<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Ethical Problems and Legal Issues in Development and Usage Autonomous Adversaries in Cyber Domain</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Corresponding Author: Muhammad Mudassar Yamin</string-name>
          <email>muhammad.m.yamin@ntnu.no</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Department of Information Security</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>, and Basel KATT Department of Information Security and Communication Technology, Norwegian University of Science and Technology</institution>
          ,
          <country country="NO">Norway</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Communication Technology, Norwegian University of Science and Technology</institution>
          ,
          <addr-line>Gjovik 2815</addr-line>
          ,
          <country country="NO">Norway</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>Muhammad Mudassar YAMIN</institution>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2018</year>
      </pub-date>
      <abstract>
        <p>An autonomous adversaries in cyber domain are new type of adversaries present in a cyber security exercise. Traditionally, adversaries in cyber security exercises are human who perform the roles of attackers and defenders. However, this is changing with time and autonomous adversaries are starting to appear in the cyber domain. The aim of this survey paper is to provide an overview of autonomous adversaries in cyber domain, furthermore ethical problems and legal issues related with the development and the usage of autonomous adversaries in cyber domain will be discussed.</p>
      </abstract>
      <kwd-group>
        <kwd />
        <kwd>Autonomous adversaries</kwd>
        <kwd>cyber domain</kwd>
        <kwd>ethics problems</kwd>
        <kwd>legal issues</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        A cyber security exercise, is an exercise that is designed to evaluate the performance of
cyber attackers an and defenders in a given scenario. The cyber security exercise life
cycle contains planning, dry run, execution, evaluation and repetitions. We identified that
the cyber security exercise life cycle is quite inefficient [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ] and found out that one
way to remove these inefficiencies can be achieved by autonomous execution of
adversaries present in a cyber security exercise. However, before the development of such
autonomous adversaries we want to identify the type of ethical problems and legal issues
posed by such research. In order to understand the ethical problems and legal issues
associated with autonomous adversaries, first, we need to understand the types of
autonomous systems. We identified three types [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ] of autonomous system in the literature,
details of which are given below:
      </p>
      <sec id="sec-1-1">
        <title>Supervised Autonomous Systems</title>
        <p>Autonomous systems that operate under the supervision of a human, the system
is depended on human decision making for changing mission requirements. This
system works in an human in the loop manner.</p>
        <p>We used autonomous cyber weapon as a synonym for autonomous cyber adversary as
the literature offered more material on autonomous cyber weapon, however it should be
noted that a weapon can be used for offence as well as defence, thus, creating an
adversarial environment. The rest of the paper is structured as follows. We first share the
related work related to autonomous weapon systems. Then, we highlight the methodology
which we use for the brief survey. After that we discuss the current status of autonomous
adversary and the ethical and legal issues identified in the literature. finally we analyze
the identified findings to answer the above stated questions and conclude the article.</p>
      </sec>
    </sec>
    <sec id="sec-2">
      <title>2. Related Work</title>
      <p>
        During the survey no related work focusing on our research topic was identified. Yet we
identified a multitude of survey articles related to ethical and legal issues and challenges
in cyber warfare and autonomous unmanned vehicles which are closely related to our
research topic. Robinson et al. [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ] in 2015 discussed ethical and legal issues in usage of
autonomous cyber weapons in cyber warfare from a technical prospective. According to
him, automating cyber offensive and defensive capability is a likely possibility for
nation states. He highlighted the research from Caton et al. [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ] according to which
”automated cyber weapons remove human decision making and could turn a bad situation
into a catastrophic one”. However, the problems which will arise by autonomous cyber
weapons need to be tackle by a multidisciplinary research efforts from different doamins
like laws, ethics and computer science.
      </p>
      <p>
        Schuller et al. [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ] in 2015 discussed the development and usage of autonomous
weapons’ systems with respect to international humanitarian laws. According to the
authors ”Autonomous weapon systems (AWS) are the most militarily significant yet legally
elusive challenge to international humanitarian law (IHL) since the proliferation of
cyber operations”. Authors argued that the artificial intelligence and learning capabilities
of these systems are quite different compare to traditional weapon systems. This creates
new legal requirements for governing the development and usage of such system.
