paper-with-me

홈 › Papers

Next-generation cyberattack detection with large language models: anomaly analysis across heterogeneous logs

2026-02-06 · Yassine Chagna, Antal Goldschmidt arxiv

This project explores large language models (LLMs) for anomaly detection across heterogeneous log sources. Traditional intrusion detection systems suffer from high false positive rates, semantic blindness, and data scarcity, as logs are inherently sensitive, making clean datasets rare. We address these challenges through three contributions: (1) LogAtlas-Foundation-Sessions and LogAtlas-Defense-Set, balanced and heterogeneous log datasets with explicit attack annotations and privacy preservation; (2) empirical benchmarking revealing why standard metrics such as F1 and accuracy are misleading for security applications; and (3) a two phase training framework combining log understanding (Base-AMAN, 3B parameters) with real time detection (AMAN, 0.5B parameters via knowledge distillation). Results demonstrate practical feasibility, with inference times of 0.3-0.5 seconds per session and operational costs below 50 USD per day.

📄 PDF Abstract BibTeX arXiv:2602.06777

Code (0)

등록된 구현이 없습니다.

Tasks

Knowledge DistillationIntrusion DetectionAnomaly Detection

Similar Papers 제목 키워드 기반

Assessment of Cyberattack Detection-Isolation Algorithm for CAV Platoons Using SUMO

2025-03-18 · Sanchita Ghosh, Tanushree Roy

A Connected Autonomous Vehicle (CAV) platoon in an evolving real-world driving environment relies strongly on accurate vehicle-to-vehicle (V2V) and vehicle-to-infrastructure (V2I) communication for its safe and efficient…

Large Language Model-Based Framework for Explainable Cyberattack Detection in Automatic Generation Control Systems

2025-07-29 · Muhammad Sharshar, Ahmad Mohammad Saber, Davor Svetinovic, Amr M. Youssef 외 arxiv

The increasing digitization of smart grids has improved operational efficiency but also introduced new cybersecurity vulnerabilities, such as False Data Injection Attacks (FDIAs) targeting Automatic Generation Control (A…

Large Language Models for Detecting Cyberattacks on Smart Grid Protective Relays

2026-01-07 · Ahmad Mohammad Saber, Saeed Jafari, Zhengmao Ouyang, Paul Budnarain 외 arxiv

This paper presents a large language model (LLM)-based framework that adapts and fine-tunes compact LLMs for detecting cyberattacks on transformer current differential relays (TCDRs), which can otherwise cause false trip…

Cyberattack Detection in Large-Scale Smart Grids using Chebyshev Graph Convolutional Networks

2021-12-25 · Osman Boyaci, Mohammad Rasoul Narimani, Katherine Davis, Erchin Serpedin

As a highly complex and integrated cyber-physical system, modern power grids are exposed to cyberattacks. False data injection attacks (FDIAs), specifically, represent a major class of cyber threats to smart grids by tar…

Machine Learning in Generation, Detection, and Mitigation of Cyberattacks in Smart Grid: A Survey

2020-09-01 · Nur Imtiazul Haque, Md Hasan Shahriar, Md Golam Dastgir, Anjan Debnath 외

Smart grid (SG) is a complex cyber-physical system that utilizes modern cyber and physical equipment to run at an optimal operating point. Cyberattacks are the principal threats confronting the usage and advancement of t…

BIG-bench Machine Learning