Adversarial Robustness in Machine LearningAdvanced Malware Detection TechniquesNetwork Security and Intrusion Detection

David Haunschild, S. Kothari, S. Gill, Steve Uhlig

2026.2.6International Journal of Operations Research and Information Systems

DOI: 10.4018/ijoris.400902

tlooto Summary

This PoC demonstrates a collaborative defense approach suitable for critical infrastructure, such as permissioned mission critical service operators, and durable knowledge sharing under strict compliance requirements, and how independent cloud tenants strengthen local models.

Abstract

The authors propose a proof of concept (PoC) combining Adversarial Machine Learning (AML) for robust local ransomware detection with blockchain to share adversarial threat intelligence (TI) across connectivity networks (air gaps). Using a ransomware dataset in a simulated air gap environment, they show how independent cloud tenants strengthen local models. Achieved through adversarial threat intelligence training and publishing immutable intelligence on new evasion tactics to a shared ledger, Baseline Machine Learning (ML) models are vulnerable to carefully crafted perturbations. Modern Artificial Intelligence (AI) security adversarial TI training greatly enhances robustness. When a tenant adopts blockchain-anchored intelligence produced by another tenant, it gains significant advantages against previously unseen adversarial ransomware. This PoC demonstrates a collaborative defense approach suitable for critical infrastructure, such as permissioned mission critical service operators, and durable knowledge sharing under strict compliance requirements.

Citation format

HAUNSCHILD, David, et al. Blockchain-enabled adversarial threat intelligence sharing for robust ransomware detection in air gaps. International Journal of Operations Research and Information Systems, 2026, 17(1): 1–18.