Authors further elaborated that the commonalities of traditional and autonomous weapon
systems can be governed under the same laws, however, the principles upon which the
law is applied on traditional and autonomous weapon system will be quite different.
      </p>
      <p>
        Lucas et al. [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ] in 2014 discussed the legal and ethical precepts of emerging
military technologies. The emerging military technologies include autonomous weapons.
The researchers answered eleven precepts on the development and usage of autonomous
weapons systems.
researchers concluded that in case of a conflict where usage of traditional weapons are
justifiable by law, the justification will extend to not just traditional weapons but cyber
      </p>
    </sec>
    <sec id="sec-3">
      <title>3. Methodology</title>
      <p>weapons as well. In comparison to traditional weapons, cyber weapons provides a non
lethal force enhancement capability which limits collateral damage. If the results of both
cyber weapon and traditional weapons are equivalent the the usage of cyber weapons in
obligatory.</p>
      <p>
        To identify relevant literature for the survey, keyword based search is used. We started
with ”autonomous cyber weapons”, ”autonomous cyber weapons” with ”ethics” and
”autonomous cyber weapons” with ”laws”. We searched these keywords in academic
databases like IEEE and ACM [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ] to identify initial literature for the survey. After the
initial collection of literature, we realized that the topics fall into interdisciplinary filed
of study. Therefore we used Google scholar to relevant literature for relevant disciplines
like defence and law. Although we identified many relevant material during the research
we only used indexed research articles. We performed the collection of literature with
keyword based search, however, repeating the same process will not yield the same
results [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ]. Therefore we are including the inclusion and exclusion criteria of research
articles, to reduce the variation of results in literature searching.
      </p>
      <sec id="sec-3-1">
        <title>3.1. Inclusion Criteria</title>
        <sec id="sec-3-1-1">
          <title>We set the following inclusion criteria to for the survey:</title>
        </sec>
        <sec id="sec-3-1-2">
          <title>Articles written in English Articles directly related to autonomous cyber weapons. Articles that addresses ethical or legal, issues and challenges in usage of autonomous cyber weapons.</title>
        </sec>
      </sec>
      <sec id="sec-3-2">
        <title>3.2. Exclusion Criteria</title>
        <p>Due to large amount of identified literature we set the following exclusion criteria:
Articles that mentions autonomous cyber weapons but are not directly related to
them.</p>
        <p>Conference abstracts, book reviews, conference info, discussion, editorials, mini
reviews, news and short communications.</p>
      </sec>
      <sec id="sec-3-3">
        <title>3.3. Quality of Articles</title>
        <p>The collected articles were evaluated against our defined criteria five quality assurance
matrices. Points are allocated on a scale of one to five where five is considered as the
highest value. The articles which scored the most on our defined criteria are given
priority. The criteria which we used is given below:</p>
        <p>Reputation of publication channel, publication channels which are well known
and recognized by academia scored higher in our criteria.</p>
        <p>Citation of article, articles with more citations given higher score in our criteria.</p>
        <p>Relevance of article content related to survey topic</p>
        <p>Publication date of articles, recently published articles received higher score
compare to older articles.</p>
        <p>Number of references used to build the arguments in the article, articles scored
higher with more references</p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>4. Autonomous Cyber Adversaries</title>
      <p>In this section we present the unclassified autonomous cyber adversaries that we
identified in the literature. We identified two types of autonomous adversaries, one performs
offensive cyber security operation, while the other performs defensive cyber security
operation. Details of both are given below:</p>
      <sec id="sec-4-1">
        <title>4.1. Offensive Autonomous Cyber Adversaries</title>
        <p>
          SC2RAM [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ]
SC2RAM (Simulated Cognitive Cyber Red-team Attacker Model) is developed
to mimic the red team execution steps in a cyber security-exercise. It combines
the cognitive capabilities of humans with the efficiency and reproduce-ability of
a computer program. It can perform DoS (Denial-of-Service) attack on a given
network. It is still at prototyping stage and is deployed at Michigan cyber-range
and being used for testing and training purposes.
