Papers

  1. 2026

    MCP-in-SOS: Measuring the Security Posture of Open-Source MCP Servers Accepted

    Pratyay Kumar*, Miguel Antonio Guirao Aguilera*, Srikathyayani Srikanteswara, Abu Saleh Md Tayeen, Satyajayant Misra

    IEEE ICNP 2026 Workshop on Networking Foundations for Autonomous Agents (AgentNet) · * Equal contribution

    arXiv v1 is an earlier version with a different title and author order.

    MCP-in-SOS assesses the security of open-source Model Context Protocol (MCP) servers, which connect AI agents to tools and data. The study combines static analysis of 1,186 repositories with dynamic testing of 154 live servers. It maps findings to known weakness classes (CWE) and attack patterns (CAPEC) and prioritizes them for manual review. Review of the highest-risk findings confirmed 68 vulnerabilities in 32 repositories; 72% of the confirmed vulnerabilities involved server-side request forgery (SSRF). Confirmed cases are being reported to maintainers through coordinated disclosure. The static-analysis queries, weakness taxonomy, and validation data are public.

    arXiv v1Code and data
  2. 2026

    Generative AI and Federated Learning for Intrusion Detection Systems: A Survey Preprint

    Jiefei Liu, Abu Saleh Md Tayeen, Pratyay Kumar, Qixu Gong, Wenbin Jiang, Huiping Cao, Satyajayant Misra, Jayashree Harikumar

    arXiv:2607.01305 [cs.CR]

    This survey reviews generative AI and federated learning for intrusion detection, covering model families, data scarcity, class imbalance, privacy, and evaluation. It examines the usefulness of synthetic traffic and the limits of assessing it through statistical similarity alone.

    arXiv v1
  3. 2026

    NetDiffuser: Deceiving DNN-Based Network Attack Detection Systems with Diffusion-Generated Adversarial Traffic Preprint

    Pratyay Kumar, Abu Saleh Md Tayeen, Satyajayant Misra, Huiping Cao, Jiefei Liu, Qixu Gong, Jayashree Harikumar

    arXiv:2603.08901 [cs.CR]

    NetDiffuser uses diffusion models to generate adversarial flow features for evaluating deep-learning intrusion detectors. Across three benchmark datasets and several model architectures, it increased attack success rates by up to 29.93 percentage points compared with baseline attacks. It also reduced the AUC-ROC of adversarial-example detectors by up to 0.534.

    arXiv v1
  4. 2025

    NetPrompt: Evaluation of LLMs as Network Intrusion Detection System

    Pratyay Kumar, Abu Saleh Md Tayeen, Qixu Gong, Jiefei Liu, Satyajayant Misra, Huiping Cao, Jayashree Harikumar

    IEEE Military Communications Conference (MILCOM 2025)

    NetPrompt evaluates three large language models (LLMs) as network intrusion detectors using prompting alone, without task-specific fine-tuning. It represents network flows as text, compares prompting strategies, and uses iCentroid to select representative examples for each traffic class. These examples improved performance, but results varied by dataset: the strongest LLM tested outperformed a multilayer perceptron (MLP) baseline on CICDDoS2019 and performed worse on CICIDS2017.

    PaperCode
  5. 2025

    Is Synthetic Flow Data from Generative Models Ready for Network Intrusion Detection Systems?

    Jiefei Liu, Qixu Gong, Wenbin Jiang, Pratyay Kumar, Abu Saleh Md Tayeen, Huiping Cao, Satyajayant Misra, Jayashree Harikumar

    IEEE MILCOM 2025 Workshop on Security, Resilient, and Robustness of Systems and Software

    This study tests whether synthetic network flows generated by CTGAN, TabDDPM, and the LLM-based GReaT can train intrusion detectors to classify real traffic. Detectors trained on synthetic flows are evaluated on held-out real data from UNSW-NB15, CICIDS2017, and CICDDoS2019. Performance varied by dataset and attack class. LLM-generated flows improved detection for several minority classes, but extreme class imbalance remained difficult for all three methods.

    Paper
  6. 2025

    NeTIF: Network Traffic to Image Features for Robust Intrusion Detection

    Stephen Villanueva, Abu Saleh Md Tayeen, Qixu Gong, Satyajayant Misra, Aden Dogar, Huiping Cao, Jiefei Liu, Pratyay Kumar, Jayashree Harikumar

    IEEE MILCOM 2025 Workshop on Security, Resilient, and Robustness of Systems and Software

    NeTIF groups packets into flows and converts their header and payload bytes into image-like representations for a lightweight convolutional neural network (CNN). On CICIDS2017 and UNSW-NB15, it improved detection compared with the evaluated baselines. Its intermediate CNN features can also be visualized.

    Paper
  7. 2023

    Multi-Model-Based Federated Learning to Overcome Local Class Imbalance Issues

    Jiefei Liu, Huiping Cao, Abu Saleh Md Tayeen, Satyajayant Misra, Pratyay Kumar, Jayashree Harikumar

    IEEE International Conference on Machine Learning and Applications (ICMLA 2023)

    Multi-model federated learning (MMFL) addresses local class imbalance in intrusion detection, where clients observe different proportions of traffic classes. It automatically groups similar local models, applies a new data augmentation method, and combines model predictions through majority voting. In experiments on two large intrusion detection datasets, it outperformed five baselines.

    PaperCode
  8. 2023

    FLNET2023: Realistic Network Intrusion Detection Dataset for Federated Learning

    Pratyay Kumar, Jiefei Liu, Abu Saleh Md Tayeen, Satyajayant Misra, Huiping Cao, Jayashree Harikumar, Oscar Perez

    IEEE Military Communications Conference (MILCOM 2023)

    FLNET2023 is a dataset for federated intrusion detection, with normal and attack traffic collected at ten routers in the 40-router GEANT-2012 topology emulated in CORE. It preserves differences in traffic volume and the absence of some attack classes at individual routers. These differences reveal accuracy and convergence problems that local class imbalance can cause in federated detection.

    PaperDataset