paper-with-me

Papers

Attribution-Driven Explainable Intrusion Detection with Encoder-Based Large Language Models

2026-04-07 · Umesh Biswas, Shafqat Hasan, Syed Mohammed Farhan, Nisha Pillai, Charan Gudla arxiv

Software-Defined Networking (SDN) improves network flexibility but also increases the need for reliable and interpretable intrusion detection. Large Language Models (LLMs) have recently been explored for cybersecurity tasks due to their strong representation learning capabilities; however, their lack of transparency limits their practical adoption in security-critical environments. Understanding how LLMs make decisions is therefore essential. This paper presents an attribution-driven analysis of encoder-based LLMs for network intrusion detection using flow-level traffic features. Attribution analysis demonstrates that model decisions are driven by meaningful traffic behavior patterns, improving transparency and trust in transformer-based SDN intrusion detection. These patterns align with established intrusion detection principles, indicating that LLMs learn attack behavior from traffic dynamics. This work demonstrates the value of attribution methods for validating and trusting LLM-based security analysis.

📄 PDF Abstract BibTeX arXiv:2604.06266

Code (0)

등록된 구현이 없습니다.

Tasks

Network Intrusion DetectionRepresentation Learning

Similar Papers 제목 키워드 기반

Explainable Threat Attribution for IoT Networks Using Conditional SHAP and Flow Behavior Modelling

2026-03-24 · Samuel Ozechi, Jennifer Okonkwoabutu arxiv

As the Internet of Things (IoT) continues to expand across critical infrastructure, smart environments, and consumer devices, securing them against cyber threats has become increasingly vital. Traditional intrusion detec…

Binary ClassificationIntrusion Detection

Enhancing Adversarial Robustness of IoT Intrusion Detection via SHAP-Based Attribution Fingerprinting

2025-11-09 · Dilli Prasad Sharma, Liang Xue, Xiaowei Sun, Xiaodong Lin 외 arxiv

The rapid proliferation of Internet of Things (IoT) devices has transformed numerous industries by enabling seamless connectivity and data-driven automation. However, this expansion has also exposed IoT networks to incre…

Adversarial RobustnessIntrusion Detection

LENS-XAI: Redefining Lightweight and Explainable Network Security through Knowledge Distillation and Variational Autoencoders for Scalable Intrusion Detection in Cybersecurity

2025-01-01 · Muhammet Anil Yagiz, Polat Goktas

The rapid proliferation of Industrial Internet of Things (IIoT) systems necessitates advanced, interpretable, and scalable intrusion detection systems (IDS) to combat emerging cyber threats. Traditional IDS face challeng…

Computational EfficiencyIntrusion DetectionKnowledge Distillation

Towards Explainable Meta-Learning for DDoS Detection

2022-04-05 · Qianru Zhou, Rongzhen Li, Lei Xu, Arumugam Nallanathan 외

The Internet is the most complex machine humankind has ever built, and how to defense it from intrusions is even more complex. With the ever increasing of new intrusions, intrusion detection task rely on Artificial Intel…

Intrusion DetectionMeta-Learning

Explainable Autoencoder-Based Anomaly Detection in IEC 61850 GOOSE Networks

2026-01-14 · Dafne Lozano-Paredes, Luis Bote-Curiel, Juan Ramón Feijóo-Martínez, Ismael Gómez-Talal 외 arxiv

The IEC 61850 Generic Object-Oriented Substation Event (GOOSE) protocol plays a critical role in real-time protection and automation of digital substations, yet its lack of native security mechanisms can expose power sys…

Intrusion DetectionAnomaly Detection