The paper evaluates the common assumption that combining flow statistics and TLS handshake fingerprints improves encrypted command-and-control detection. Using 17,577 TLS flows from 62 real Cobalt Strike captures, the authors show that data leakage and preprocessing choices inflate performance metrics, revealing that the true benefit of multi-view fusion is minimal (0.022 F1). They also uncover that many captures contain only benign traffic and that class imbalance is an artifact of analysis rather than a real feature of the task.
By Hoang-Huy Nguyen-Huu, Van-Tri Phan, Khuong Nguyen-An
The paper evaluates CASCADE, a fully local layered defense for Model Context Protocol (MCP)-based systems, by conducting a component ablation and corpus audit on a fixed 5,000-sample dataset. It demonstrates that the choice of aggregation convention heavily influences reported metrics, that detection performance varies with provenance, and that the released configuration does not fully disclose the operating point. The study also shows that a local review model invoked for a third of requests does not alter classification outcomes, highlighting the importance of reproducibility and transparency in defense evaluations.
By \.Ipek Abas{\i}kele\c{s} Turgut, Edip G\"um\"u\c{s}
The paper introduces DISCERN, a two-tier protocol for certifying that updates to production models do not increase risk. It first uses unlabeled data to detect benign updates based on disagreement rates, then selectively labels only disagreements through an anytime-valid confidence sequence. The method achieves finite-sample validity with label-complexity bounds of order ρ²/ε², demonstrating significant label savings and strong empirical performance across 14,000+ audit streams.
By Vishnu Bindu Balachandran
arXiv:2608. 15761v1 Announce Type: cross Abstract: Edge-IIoTset is the reference benchmark for machine-learning intrusion detection in the industrial Internet of Things, and results reported on it cluster above 99%.
By Mostafa M. Galal
arXiv:2609.14451v1 Announce Type: cross
Abstract: Modern semi-supervised learning (SSL) couples pseudo-label generation and classifier training, using the classifier's own confidence to select the ps...
By Itai David, Daphna Weinshall
arXiv:2608. 15565v1 Announce Type: new Abstract: Experience-learning agents for optimization modeling improve by storing verified skills, but existing learners admit knowledge by checking against known answers, which real ticket streams do not provide.
By Junbo Jacob Lian, Huiling Chen, Hanzhang Qin, Chung-Piaw Teo
The paper presents a compliance screening system that evaluates blockchain addresses by their position in a large multi‑chain transaction graph instead of relying on sanctions lists. Using a single graph of 835 million addresses and 15.8 billion edges across five EVM chains, the system employs a shared inductive encoder with per‑chain normalization and two scoring heads, with decision thresholds set as exact quantiles of the score distribution. The authors demonstrate label‑free transfer, achieving high recall on held‑out positives for Base, Arbitrum, and Gnosis, and report significant lead‑time in flagging external registry events, efficient serving latency, and robustness checks against adversarial behavior.
arXiv:2608. 12652v1 Announce Type: cross Abstract: Benchmark contamination is diagnosed today with n-gram overlap, with likelihood-based membership inference, or with canary strings, and each needs something usually unavailable: the training corpus, a well-chosen test statistic, or foresight at dataset release.
By Florian Braun
arXiv:2606. 00155v1 Announce Type: cross Abstract: Modern network intrusion detection systems (NIDS) are caught in a structural contradiction: the protocols carrying the highest threat intelligence are precisely those encrypted under TLS 1.
By Vivek Kumar Sharma
arXiv:2609. 18960v1 Announce Type: new Abstract: Quality-aware synthetic-data selection rests on a proxy: examples that an LLM judge rates as good should also help a downstream model learn.
By Son Ha Xuan, Phat T. Tran-Truong, Xuan-Bach Le
The paper presents a deployed system that scores blockchain addresses using their position in a massive multi‑chain transaction graph instead of relying on sanctions lists. The system operates on a single graph of 835 million addresses and 15.8 billion edges across five EVM chains, employing a shared inductive encoder with per‑chain normalization and two scoring heads. It demonstrates label‑free transfer, achieving high recall on held‑out positives for Base, Arbitrum, and Gnosis at a very low alert rate, and shows significant lead time over external registry events, while maintaining fast, reproducible serving performance.
By Yury Korolev
arXiv:2606. 08372v1 Announce Type: cross Abstract: Synthetic data is increasingly promoted as a privacy-preserving substitute for releasing sensitive tabular records, yet its central adversarial threat ("reconstruction", the recovery of an individual's hidden attribute values from a synthetic release and a handful of known quasi-identifiers) has been studied only in scattered, hard-to-compare settings.
By Steven Golob, Sikha Pentyala, Martine De Cock