16 papers
Find Before You Fine-Tune: A Diagnostic Study of Small LLMs for Cybersecurity QA
Shaswata Mitra, Subash Neupane, Trisha Chakraborty +4
Large Language Models (LLMs) are increasingly fine-tuned for critical-domain Question-Answering (QA), yet choosing which small model to adapt, before paying the cost of adaptation,…
SMETA-ZSL:Semantic Meta-Alignment for Zero-Shot Threat Classification
Ivan Alejandro Montoya Sanchez, Anantaa Kotal, Aritran Piplai
Cybersecurity systems must adapt rapidly to emerging threats. However, labeled data for new threat categories is unavailable when those threats first appear. Generalized zero-shot…
FALCON: Transforming Cyber Threat Intelligence into Deployable IDS Rules with Self-Reflection
Shaswata Mitra, Subash Neupane, Martin Duclos +5
Signature-based Intrusion Detection Systems (IDS) detect malicious activity by matching network or host events against predefined rules. Security analysts manually develop these ru…
McNdroid: A Longitudinal Multimodal Benchmark for Robust Drift Detection in Android Malware
Md Mahmuduzzaman Kamol, Jesus Lopez, Saeefa Rubaiyet Nowmi +5
Machine learning (ML) in real-world systems must contend with concept drift, adversarial actors, and a spectrum of potential features with varying costs and benefits. Malware natur…
Minerva: Reinforcement Learning with Verifiable Rewards for Cyber Threat Intelligence LLMs
Md Tanvirul Alam, Aritran Piplai, Ionut Cardei +2
Cyber threat intelligence (CTI) analysts routinely convert noisy, unstructured security artifacts into standardized, automation-ready representations. Although large language model…
Evaluating Generalization Mechanisms in Autonomous Cyber Attack Agents
OndÅej Lukáš, Jihoon Shin, Emilia Rivas +6
Autonomous offensive agents often fail to transfer beyond the networks on which they are trained. We isolate a minimal but fundamental shift -- unseen host/subnet IP reassignment i…