasasecurityrequirementratherthan acompliancecheckbox.
Both sides will keep getting better tools. The question is whether governance, accountability, and institutional readiness improve at the same rate. Right now, honestly, theyarenot.Thatisthegapthatactuallymatters.
[1] R. Sommer and V. Paxson, "Outside the closed world: On usingmachinelearningfornetworkintrusiondetection," in Proc. 2010 IEEE Symposium on Security and Privacy, Oakland,CA,May2010,pp.305–316.
[2] I. Goodfellow, J. Shlens, and C. Szegedy, "Explaining and harnessing adversarial examples," 2015, arXiv preprint arXiv:1412.6572. [Online]. Available: https://arxiv.org/abs/1412.6572
[3] W. Hu and Y. Tan, "Generating adversarial malware examples for black-box attacks based on GAN," arXiv preprintarXiv:1702.05983,2017.
[4] N. Carlini and D. Wagner, "Audio adversarial examples: Targeted attacks on speech-to-text," in Proc. IEEE Security and Privacy Workshops (SPW), San Francisco, CA,2018,pp.1–7.
[5] H. Anderson, S. Woodbridge, and B. Filar, "DeepDGA: Adversarially-tuned domain generation and detection," in Proc. ACM Workshop on Artificial Intelligence and Security(AISec’16),Vienna,Austria,2016,pp.13–21.
[6] B. Biggio and F. Roli, "Wild patterns: Ten years after the rise of adversarial machine learning," Pattern Recognition,vol.84,pp.317–331,Dec.2018.
[7] L. Demetrio, S. Coull, B. Biggio, G. Lagorio, A. Armando, and F. Roli, "Adversarial EXEmples: A survey and experimental evaluation of practical attacks on machine learning for Windows malware detection," ACM Transactions on Privacy and Security, vol. 24, no. 4, pp. 1–31,2021.
[8] B. Marczak, J. Scott-Railton, S. McKune, B. A. Razzak,and R. Deibert, "Hide and seek: Tracking NSO Group’s Pegasus spyware to operations in 45 countries," The Citizen Lab, Munk School of Global Affairs, Univ. of Toronto, Toronto, Canada, Research Rep., Sep. 2018. [Online]. Available: https://citizenlab.ca/2018/09/hideand-seek-tracking-nso-groups-pegasus-spyware-tooperations-in-45-countries/
[9]C.Cimpanu,"ApplesaysNSOGroup’szero-clickiMessage exploittargetedjournalistsandactivists,"ZDNet,Sep.13, 2021.[Online].Available:https://www.zdnet.com
[10] A. A. Chandio, N. Masood, A. Iqbal, and M. A. Tahir, "Explainableartificialintelligence(XAI)incybersecurity: A comprehensive survey," IEEE Access, vol. 11, pp. 45836–45853,2023.
[11] M. Campos, J. J. Maestre Vidal, and A. F. Skarmeta, "Evaluating the impact of concept drift on machine learning-based network intrusion detection," IEEE Access,vol.8,pp.121567–121584,2020.
[12] N. Kaloudi and J. Li, "The AI-based cyber threat landscape: A survey," ACM Computing Surveys, vol. 53, no.1,article20,pp.1–34,Feb.2020.
[13] Y. Mirsky and W. Lee, "The creation and detection of deepfakes: A survey," ACM Comput. Surv., vol. 54, no. 1, pp.1–41,Jan.2021.
[14] J. Hazell, "Spear phishing with large language models," arXiv preprint arXiv:2305.01247, May 2023. [Online]. Available: https://arxiv.org/abs/2305.01247
[15] S. M. Lundberg and S. Lee, "A unified approach to interpreting model predictions," in Advances in Neural Information Processing Systems (NeurIPS), vol. 30, Long Beach,CA,2017,pp.4765–4774.
[16] M. Jagielski, A. Oprea, B. Biggio, C. Liu, C. Nita-Rotaru, and B. Li, "Manipulating machine learning: Poisoning attacksandcountermeasuresforregressionlearning,"in

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Proc.39thIEEESymposiumonSecurityandPrivacy,San Francisco,CA,2018,pp.19–35.
[17] R. Binns, "Fairness in machine learning: Lessons from political philosophy," in Proc. Conference on Fairness, Accountability and Transparency (FAT*), New York, NY, USA,2018,pp.149–159.
[18] N. Papernot and P. McDaniel, "Privacy and security in the age of machine learning," IEEE Security & Privacy, vol.16,no.3,pp.56–59,May–Jun.2018.
[19] D. Statt, "Fraudsters used AI to mimic a CEO’s voice in unusual cybercrime case," The Wall Street Journal, Aug. 30, 2019. [Online]. Available: https://www.wsj.com/articles/fraudsters-used-ai-tomimic-ceos-voice-in-unusual-cybercrime-case11567157402
[20] European Parliament, "Regulation (EU) 2024/1689 of the European Parliament and of the Council on Artificial Intelligence (Artificial Intelligence Act)," Official Journal of the European Union, L series, Jun. 2024. [Online]. Available: https://eur-lex.europa.eu/legalcontent/EN/TXT/?uri=CELEX:32024R1689
[21] Gartner Inc., "AI for cybersecurity: Key use cases and recommendations for security leaders," Gartner Research,Stamford,CT,USA,WhitePaper,2022.
[22] Kaspersky Lab, "IT threat evolution in Q1 2023: Statistics," Kaspersky Securelist, Moscow, Russia, Quarterly Threat Report, Apr. 2023. [Online]. Available: https://securelist.com/it-threat-evolution-q1-2023statistics/109870/
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072 © 2025, IRJET | Impact Factor value: 8.315 | ISO 9001:2008 Certified Journal | Page1235