        </p>
        <p>
          SVED [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ]
SVED (Scanning, Vulnerabilities, Exploits and Detection) utilizes freely
available exploit tools such as metasploit and nmap and automate their operations to
execute red team activities autonomously in a cyber security exercise. SVED is
deployed at CRATE cyber range and used for testing and training purposes.
Stuxnet [
          <xref ref-type="bibr" rid="ref12">12</xref>
          ]
Stuxnet was the most advance cyber weapon ever used in a military engagement.
It is a piece of malware, that once injected in the target autonomously spread
and compromise the whole network. It was designed to physically destroy the
assigned military target by exploiting vulnerability in cyber physical infrastructure.
        </p>
      </sec>
      <sec id="sec-4-2">
        <title>4.2. Defensive Autonomous Cyber Adversaries</title>
        <sec id="sec-4-2-1">
          <title>Intelligent Autonomous Agents for Cyber Defense [13]</title>
          <p>Researchers at United State army research laboratory proposed a model of an
intelligent autonomous cyber defender. According to the proposed model the agent
should be able to understand the environment in which it is operating. The agent
should be able to identify malicious and non malicious changes in the
environment and should autonomously act upon malicious change. The agent should be
able to manage trust relationship with other operating agents and humans through
a communication medium. Finally, the agent need to asses its performance and
make necessary changes in its operating behavior to improve the performance for
achieving the set objectives.</p>
          <p>
            Immuno-Inspired Autonomic System for Cyber Defense [
            <xref ref-type="bibr" rid="ref14">14</xref>
            ]
A human immune system inspired automatic cyber defense model, that change
systems security settings based upon evolving threats. The system is
conceptualized to be fully autonomous in nature and able to with stand current and new
cyber attacks by adapting to the security challenges posed by evolving threats.
VIAssist [
            <xref ref-type="bibr" rid="ref15">15</xref>
            ]
A cyber security defender assistant that collects and visualizes data related to
cyber security events. It automates the cognitive function required to analyze cyber
security event data and presents the processed information to human defender to
make final decision on the cyber security event.
          </p>
          <p>Autonomous cyber adversaries are similar autonomous physical weapons, however they
operates on the junction of cyber physical space. The action in cyber space have
consequences in physical space, therefore we consider the existing ethical problem and legal
issues for autonomous weapons systems to map it with autonomous cyber adversaries.</p>
        </sec>
      </sec>
    </sec>
    <sec id="sec-5">
      <title>5. Ethical Problems</title>
      <p>What is ethically acceptable for the usage of autonomous cyber adversaries? Which
principals govern the morality in development of autonomous cyber adversaries? We
analyzed ongoing research to answer these questions. We first describe the ethical
foundation of using autonomous weapons systems. After that we analyze the military impact of
such systems. Finally we focus on there effects of cyber operations.</p>
      <p>
        International organization and research institutes have put significant efforts in
determining the ethical foundation of development and usage of autonomous weapon
systems. One such effort is led by joint efforts of Human Rights Watch (HRW), International
Human Rights Council (IHRC), and Harvard Law School. Since November 2012, these
efforts produced three detailed reports regarding the threats presented by ”autonomous
weapons systems”. They characterize it as completely autonomous weapons with human
out of the loop that ”have the capacity to identify and engage with their target without
significant human intervention. Their first report, Losing Humanity: The Case against Killer
Robots(November 2012) [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ] forms a case for the likelihood of autonomous weapon
systems getting to be reality within 20 to 30 years also as an earnestness for their
suggestion for suitable national and worldwide measures to forbid the advancement,
development, and usage of completely autonomous weapons. The second report Shaking the
Foundations, The Human Rights Implications of Killer Robots(May 2014) [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ] stresses
the moral ideas of human dignity and respect of human life. There report concludes that,
fully autonomous weapon systems would not respect human life and dignity. The failure
to maintain this basic guideline of human rights brings up genuine concern about the
possibility of enabling a autonomous weapons to take a human life. The third and latest
report, Mind the Gap: The Lack of Accountability for Killer Robots [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ] (April 2015)
concludes that the developers and operators of autonomous weapons system that breaks
the laws should be held accountable for their actions.
