arXiv Machine Learning

SoK: Where Do Flow Labels Come From? Auditing Label Provenance in Encrypted Traffic Benchmarks

The paper audits 14 encrypted traffic classification benchmarks to investigate how flow labels are generated. It finds two common labeling strategies—coarse inheritance, which may mislabel flows, and overstrict filtering, which may discard useful flows—leading to inconsistencies between benchmark labels and actual traffic records. The study also quantifies the impact of these labeling practices on classifier accuracy, showing that inherited labels limit balanced accuracy to 0.56–0.76, while filtering can raise macro accuracy from 0.44 to 0.65.

arXiv AI
Sep 24

Multi-View Fusion for Encrypted C2 Detection: A Leakage-Controlled Measurement Study of Evaluation Pitfalls

The paper evaluates the common assumption that combining flow statistics and TLS handshake fingerprints improves encrypted command-and-control detection. Using 17,577 TLS flows from 62 real Cobalt Strike captures, the authors show that data leakage and preprocessing choices inflate performance metrics, revealing that the true benefit of multi-view fusion is minimal (0.022 F1). They also uncover that many captures contain only benign traffic and that class imbalance is an artifact of analysis rather than a real feature of the task.

By Hoang-Huy Nguyen-Huu, Van-Tri Phan, Khuong Nguyen-An
arXiv AI
Sep 4

CASCADE: A Component Ablation and Corpus Audit of a Layered Local Defense for MCP-Based Systems

The paper evaluates CASCADE, a fully local layered defense for Model Context Protocol (MCP)-based systems, by conducting a component ablation and corpus audit on a fixed 5,000-sample dataset. It demonstrates that the choice of aggregation convention heavily influences reported metrics, that detection performance varies with provenance, and that the released configuration does not fully disclose the operating point. The study also shows that a local review model invoked for a third of requests does not alter classification outcomes, highlighting the importance of reproducibility and transparency in defense evaluations.

By \.Ipek Abas{\i}kele\c{s} Turgut, Edip G\"um\"u\c{s}
arXiv AI
Sep 17

Pay Only for Disagreement: Certified No-Regression Verdicts for Model Updates with Matching Label-Complexity Bounds

The paper introduces DISCERN, a two-tier protocol for certifying that updates to production models do not increase risk. It first uses unlabeled data to detect benign updates based on disagreement rates, then selectively labels only disagreements through an anytime-valid confidence sequence. The method achieves finite-sample validity with label-complexity bounds of order ρ²/ε², demonstrating significant label savings and strong empirical performance across 14,000+ audit streams.

By Vishnu Bindu Balachandran
Hugging Face Trending Papers
Sep 2

Population-Calibrated Graph Screening at 835-Million-Address Scale, with Label-Free Transfer to New Chains

The paper presents a compliance screening system that evaluates blockchain addresses by their position in a large multi‑chain transaction graph instead of relying on sanctions lists. Using a single graph of 835 million addresses and 15.8 billion edges across five EVM chains, the system employs a shared inductive encoder with per‑chain normalization and two scoring heads, with decision thresholds set as exact quantiles of the score distribution. The authors demonstrate label‑free transfer, achieving high recall on held‑out positives for Base, Arbitrum, and Gnosis, and report significant lead‑time in flagging external registry events, efficient serving latency, and robustness checks against adversarial behavior.

arXiv Machine Learning
Sep 4

Population-Calibrated Graph Screening at 835-Million-Address Scale, with Label-Free Transfer to New Chains

The paper presents a deployed system that scores blockchain addresses using their position in a massive multi‑chain transaction graph instead of relying on sanctions lists. The system operates on a single graph of 835 million addresses and 15.8 billion edges across five EVM chains, employing a shared inductive encoder with per‑chain normalization and two scoring heads. It demonstrates label‑free transfer, achieving high recall on held‑out positives for Base, Arbitrum, and Gnosis at a very low alert rate, and shows significant lead time over external registry events, while maintaining fast, reproducible serving performance.

By Yury Korolev
arXiv Machine Learning
Jun 9

SoK: Reconstruction Attacks on Synthetic Tabular Data (Insights from Winning the NIST CRC)

arXiv:2606. 08372v1 Announce Type: cross Abstract: Synthetic data is increasingly promoted as a privacy-preserving substitute for releasing sensitive tabular records, yet its central adversarial threat ("reconstruction", the recovery of an individual's hidden attribute values from a synthetic release and a handful of known quasi-identifiers) has been studied only in scattered, hard-to-compare settings.

By Steven Golob, Sikha Pentyala, Martine De Cock