arXiv AI

Traffic-Aware Randomized Smoothing for LLM-Based Network Intrusion Detection

arXiv:2607. 13801v1 Announce Type: cross Abstract: Large language model (LLM)-based intrusion detection systems (IDS) are increasingly studied for security monitoring, yet their robustness against feasible traffic manipulation remains largely empirical.

arXiv Machine Learning
Sep 7

Candidate Comparability Before Promotion: Conditional Validation in Adaptive Network Intrusion Detection

The paper investigates how to properly validate candidate models before promoting them to replace incumbent classifiers in adaptive network intrusion detection systems. It demonstrates that promotion decisions can be biased by how challengers are constructed and the amount of evidence they receive, and that using self‑contained challenger pipelines and sufficient candidate evidence reduces apparent promotion harm. The study also shows that policy rankings shift with candidate comparability and that no single update policy dominates across benchmarks.

By Roberto Fern\'andez-Barrios, Iker Pastor-L\'opez, Amaia Pikatza-Huerga, Pablo Garc\'ia Bringas
arXiv AI
Sep 15

A Three-Axis Stress Test of LLM vs Classical ML for Network Intrusion Detection under Distribution Shift and Adversarial Evasion

The study compares XGBoost and RoBERTa‑LoRA for network intrusion detection across three evaluation axes: same‑dataset performance, cross‑dataset transfer, and adversarial evasion. Both models perform similarly on the same dataset, but XGBoost outperforms RoBERTa‑LoRA by 15 F1 points and 25 balanced accuracy points when transferred to a different network, while RoBERTa‑LoRA wins by about 17 F1 points under adversarial evasion. Feature‑leakage ablation shows that cross‑dataset transfer improvements are non‑monotonic and directional, suggesting leakage is spread across features rather than isolated. "whyItMatters":"The findings demonstrate that a model’s superiority depends on the specific robustness axis evaluated, underscoring the need for multi‑axis, multi‑metric testing in network intrusion detection research."

By Muhammad Ebad Atif, Muhammad Haider Ali
arXiv AI
Jun 9

SHIELD-IDS: Structurally Heterogeneous Ensemble with Integrated Layered Defense for Intrusion Detection Systems

arXiv:2606. 07716v1 Announce Type: cross Abstract: Adversarial attacks pose a serious and growing threat to Machine Learning (ML)-based Intrusion Detection Systems (IDS), where imperceptible perturbations to network flow features can systematically mislead classifiers into accepting malicious traffic as benign.

By Maryam Zaman, Muhammad Khuram Shahzad
arXiv AI
Sep 18

Robust Conformal Intrusion Detection via Traffic-Aware Calibration and Attack-Orbit Invariance

The paper addresses the lack of statistical validity in language‑model‑based network intrusion detection. It introduces traffic‑aware conformal prediction, which calibrates on attacker‑expected traffic to restore coverage guarantees, and further mitigates adaptive attacks by removing attacker‑controllable features, achieving exact pathwise coverage. Experiments on three benchmarks show that this approach maintains coverage while incurring a modest accuracy cost.

By Zhenpeng Li