      </p>
      <p>
        The 2014 NATO Allied Command Transformation report on utilization of
autonomous weapon system [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ] discussed the moral issues of using autonomous weapon
in the military. They concluded that the use of autonomous weapons system provides a
unique opportunity to reduce risk to human life by not putting a human being in line of
fire. It boost the moral of the fighting force by providing disposable alternative resources
to conduct risky operations. Furthermore, autonomous weapons systems doesn’t suffers
from the psychological stress caused by critical military tasks. Although some of these
weapons do not kill directly humans, they can attack infrastructures that in a longer term
can, indirectly, cause great human damage and sufferings.
      </p>
      <p>
        Stuxnet [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ] is the perfect example of a autonomous cyber weapon usage. Stuxnet
was designed to destroy the uranium enrichment centrifuges of Iranian nuclear plants.
Achieving this feat physically would have required deployment military personals in
hostile territory. This could put human life in danger. However, with Stuxnet this feat
is achieved without firing a single bullet. Stuxnet was the first known usage of a cyber
physical weapons, it performed its intended mission, however, during its execution it also
affected multiple civilian targets which raise the requirements for ethical conduct of such
weapons under international law which. Similarly when cyber weapons are leaked they
were used by adversaries and cyber criminals for monitory gains [
        <xref ref-type="bibr" rid="ref21">21</xref>
        ].
      </p>
    </sec>
    <sec id="sec-6">
      <title>6. Legal Issues</title>
      <p>What is legally acceptable for the usage of autonomous cyber adversaries? Which laws
governs the development of autonomous cyber adversaries? We analyzed ongoing
research to answers these questions. We first analyzed the international laws available to
govern the development of autonomous cyber adversaries. Secondly we analyzed United
nations assessment on proliferation and development of autonomous cyber adversaries.
Finally, we focus on the human factor in usage and control of autonomous adversaries.</p>
      <p>
        Autonomous weapons creates a moral asymmetry between the two adversaries and
according to Lucas [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ] there is no requirement of fairness or technological equality in
carrying out justified international armed conflict or lawful domestic security operations.
He argued that International Security Assistance Force (ISAF) is fighting a vastly
technologically inferior adversary in Afghanistan, which is acceptable by international law.
The technological superiority provide distinct advantages over the potential adversaries
which resulted in proliferation advance weapons capabilities. This led to development of
autonomous weapons for physical and cyber space.
      </p>
      <p>
        United Nation member states that signed Convention on Certain Conventional
Weapons (CCW) a treaty for eliminating munitions that are considered as inhuman, are
working on to assessment of the threats and dangers posed by autonomous weapons
systems [
        <xref ref-type="bibr" rid="ref19">19</xref>
        ]. In their most recent Group of Governmental Experts (GGE) meeting in Aug
2018 Geneva, all members agreed that humans should always retain the control of
autonomous weapon systems. However they failed to reach an agreement for the
achievement of this objective. They agreed on further discussion on this topic in next GGE
meeting in 2019.
      </p>
      <p>
        Autonomous decision of engagement with a target will pose significant legal
concerns. In SC2RAM [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ] the cognitive decision making ability of an attacker is mapped in
to a computer program, which makes independent decision in achieving the target set by
a human. The implications of those decisions need to be considered before the usage of
such autonomous weapon. This technology is currently being used only for testing and
training purposes however this technology has the potential to be used in actual cyber
engagements if required. Red Cross in there 2016 report on autonomous weapons [
        <xref ref-type="bibr" rid="ref20">20</xref>
        ]
discussed the autonomy of weapons systems in lethal engagement of targets. According
to Red Cross such technology is not deployed yet in theater of war but the technology is
certainly not out of the reach.
