paper-with-me

홈 › Papers

Metric Matters: A Formal Evaluation of Similarity Measures in Active Learning for Cyber Threat Intelligence

2025-08-26 · Sidahmed Benabderrahmane, Talal Rahwan arxiv

Advanced Persistent Threats (APTs) pose a severe challenge to cyber defense due to their stealthy behavior and the extreme class imbalance inherent in detection datasets. To address these issues, we propose a novel active learning-based anomaly detection framework that leverages similarity search to iteratively refine the decision space. Built upon an Attention-Based Autoencoder, our approach uses feature-space similarity to identify normal-like and anomaly-like instances, thereby enhancing model robustness with minimal oracle supervision. Crucially, we perform a formal evaluation of various similarity measures to understand their influence on sample selection and anomaly ranking effectiveness. Through experiments on diverse datasets, including DARPA Transparent Computing APT traces, we demonstrate that the choice of similarity metric significantly impacts model convergence, anomaly detection accuracy, and label efficiency. Our results offer actionable insights for selecting similarity functions in active learning pipelines tailored for threat intelligence and cyber defense.

📄 PDF Abstract BibTeX arXiv:2508.19019

Code (0)

등록된 구현이 없습니다.

Tasks

Anomaly DetectionActive Learning

Similar Papers 제목 키워드 기반

Conformal Prediction Sets with Improved Conditional Coverage using Trust Scores

2025-01-17 · Jivat Neet Kaur, Michael I. Jordan, Ahmed Alaa

Standard conformal prediction offers a marginal guarantee on coverage, but for prediction sets to be truly useful, they should ideally ensure coverage conditional on each test point. Unfortunately, it is impossible to ac…

Conformal PredictionPredictionvalid

Does It Capture STEL? A Modular, Similarity-based Linguistic Style Evaluation Framework

2021-09-10 · EMNLP 2021 11 · Anna Wegmann, Dong Nguyen

Style is an integral part of natural language. However, evaluation methods for style measures are rare, often task-specific and usually do not control for content. We propose the modular, fine-grained and content-control…

Extending Text Informativeness Measures to Passage Interestingness Evaluation (Language Model vs. Word Embedding)

2020-04-14 · Carlos-Emiliano González-Gallardo, Eric SanJuan, Juan-Manuel Torres-Moreno

Standard informativeness measures used to evaluate Automatic Text Summarization mostly rely on n-gram overlapping between the automatic summary and the reference summaries. These measures differ from the metric they use …

Information RetrievalInformativenessLanguage ModelingLanguage Modelling+3

Metric Space Magnitude for Evaluating the Diversity of Latent Representations

2023-11-27 · Katharina Limbeck, Rayna Andreeva, Rik Sarkar, Bastian Rieck

The magnitude of a metric space is a novel invariant that provides a measure of the 'effective size' of a space across multiple scales, while also capturing numerous geometrical properties, such as curvature, density, or…

Dimensionality ReductionDiversityRepresentation Learning

Entropic Context Shaping: Information-Theoretic Filtering for Context-Aware LLM Agents

2026-01-01 · Hyunjun Kim arxiv

Context engineering for large language model (LLM) agents requires distinguishing pragmatically useful information from misleading distractors. We introduce Entropic Context Shaping (ECS), an information-theoretic framew…