[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-125645-en":3,"doc-seo-125645-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},125645,962075006959,"Anda","https://ap-avatar.wpscdn.com/avatar/e0002397efbe92a78e?_k=1776741047341049297",8,"Research & Report","Machine Learning (In) Security - A Stream of Problems - An ML Security Challenges Review","Machine Learning has become central to cybersecurity, yet evaluating ML-driven defenses remains difficult because security-specific challenges often differ from other domains. The work analyzes core obstacles in applying ML to cybersecurity data, focusing on concept drift, adversarial ML, evolution effects, and delayed labels. It also examines how data collection practices influence result quality in security research, arguing for improved strategies and highlighting scenarios where existing solutions can fail. A mitigation-oriented checklist supports future system development.","1  \narXiv :2010 . 16045v2 [ cs .CR] 4 Sep 2023  \nMachine Learning (In) Security: A Stream of Problems  \nFABRÍCIO CESCHIN, Federal University of Paraná, Brazil and Georgia Institute of Technology, USA MARCUS BOTACIN, Texas A&M University, USA  \nALBERT BIFET, University of Waikato, New Zealand BERNHARD PFAHRINGER, University of Waikato, New Zealand LUIZ S. OLIVEIRA, Federal University of Paraná, Brazil  \nHEITOR MURILO GOMES, Victoria University of Wellington, New Zealand ANDRÉ GRÉGIO, Federal University of Paraná, Brazil  \nMachine Learning (ML) has been widely applied to cybersecurity and is considered state-of-the-art for solving many of the open issues in that field. However, it is very difficult to evaluate how good the produced solutions are, since the challenges faced in security may not appear in other areas. One of these challenges is the concept drift, which increases the existing arms race between attackers and defenders: malicious actors can always create novel threats to overcome the defense solutions, which may not consider them in some approaches. Due to this, it is essential to know how to properly build and evaluate an ML-based security solution. In this paper, we identify, detail, and discuss the main challenges in the correct application of ML techniques to cybersecurity data. We evaluate how concept drift, evolution, delayed labels, and adversarial ML impact the existing solutions. Moreover, we address how issues related to data collection affect the quality of the results presented in the security literature, showing that new strategies are needed to improve current solutions. Finally, we present how existing solutions may fail under certain circumstances, and propose mitigations to them, presenting a novel checklist to help the development of future ML solutions for cybersecurity.  \nCCS Concepts: • Security and privacy → Intrusion/anomaly detection and malware mitigation; Systems security;  \nAdditional Key Words and Phrases: machine learning, cybersecurity, data streams  \nACM Reference Format:  \nFabrício Ceschin, Marcus Botacin, Albert Bifet, Bernhard Pfahringer, Luiz S. Oliveira, Heitor Murilo Gomes, and André Grégio.  \n2023. Machine Learning (In) Security: A Stream of Problems. Digit. Threat. Res. Pract. 1, 1, Article 1 (January 2023), 34 pages. [https://doi.org/10.1145/3617897](https://doi.org/10.1145/3617897)  \n1 INTRODUCTION  \nThe massive amount of data produced daily demands automated solutions capable of keeping Machine Learning (ML) models updated and working properly, even with all emerging threats that constantly try to evade these  \nAuthors’ addresses: Fabrício Ceschin, [fjoceschin@inf.ufpr.br](fjoceschin@inf.ufpr.br), Federal University of Paraná, Rua Cel. Francisco H. dos Santos, 100, Curitiba, PR, 81531-980, Brazil and Georgia Institute of Technology, 756 West Peachtree Street NW, Atlanta, GA, 30308-4016, USA; Marcus Botacin, [botacin@tamu.edu](botacin@tamu.edu), Texas A&M University, Department of Computer Science & Engineering, College Station, TX, 77843-3127, USA; Albert Bifet, [abifet@waikato.ac.nz](abifet@waikato.ac.nz), University of Waikato, Department of Computer Science, Waikato, Hamilton,, New Zealand; Bernhard Pfahringer, [bernhard@waikato.ac.nz](bernhard@waikato.ac.nz), University of Waikato, Department of Computer Science, Waikato, Hamilton,, New Zealand; Luiz S. Oliveira, [lesoliveira@inf.ufpr.br](lesoliveira@inf.ufpr.br), Federal University of Paraná, Rua Cel. Francisco H. dos Santos, 100, Curitiba, PR, 81531-980, Brazil; Heitor Murilo Gomes, [heitor.gomes@vuw.ac.nz](heitor.gomes@vuw.ac.nz), Victoria University of Wellington, School of Engineering and Computer Science, Wellington,,, New Zealand; André Grégio, [gregio@inf.ufpr.br](gregio@inf.ufpr.br), Federal University of Paraná, Rua Cel. Francisco H. dos Santos, 100, Curitiba, PR, 81531-980, Brazil.  \nPermission to make digital or hard copies of part or all of this work for personal or classroom use is granted without fee provide","cbCaifdK07h4CkwP","https://ap.wps.com/l/cbCaifdK07h4CkwP","pdf",1498124,1,34,"English","en",105,"# Introduction\n## Concept drift and attacker–defender arms race\n## Evaluating ML-based security solutions\n## Key challenges in ML for cybersecurity data\n## Mitigations and proposed checklist","[{\"question\":\"Why is it difficult to evaluate ML-based solutions in cybersecurity?\",\"answer\":\"Security challenges may not occur in other areas, and attackers continuously create novel threats, making evaluation conditions unstable. This makes it harder to judge whether produced solutions remain effective over time.\"},{\"question\":\"What major ML-related factors are evaluated in the paper?\",\"answer\":\"The analysis covers concept drift, evolution effects, delayed labels, and adversarial ML. These factors shape how existing solutions perform on cybersecurity data streams.\"},{\"question\":\"How can data collection affect the quality of security research results?\",\"answer\":\"Issues in collecting and representing cybersecurity data can degrade the quality of findings in the security literature. The paper argues that new strategies are needed to improve current solutions.\"}]","Machine Learning (In) Security - A Stream of Problems - An ML Security Challenges Review | PDF",1785900391,86,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"machine-learning-in-security-a-stream-of-problems-an-ml-security-challenges-review","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/machine-learning-in-security-a-stream-of-problems-an-ml-security-challenges-review/125645/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-05",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why is it difficult to evaluate ML-based solutions in cybersecurity?","Question",{"text":75,"@type":76},"Security challenges may not occur in other areas, and attackers continuously create novel threats, making evaluation conditions unstable. This makes it harder to judge whether produced solutions remain effective over time.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What major ML-related factors are evaluated in the paper?",{"text":80,"@type":76},"The analysis covers concept drift, evolution effects, delayed labels, and adversarial ML. These factors shape how existing solutions perform on cybersecurity data streams.",{"name":82,"@type":73,"acceptedAnswer":83},"How can data collection affect the quality of security research results?",{"text":84,"@type":76},"Issues in collecting and representing cybersecurity data can degrade the quality of findings in the security literature. The paper argues that new strategies are needed to improve current solutions.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]