      </p>
    </sec>
    <sec id="sec-7">
      <title>7. Analysis</title>
      <sec id="sec-7-1">
        <title>7.1. Current Status</title>
        <p>Details of current status of autonomous cyber adversaries are shared in section 4.
Currently, offensive autonomous cyber adversaries are being rapidly developed, and used for
training, testing and exploitation purposes. On the other hand, most of the research for
defensive autonomous adversaries is at designing stage. Most of the current research is
funded by milliliters around the world for the achievement of technological edge over
their human adversaries</p>
      </sec>
      <sec id="sec-7-2">
        <title>7.2. Legal Status</title>
        <p>
          Development and usage of autonomous cyber adversaries are currently in a legal gray
area. There is currently no law exists that explicitly prohibits the development and usage
of such technologies [
          <xref ref-type="bibr" rid="ref19">19</xref>
          ]. International efforts are being carried out to reach a consensus
on regularizing the proliferation of such weapons, however, no common ground on this
issue is achieved yet [
          <xref ref-type="bibr" rid="ref19">19</xref>
          ] [
          <xref ref-type="bibr" rid="ref4">4</xref>
          ].
        </p>
      </sec>
      <sec id="sec-7-3">
        <title>7.3. Ethical Guideline</title>
        <p>
          Autonomous cyber weapons provide unique opportunity in reducing human suffering by
achieving the desired military objective in a non lethal way [
          <xref ref-type="bibr" rid="ref5">5</xref>
          ]. However, such weapons
decrease the threshold of a conflict between adversaries [
          <xref ref-type="bibr" rid="ref13">13</xref>
          ]. Therefore, the usages
should be governed by ethical and moral guidelines where commonalities with other
weapons systems exists [
          <xref ref-type="bibr" rid="ref6">6</xref>
          ]. Human dignity and respect of human life should be given
up-most priority while using such technologies [
          <xref ref-type="bibr" rid="ref17">17</xref>
          ].
        </p>
      </sec>
      <sec id="sec-7-4">
        <title>7.4. Civil Liabilities and Unintended Consequences</title>
        <p>
          Autonomous weapons system developers are responsible for unintended consequences
of the autonomous system functionality and the autonomous weapon system user is
responsible for criminal negligence [
          <xref ref-type="bibr" rid="ref7">7</xref>
          ]. The consensus of international community
established that the decision making of a autonomous system should always be governed by
human [
          <xref ref-type="bibr" rid="ref19">19</xref>
          ].
        </p>
      </sec>
    </sec>
    <sec id="sec-8">
      <title>8. Conclusion</title>
      <p>From the above analysis it can be concluded that there is no legal restriction in
development of autonomous adversaries. However, the developers of such systems are liable for
any intended consequence of such technologies. Similarly user are of such technologies
are liable for any kind of criminal negligence in there operation. International consensus
is already established that any kind of fully autonomous weapon system with human out
of the loop is not acceptable. However, a philosophical question is still open for further
research: Do we wants to develop autonomous machine slaves that blindly follows
human orders or do we want to develop autonomous machine that question the ethics and
morality of human orders ?</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <surname>Vykopal</surname>
          </string-name>
          ,
          <string-name>
            <surname>Jan</surname>
          </string-name>
          , et al. ”
          <article-title>Lessons learned from complex hands-on defence exercises in a cyber range.” Frontiers in Education Conference (FIE)</article-title>
          . IEEE,
          <year>2017</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>Uckan</given-names>
            <surname>Frnman</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            ,
            <surname>Koraeus</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            , and
            <surname>Backman</surname>
          </string-name>
          ,
          <string-name>
            <surname>S.</surname>
          </string-name>
          (
          <year>2015</year>
          ).
