paper-with-me

홈 › Papers

Zero-shot learning approach to adaptive Cybersecurity using Explainable AI

2021-06-21 · Dattaraj Rao, Shraddha Mane

Cybersecurity is a domain where there is constant change in patterns of attack, and we need ways to make our Cybersecurity systems more adaptive to handle new attacks and categorize for appropriate action. We present a novel approach to handle the alarm flooding problem faced by Cybersecurity systems like security information and event management (SIEM) and intrusion detection (IDS). We apply a zero-shot learning method to machine learning (ML) by leveraging explanations for predictions of anomalies generated by a ML model. This approach has huge potential to auto detect alarm labels generated in SIEM and associate them with specific attack types. In this approach, without any prior knowledge of attack, we try to identify it, decipher the features that contribute to classification and try to bucketize the attack in a specific category - using explainable AI. Explanations give us measurable factors as to what features influence the prediction of a cyber-attack and to what degree. These explanations generated based on game-theory are used to allocate credit to specific features based on their influence on a specific prediction. Using this allocation of credit, we propose a novel zero-shot approach to categorize novel attacks into specific new classes based on feature influence. The resulting system demonstrated will get good at separating attack traffic from normal flow and auto-generate a label for attacks based on features that contribute to the attack. These auto-generated labels can be presented to SIEM analyst and are intuitive enough to figure out the nature of attack. We apply this approach to a network flow dataset and demonstrate results for specific attack types like ip sweep, denial of service, remote to local, etc. Paper was presented at the first Conference on Deployable AI at IIT-Madras in June 2021.

📄 PDF Abstract BibTeX arXiv:2106.14647

Code (0)

등록된 구현이 없습니다.

Tasks

Intrusion DetectionManagementZero-Shot Learning

Methods 이 논문이 사용한 방법론

Golden Queue Managers 설명 없음

Similar Papers 제목 키워드 기반

Learning-to-Explain through 20Q Gaming: An Explainable Recommender for Cybersecurity Education

2026-04-14 · Mary Nusrat, Sarfuddin Bhuiyan, Gahangir Hossain arxiv

The growing sophistication of contemporary cyber threats necessitates a more effective and adaptive approach to cybersecurity training. Intuitive and adaptive approaches to learning, which are often required, are not pro…

Reinforcement Learning

Zero-Shot Visual Deepfake Detection: Can AI Predict and Prevent Fake Content Before It's Created?

2025-09-22 · Ayan Sar, Sampurna Roy, Tanupriya Choudhury, Ajith Abraham arxiv

Generative adversarial networks (GANs) and diffusion models have dramatically advanced deepfake technology, and its threats to digital security, media integrity, and public trust have increased rapidly. This research exp…

Self-Supervised LearningFederated LearningZero-Shot LearningDeepFake Detection

A ChatGPT Aided Explainable Framework for Zero-Shot Medical Image Diagnosis

2023-07-05 · Jiaxiang Liu, Tianxiang Hu, Yan Zhang, Xiaotang Gai 외

Zero-shot medical image classification is a critical process in real-world scenarios where we have limited access to all possible diseases or large-scale annotated data. It involves computing similarity scores between a …

Diagnosticimage-classificationImage ClassificationMedical Image Classification

Explainable Artificial Intelligence and Cybersecurity: A Systematic Literature Review

2023-02-27 · Carlos Mendes, Tatiane Nogueira Rios

Cybersecurity vendors consistently apply AI (Artificial Intelligence) to their solutions and many cybersecurity domains can benefit from AI technology. However, black-box AI techniques present some difficulties in compre…

Explainable artificial intelligenceExplainable Artificial Intelligence (XAI)Systematic Literature Review

Adaptive Cybersecurity Architecture for Digital Product Ecosystems Using Agentic AI

2025-09-25 · Oluwakemi T. Olayinka, Sumeet Jeswani, Divine Iloh arxiv

Traditional static cybersecurity models often struggle with scalability, real-time detection, and contextual responsiveness in the current digital product ecosystems which include cloud services, application programming …

Anomaly DetectionDecision Making