Suhrobjon Bozorov · Zenodo (CERN European Organization for Nuclear Research) 2026 · 2026
DOI: 10.5281/zenodo.22930218
Counts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
Research on the security of machine-learning network defense treats the detector as the object under attack. A system that also acts - installing enforcement rules, resetting sessions, quarantining endpoints and revising its own policy from observed outcomes - acquires an attack surface of its own, and that surface is neither enumerated nor measured across most of the literature. This paper analyses an eight-agent detect-and-respond architecture with evidence-theoretic fusion and a reinforcement-learned response policy as a target rather than a defense. Ten threats are enumerated across four surfaces - the evidence path, the coordination bus, the learning path and the enforcement plane - each mapped to an architectural control and to a stated residual risk. Three findings follow: under constrained protocol-valid perturbation the dominant failure mode is displaced rather than removed, reliability discounting bounds agent compromise only asymptotically, and finally, the conflict gate introduces a failure mode of its own: Each control bounds its threat; none eliminates one, and one creates a new one.
No comments yet — start the discussion below.