          <source>The 2015 Report on National and International Cyber Security Exercises: Survey, Analysis and Recommendations.</source>
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <surname>Anderson</surname>
            ,
            <given-names>J. M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Arbour</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Arnold</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kadiofsky</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Keeley</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>MacLeod</surname>
            ,
            <given-names>M. R.</given-names>
          </string-name>
          , ... and
          <string-name>
            <surname>Roorda</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          (
          <year>2015</year>
          ).
          <article-title>Autonomous Systems: Issues for Defence Policymakers. NATO SUPREME ALLIED COMMAND TRANSFORMATION NORFOLK VA NORFOLK</article-title>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <surname>Robinson</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Jones</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          , and
          <string-name>
            <surname>Janicke</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          (
          <year>2015</year>
          ).
          <article-title>Cyber warfare: Issues and challenges</article-title>
          .
          <source>Computers and security</source>
          ,
          <volume>49</volume>
          ,
          <fpage>70</fpage>
          -
          <lpage>94</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <surname>Caton</surname>
            ,
            <given-names>J. L.</given-names>
          </string-name>
          (
          <year>2013</year>
          , June).
          <article-title>Exploring the prudent limits of automated cyber attack</article-title>
          .
          <source>In Cyber conflict (CyCon)</source>
          ,
          <year>2013</year>
          5th international conference on Cyber conflict (pp.
          <fpage>1</fpage>
          -
          <lpage>16</lpage>
          ). IEEE.
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <surname>Schuller</surname>
            ,
            <given-names>A. L.</given-names>
          </string-name>
          (
          <year>2017</year>
          ).
          <article-title>At the crossroads of control: The intersection of artificial intelligence in autonomous weapon systems with international humanitarian law</article-title>
          .
          <source>Harv</source>
          .
          <string-name>
            <surname>Nat'l Sec</surname>
          </string-name>
          . J.,
          <volume>8</volume>
          ,
          <fpage>379</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>Lucas</given-names>
            <surname>Jr</surname>
          </string-name>
          ,
          <string-name>
            <surname>G. R.</surname>
          </string-name>
          (
          <year>2014</year>
          ).
          <article-title>Legal and ethical precepts governing emerging military technologies: Research and use</article-title>
          .
          <source>Amsterdam LF</source>
          ,
          <volume>6</volume>
          ,
          <fpage>23</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <surname>Jesson</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Matheson</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          , and
          <string-name>
            <surname>Lacey</surname>
            ,
            <given-names>F. M.</given-names>
          </string-name>
          (
          <year>2011</year>
          ).
          <article-title>Doing your literature review: Traditional and systematic techniques</article-title>
          .
          <source>Sage.</source>
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <surname>Kitchenham</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Brereton</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Li</surname>
            ,
            <given-names>Z.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Budgen</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          , and
          <string-name>
            <surname>Burn</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          (
          <year>2011</year>
          , April).
          <article-title>Repeatability of systematic literature reviews</article-title>
          .
          <source>In Evaluation and Assessment in Software Engineering (EASE</source>
          <year>2011</year>
          ), 15th Annual Conference on (pp.
          <fpage>46</fpage>
          -
          <lpage>55</lpage>
          ). IET.
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <surname>Jones</surname>
            ,
            <given-names>R. M.</given-names>
          </string-name>
          ,
          <string-name>
            <given-names>OGrady</given-names>
            , R.,
            <surname>Nicholson</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            ,
            <surname>Hoffman</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            ,
            <surname>Bunch</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            ,
            <surname>Bradshaw</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            , and
            <surname>Bolton</surname>
          </string-name>
          ,
          <string-name>
            <surname>A.</surname>
          </string-name>
          (
          <year>2015</year>
          ).
          <article-title>Modeling and integrating cognitive agents within the emerging cyber domain</article-title>
          .
          <source>In Proceedings of the Interservice/Industry Training, Simulation, and Education Conference (I/ITSEC)</source>
          (Vol.
