CORTEXA
← Browse
arxivcs.NI2026-07-01

Data-driven mitigation of catastrophic forgetting in dynamic physical layer attack detection

Aleksandra Knapińska, Marija Furdek

Optical networks are critical infrastructure that underpins global communications, and detecting security breaches that jeopardize them is essential to maintaining worldwide connectivity. As malicious actors continuously evolve their attack techniques, dynamically updated intrusion detection models have become a key component of modern defense mechanisms. By incorporating newly acquired telemetry data, these models can adapt to emerging threats while maintaining high detection performance. However, when previously encountered attacks reappear after a prolonged period of absence, adaptive models may fail to recognize them due to the phenomenon of catastrophic forgetting. In contrast, statically trained models can reliably detect attacks represented in the original training data but lack the ability to adapt to previously unseen attack patterns. Consequently, intrusion detection systems face a fundamental tradeoff between adaptability to evolving threats and long-term retention of previously acquired knowledge. In this work, we propose a data-driven mechanism to cope with catastrophic forgetting in dynamic attack detection systems. Our approach balances the model update datasets by using parts of past attack data. We utilize a threshold-based mechanism to trigger data balancing after accuracy drops due to an active attack change. Applied to an experimental optical network security dataset, the proposed approach reduces the average model adaptation time by 37% compared to its dynamic counterpart that does not employ data balancing. Compared to a baseline from the literature that relies on neural network depth increasing, our approach requires 6% fewer data batches to adapt to changing conditions and regain performance.

View free PDFSource page

Related papers

arxivcs.ITcs.CRcs.GTcs.LGcs.NI2026-07-07

6G Sensing Security: Distributed Game-Theoretic RL for Urban Beamforming and Attacker Detection

Parmida Geranmayeh, Onur Günlü

In next-generation networks, communication systems will no longer be limited to data transmission and will be expected to acquire awareness of the surrounding environment. This leads to the concept of integrated sensing and communication (ISAC), where the same wireless infrastruc…

View free PDFSource page
arxivcs.NI2026-07-01

SNR-Adaptive Optimal Threshold Design for Energy Detection in Dynamic Spectrum Access

Sushila Dhaka, Jane-Hwa Huang, Chin-Min Yu, Li-Chun Wang

This paper proposes an SNR-adaptive optimal threshold design framework for energy detection in Dynamic Spectrum Access (DSA). Unlike conventional constant false-alarm rate (CFAR)-based schemes that determine the sensing threshold solely from a predefined false-alarm constraint, t…

View free PDFSource page
arxivcs.NI2026-07-23

Out-of-Distribution Detection in Wireless Multimodal Foundation Models for 6G ISAC

Mohammad Farzanullah, Akram Bin Sediq, Ali Afana, Melike Erol-Kantarci

The integration of Foundation Models (FMs), such as the Wireless Multimodal Foundation Model (WMFM), into 6G networks provides a unified framework for Integrated Sensing and Communication (ISAC), leveraging generalized representations to simultaneously optimize data transmission…

View free PDFSource page
arxivcs.NIcs.AI2026-07-01

Fully Unsupervised Detection of Physical Contacts on Subsea Cables via State-of-Polarization Monitoring

Agastya Raj, Alvaro Doval, Tian Tian, Steinar Bjørnstad, Marco Ruffini

We present a fully unsupervised Fast-Slow DSVDD detector for continuous State-of-Polarization monitoring on a deployed subsea cable. Trained without event labels, it ranks all five confirmed trawler contacts within the top 13 of 122,174 recordings and surfaces additional corrobor…

View free PDFSource page
arxivcs.NIcs.AIcs.CRcs.MA2026-06-29

COHORT: Collaborative Orchestration for Hardening via Offensive Replay on Emulated Topologies

Chen Frydman, Aviram Zilberman, Rubin Krief, Abed Showgan, Andres Murillo, Sekiya Motoyoshi, et al.

Mitigating an observed adversary in an enterprise network typically takes weeks of expert work: an analyst derives a mitigation tailored to that adversary, validates it without breaking production, and verifies it disrupts the specific attack. The procedure relies on expert judgm…

View free PDFSource page