ArXivCSExplorer
☆☆Bookmarks🏆RSSHow to UseFAQ
Built with and by Teycir Ben Soltane•
How to Use•FAQ•GitHub•arXiv.org•
Share:

~ similar to 2605.27299v1· 20 results

cs.CRRecentMay 8, 2026

AI-Driven Security Alert Screening and Alert Fatigue Mitigation in Security Operations Centers: A Survey

Samuel Ndichu, Tao Ban, Seiichi Ozawa, Takeshi Takahashi +1 more

This survey reviews AI-driven methods for filtering and prioritizing security alerts to combat alert fatigue, establishing a four-stage workflow taxonomy and identifying critical gaps in current resea…

View →
cs.CRcs.LGRecentMay 29, 2026

Send a SCOUT First: Pre-hoc Reasoning for Adaptive Detector Allocation in Prompt-Injection Defense

Shuhao Zhang, Jiarui Li, Qi Cao, Ruiyi Zhang +1 more

The paper introduces SCOUT, a dynamic detector allocation framework that improves prompt-injection defense by predicting detector reliability and latency to optimize the trade-off between safety and o…

View →
cs.CRcs.AIcs.LGRecentMay 24, 2026

Enhancing Autonomous Online Intrusion Detection for IoT with Balanced Learning, Reliable Pseudo-Labels, and Lightweight Architectures

Hanzala Afzaal, Danish Memon, Chouhdary Bilal Raza, Muhammad Khurram Shahzad

This paper enhances an existing autonomous online Intrusion Detection System (AOC-IDS) for IoT by addressing class imbalance, pseudo-label reliability, and computational overhead, achieving significan…

View →
cs.CRRecentMay 6, 2026

Assessing Generalisation Capability of Machine Learning Models for Intrusion Detection

Md Zakir Hossain, Md Ayshik Rahman Khan, Md Rafiqul Islam, Syed Mohammed Shamsul Islam +1 more

The study assesses the generalization capability of supervised machine learning models for intrusion detection using UNSW-NB15 and TON_IoT, finding a significant performance drop when models are teste…

View →
cs.CRcs.AIRecentMay 9, 2026

AI Native Asset Intelligence

Gal Engelberg, Leon Goldberg, Konstantin Koutsyi, Boris Plotnikov +2 more

The paper introduces AI-native asset intelligence, a framework that structures heterogeneous security data into a consistent, contextual layer for proactive, stable, and accurate asset-level risk prio…

View →
cs.CRRecentMay 21, 2026

PACT: Reducing Alert Fatigue in Low-Prevalence SOC Streams with Triggered Active Learning

Samuel Ndichu, Tao Ban, Seiichi Ozawa, Takeshi Takahashi +1 more

PACT is a Pareto-aware active learning controller that significantly reduces the false-positive investigation burden in low-prevalence security alert streams without sacrificing recall.

View →
cs.CRcs.AIRecentApr 15, 2026

Robustness Analysis of Machine Learning Models for IoT Intrusion Detection Under Data Poisoning Attacks

Fortunatus Aabangbio Wulnye, Justice Owusu Agyemang, Kwame Opuni-Boachie Obour Agyekum, Kwame Agyeman-Prempeh Agyekum +2 more

This paper analyzes how vulnerable various machine learning models are to data poisoning attacks in IoT intrusion detection, finding that ensemble methods are more robust than Logistic Regression and…

View →
cs.CRcs.LGRecentMay 23, 2026

CALIBURN: A Regime-Sensitivity Study of Operationally Calibrated Streaming Intrusion Detection

Michel A. Youssef

CALIBURN introduces a novel, five-component streaming pipeline for intrusion detection that allows operators to specify alerting behavior using cost and budget constraints, achieving state-of-the-art…

View →
cs.CRRecentJun 2, 2026

Operationalizing Cyber Attack Prediction: A Gap-Prioritized Framework with Dataset and Model Selection Guidelines

Aminu Muhammad Auwal

This paper proposes a gap-prioritization framework to bridge the gap between theoretical cyber attack prediction research and practical operational deployment by identifying critical implementation hu…

View →
cs.CRcs.LGRecentMar 24, 2026

Explainable Threat Attribution for IoT Networks Using Conditional SHAP and Flow Behavior Modelling

