arXiv Machine Learning By Christian Scano, Giuseppe Floris, Biagio Montaruli, Luca Demetrio, Andrea Valenza, Luca Compagna, Davide Ariu, Luca Piras, Davide Balzarotti, Battista Biggio

ModSec-Learn: Boosting ModSecurity with Machine Learning

Read the original on arXiv Machine Learning →

The Flow has not summarised this story yet — read it at arXiv Machine Learning.

arXiv AI
Sep 10

WAPP: Safe Learning of Positive Security WAF Policies from Live Traffic

The paper introduces WAPP, a framework for safely learning positive security Web Application Firewall (WAF) policies from live traffic. It combines trust filtering, deterministic rule synthesis, confidence scoring, and validation to protect against poisoned training data. Experiments on controlled applications show that WAPP improves poisoning resilience and blocks confirmed CRS bypasses, though free‑text fields still pose precision challenges.

By Heba Osama, Zeyad Ahmed, Mohamed Amgad, Ahmed Saafan, Jana Elfeky, Mariam Abdelati, Haitham Ghalwash
arXiv AI
Sep 24

Comparative Evaluation of Static Embedding Models for HTTP Request Anomaly Detection

The paper benchmarks static embedding models—Word2Vec, FastText, and Doc2Vec—for detecting anomalous HTTP requests using a single‑class classification framework. It introduces HEDA, a modular pipeline that trains both embeddings and detectors solely on benign traffic in an unsupervised setting. Experiments on synthetic and real datasets show that FastText embeddings consistently yield high detection rates with controlled false positives.

By Amanda Riverol, Gustavo Betarte, Rodrigo Mart\'inez, \'Alvaro Pardo
arXiv Machine Learning
Sep 14

Correlation-Guided Fast Machine Unlearning via Hessian Analysis

The paper presents a fast machine unlearning method that uses Hessian analysis to identify correlated training data and applies a closed‑form update rule. This approach achieves an 82× speedup over traditional influence‑function unlearning while maintaining or slightly improving model accuracy. Experiments on seven dataset‑architecture pairs, including CIFAR‑100 with ResNet‑50, show strong forgetting performance and low vulnerability to membership inference attacks.

By Ayushi Thakur, Ruchir Gupta, Amit Kumar Jaiswal, Prayag Tiwari