          <volume>20</volume>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <surname>Holm</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          , and
          <string-name>
            <surname>Sommestad</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          (
          <year>2016</year>
          , November).
          <article-title>Sved: Scanning, vulnerabilities, exploits and detection</article-title>
          . In Military Communications Conference,
          <string-name>
            <surname>MILCOM</surname>
          </string-name>
          <year>2016</year>
          -2016 IEEE (pp.
          <fpage>976</fpage>
          -
          <lpage>981</lpage>
          ). IEEE.
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <surname>Langner</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          (
          <year>2011</year>
          ).
          <article-title>Stuxnet: Dissecting a cyberwarfare weapon</article-title>
          .
          <source>IEEE Security and Privacy</source>
          ,
          <volume>9</volume>
          (
          <issue>3</issue>
          ),
          <fpage>49</fpage>
          -
          <lpage>51</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <surname>Kott</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Thomas</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Draar</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kont</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Poylisher</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Blakely</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          , ... and
          <string-name>
            <surname>Rigaki</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          (
          <year>2018</year>
          ).
          <source>Toward Intelligent Autonomous Agents for Cyber Defense: Report of the 2017 Workshop by the North Atlantic Treaty Organization (NATO) Research Group IST-152-RTG</source>
          . arXiv preprint arXiv:
          <year>1804</year>
          .07646.
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <surname>Dasgupta</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          (
          <year>2007</year>
          ).
          <article-title>Immuno-inspired autonomic system for cyber defense</article-title>
          .
          <source>information security technical report</source>
          ,
          <volume>12</volume>
          (
          <issue>4</issue>
          ),
          <fpage>235</fpage>
          -
          <lpage>241</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <surname>Goodall</surname>
            ,
            <given-names>J. R.</given-names>
          </string-name>
          , and
          <string-name>
            <surname>Sowul</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          (
          <year>2009</year>
          , May).
          <article-title>VIAssist: Visual analytics for cyber defense</article-title>
          .
          <source>In Technologies for Homeland Security</source>
          ,
          <year>2009</year>
          . HST'09. IEEE Conference on (pp.
          <fpage>143</fpage>
          -
          <lpage>150</lpage>
          ). IEEE.
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <surname>Docherty</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          (
          <year>2012</year>
          ).
          <article-title>Losing humanity: The case against killer robots</article-title>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <surname>Docherty</surname>
            ,
            <given-names>B. L.</given-names>
          </string-name>
          (
          <year>2014</year>
          ).
          <article-title>Shaking the Foundations: The Human Rights Implications of Killer Robots. Human Rights Watch</article-title>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <surname>Docherty</surname>
            ,
            <given-names>B. L.</given-names>
          </string-name>
          (
          <year>2015</year>
          ).
          <article-title>Mind the gap: The lack of accountability for killer robots</article-title>
          .
          <source>Human Rights Watch.</source>
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <surname>Bode</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          , and
          <string-name>
            <surname>Huelss</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          (
          <year>2018</year>
          ).
          <article-title>Autonomous weapons systems and changing norms in international relations</article-title>
          .
          <source>Review of International Studies</source>
          ,
          <volume>1</volume>
          -
          <fpage>21</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <surname>Righetti</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Pham</surname>
            ,
            <given-names>Q. C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Madhavan</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          , and
          <string-name>
            <surname>Chatila</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          (
          <year>2018</year>
          ). Lethal Autonomous Weapon Systems [Ethical, Legal, and Societal Issues].
          <source>IEEE Robotics and Automation Magazine</source>
          ,
          <volume>25</volume>
          (
          <issue>1</issue>
          ),
          <fpage>123</fpage>
          -
          <lpage>126</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <surname>Dwyer</surname>
            ,
            <given-names>A. C.</given-names>
          </string-name>
          ”
          <article-title>The NHS cyber-attack: A look at the complex environmental conditions of WannaCry</article-title>
          .” (
          <year>2018</year>
          ):
          <fpage>25</fpage>
          -
          <lpage>26</lpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>