Samuel Ozechi, Jennifer Okonkwoabutu

This paper proposes an explainable threat attribution system for IoT networks that uses SHAP and flow behavior modeling to accurately classify and explain over 30 distinct attack variants into 8 meani…

View →
cs.CRcs.LGRecentMay 15, 2026

A Multi-Layer Cloud-IDS Pipeline with LLM and Adaptive Q-Learning Calibration

Syed Waqas Ali, Ibrar Ali Shah, Farzana Zahid, Daniyal Munir +1 more

The paper proposes a confidence-aware, multi-layered Cloud-IDS pipeline that integrates adaptive Q-Learning, Chroma memory, and LLM semantic analysis to enhance detection accuracy and reduce reliance…

View →
cs.CRcs.NIRecentApr 25, 2026

Advanced Anomaly Detection and Threat Intelligence in Zero Trust IoT Environments Using Machine Learning

Muhammad Umair Basharat, Jawad Hussain, Waqas Khalid, Chiew Foong Kwong

This paper enhances anomaly detection and threat intelligence in Zero Trust IoT environments by applying and comparing various machine learning classifiers, notably using SMOTE to improve accuracy on…

View →
cs.CRRecentMay 18, 2026

From Detection to Response: A Deep Learning and Retrieval-Augmented Generation Framework for Network Intrusion Mitigation

Md Navid Bin Islam, Sajal Saha, Senior Member

The paper introduces an end-to-end framework that not only detects network intrusions using deep learning but also generates actionable, citation-grounded mitigation reports using a Retrieval-Augmente…

View →
cs.CRRecentMay 8, 2026

When the Ruler is Broken: Parsing-Induced Suppression in LLM-Based Security Log Evaluation

Chaitanya Vilas Garware, Sharif Noor Zisad

The paper demonstrates that relying on strict regular-expression parsing for evaluating LLM-based security log classifiers introduces systematic errors, potentially causing a functional model to appea…

View →
cs.CRcs.AIcs.LGRecentApr 20, 2026

ExAI5G: A Logic-Based Explainable AI Framework for Intrusion Detection in 5G Networks

Saeid Sheikhi, Panos Kostakos, Lauri Loven

The paper proposes ExAI5G, a logic-based explainable AI framework that integrates a Transformer-based IDS with XAI techniques to provide highly accurate and transparent intrusion detection for 5G netw…

View →
cs.CRcs.NImath.NARecentMay 26, 2026

Shortest Path Problem with Subnormal Gaussian Fuzzy Costs

Hande Günay Akdemir, Murat Moran

This paper proposes a reliability-aware framework to solve the fuzzy shortest path problem in directed graphs, optimizing routes based not only on cost but also on the reliability of the associated fu…

View →
cs.CRRecentApr 23, 2026

Can SOC Operators Explain their Decisions while Triaging Alarms? A Real-World Study

Jessica Moosmann, Irdin Pekaric, Giovanni Apruzzese

This study investigated whether Security Operations Center (SOC) analysts can justify their decisions when triaging alarms, finding that while they are often correct in identifying true threats, they…

View →
cs.CRRecentMay 4, 2026

Zero Day Attacks: Novel Behaviour or Novel Vulnerability?

Nnamdi Jibunoh, Sara Khanchi, Adetokunbo Makanju

The paper argues that zero-day attacks primarily exploit undisclosed vulnerabilities rather than exhibiting novel behaviors, advocating for vulnerability-centric detection methods over purely behavior…

View →
cs.CRRecentMay 3, 2026

FIRCE: A Framework for Intrusion Response and Conformal Evaluation

Seth Barrett, Lin Li, Gokila Dorai, Swarnamugi Rajaganapathy

The paper introduces FIRCE, a framework that enhances intrusion detection systems by combining conformal evaluation for uncertainty quantification and drift detection with an adaptive chunking mechani…

View →
cs.LGcs.CRRecentMay 18, 2026

A No-Defense Defense Against Gradient-Based Adversarial Attacks on ML-NIDS: Is Less More?

Mohamed elShehaby, Ashraf Matrawy

The paper demonstrates that simpler, shallower Deep Neural Network architectures with reduced features and ReLU activations can inherently improve the robustness of ML-NIDS against gradient-based adve…

View →