paper-with-me

Papers

Toward Cybersecurity-Expert Small Language Models

2025-10-15 · Matan Levi, Daniel Ohayon, Ariel Blobstein, Ravid Sagi, Ian Molloy, Yair Allouche arxiv

Large language models (LLMs) are transforming everyday applications, yet deployment in cybersecurity lags due to a lack of high-quality, domain-specific models and training datasets. To address this gap, we present CyberPal 2.0, a family of cybersecurity-expert small language models (SLMs) ranging from 4B-20B parameters. To train CyberPal 2.0, we generate an enriched chain-of-thought cybersecurity instruction dataset built with our data enrichment and formatting pipeline, SecKnowledge 2.0, which integrates expert-in-the-loop steering of reasoning formats alongside LLM-driven multi-step grounding, yielding higher-fidelity, task-grounded reasoning traces for security tasks. Across diverse cybersecurity benchmarks, CyberPal 2.0 consistently outperforms its baselines and matches or surpasses various open and closed-source frontier models, while remaining a fraction of their size. On core cyber threat intelligence knowledge tasks, our models outperform almost all tested frontier models, ranking second only to Sec-Gemini v1. On core threat-investigation tasks, such as correlating vulnerabilities and bug tickets with weaknesses, our best 20B-parameter model outperforms GPT-4o, o1, o3-mini, and Sec-Gemini v1, ranking first, while our smallest 4B-parameter model ranks second.

📄 PDF Abstract BibTeX arXiv:2510.14113

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

Leveraging Large Language Models for Cybersecurity Risk Assessment -- A Case from Forestry Cyber-Physical Systems

2025-10-07 · Fikret Mert Gultekin, Oscar Lilja, Ranim Khojah, Rebekka Wohlrab 외 arxiv

In safety-critical software systems, cybersecurity activities become essential, with risk assessment being one of the most critical. In many software teams, cybersecurity experts are either entirely absent or represented…

CyberMetric: A Benchmark Dataset based on Retrieval-Augmented Generation for Evaluating LLMs in Cybersecurity Knowledge

2024-02-12 · Norbert Tihanyi, Mohamed Amine Ferrag, Ridhi Jain, Tamas Bisztray 외

Large Language Models (LLMs) are increasingly used across various domains, from software development to cyber threat intelligence. Understanding all the different fields of cybersecurity, which includes topics such as cr…

General KnowledgeMultiple-choiceRAGRetrieval+1

Ignore Me But Don't Replace Me: Utilizing Non-Linguistic Elements for Pretraining on the Cybersecurity Domain

2024-03-15 · Eugene Jang, Jian Cui, Dayeon Yim, Youngjin Jin 외

Cybersecurity information is often technically complex and relayed through unstructured text, making automation of cyber threat intelligence highly challenging. For such text domains that involve high levels of expertise…

Language ModelingLanguage Modellingtoken-classificationToken Classification

Fine-tuning of Large Language Models for Domain-Specific Cybersecurity Knowledge

2025-09-25 · Yuan Huang arxiv

Recent advancements in training paradigms for Large Language Models (LLMs) have unlocked their remarkable capabilities in natural language processing and cross-domain generalization. While LLMs excel in tasks like progra…

Computational EfficiencyDomain Generalization

CySecBERT: A Domain-Adapted Language Model for the Cybersecurity Domain

2022-12-06 · Markus Bayer, Philipp Kuehn, Ramin Shanehsaz, Christian Reuter

The field of cybersecurity is evolving fast. Experts need to be informed about past, current and - in the best case - upcoming threats, because attacks are becoming more advanced, targets bigger and systems more complex.…

Language ModelingLanguage Modelling