arXiv Machine Learning

ModSec-Learn: Boosting ModSecurity with Machine Learning

arXiv AI
Sep 10

WAPP: Safe Learning of Positive Security WAF Policies from Live Traffic

The paper introduces WAPP, a framework for safely learning positive security Web Application Firewall (WAF) policies from live traffic. It combines trust filtering, deterministic rule synthesis, confidence scoring, and validation to protect against poisoned training data. Experiments on controlled applications show that WAPP improves poisoning resilience and blocks confirmed CRS bypasses, though free‑text fields still pose precision challenges.

By Heba Osama, Zeyad Ahmed, Mohamed Amgad, Ahmed Saafan, Jana Elfeky, Mariam Abdelati, Haitham Ghalwash
arXiv AI
Sep 24

Comparative Evaluation of Static Embedding Models for HTTP Request Anomaly Detection

The paper benchmarks static embedding models—Word2Vec, FastText, and Doc2Vec—for detecting anomalous HTTP requests using a single‑class classification framework. It introduces HEDA, a modular pipeline that trains both embeddings and detectors solely on benign traffic in an unsupervised setting. Experiments on synthetic and real datasets show that FastText embeddings consistently yield high detection rates with controlled false positives.

By Amanda Riverol, Gustavo Betarte, Rodrigo Mart\'inez, \'Alvaro Pardo
arXiv Machine Learning
Sep 14

Correlation-Guided Fast Machine Unlearning via Hessian Analysis

The paper presents a fast machine unlearning method that uses Hessian analysis to identify correlated training data and applies a closed‑form update rule. This approach achieves an 82× speedup over traditional influence‑function unlearning while maintaining or slightly improving model accuracy. Experiments on seven dataset‑architecture pairs, including CIFAR‑100 with ResNet‑50, show strong forgetting performance and low vulnerability to membership inference attacks.

By Ayushi Thakur, Ruchir Gupta, Amit Kumar Jaiswal, Prayag Tiwari
arXiv Machine Learning
Jun 29

CO-DEFEND: Continuous Decentralized Federated Learning for Secure DoH-Based Threat Detection

arXiv:2504. 01882v2 Announce Type: replace Abstract: The use of DNS over HTTPS (DoH) tunneling by an attacker to hide malicious activity within encrypted DNS traffic poses a serious threat to network security, as it allows malicious actors to bypass traditional monitoring and intrusion detection systems while evading detection by conventional traffic analysis techniques.

By Diego Cajaraville-Aboy, Marta Moure-Garrido, Carlos Beis-Penedo, Carlos Garcia-Rubio, Rebeca P. D\'iaz-Redondo, Celeste Campo, Ana Fern\'andez-Vilas, Manuel Fern\'andez-Veiga