Next-generation cyberattack detection with large language models: anomaly analysis across heterogeneous logs
This project explores large language models (LLMs) for anomaly detection across heterogeneous log sources. Traditional intrusion detection systems suffer from high false positive rates, semantic blindness, and data scarcity, as logs are inherently sensitive, making clean datasets rare. We address these challenges through three contributions: (1) LogAtlas-Foundation-Sessions and LogAtlas-Defense-Set, balanced and heterogeneous log datasets with explicit attack annotations and privacy preservation; (2) empirical benchmarking revealing why standard metrics such as F1 and accuracy are misleading for security applications; and (3) a two phase training framework combining log understanding (Base-AMAN, 3B parameters) with real time detection (AMAN, 0.5B parameters via knowledge distillation). Results demonstrate practical feasibility, with inference times of 0.3-0.5 seconds per session and operational costs below 50 USD per day.
Code (0)
등록된 구현이 없습니다.
Tasks
Knowledge DistillationIntrusion DetectionAnomaly DetectionSimilar Papers 제목 키워드 기반
Assessment of Cyberattack Detection-Isolation Algorithm for CAV Platoons Using SUMO
A Connected Autonomous Vehicle (CAV) platoon in an evolving real-world driving environment relies strongly on accurate vehicle-to-vehicle (V2V) and vehicle-to-infrastructure (V2I) communication for its safe and efficient…
Large Language Model-Based Framework for Explainable Cyberattack Detection in Automatic Generation Control Systems
The increasing digitization of smart grids has improved operational efficiency but also introduced new cybersecurity vulnerabilities, such as False Data Injection Attacks (FDIAs) targeting Automatic Generation Control (A…
Large Language Models for Detecting Cyberattacks on Smart Grid Protective Relays
This paper presents a large language model (LLM)-based framework that adapts and fine-tunes compact LLMs for detecting cyberattacks on transformer current differential relays (TCDRs), which can otherwise cause false trip…
Cyberattack Detection in Large-Scale Smart Grids using Chebyshev Graph Convolutional Networks
As a highly complex and integrated cyber-physical system, modern power grids are exposed to cyberattacks. False data injection attacks (FDIAs), specifically, represent a major class of cyber threats to smart grids by tar…
Machine Learning in Generation, Detection, and Mitigation of Cyberattacks in Smart Grid: A Survey
Smart grid (SG) is a complex cyber-physical system that utilizes modern cyber and physical equipment to run at an optimal operating point. Cyberattacks are the principal threats confronting the usage and advancement of t…
BIG-bench Machine Learning