ModSec-Learn: Boosting ModSecurity with Machine Learning
Read the original on arXiv Machine Learning →The Flow has not summarised this story yet — read it at arXiv Machine Learning.
The Flow has not summarised this story yet — read it at arXiv Machine Learning.
The paper introduces WAPP, a framework for safely learning positive security Web Application Firewall (WAF) policies from live traffic. It combines trust filtering, deterministic rule synthesis, confidence scoring, and validation to protect against poisoned training data. Experiments on controlled applications show that WAPP improves poisoning resilience and blocks confirmed CRS bypasses, though free‑text fields still pose precision challenges.
The paper benchmarks static embedding models—Word2Vec, FastText, and Doc2Vec—for detecting anomalous HTTP requests using a single‑class classification framework. It introduces HEDA, a modular pipeline that trains both embeddings and detectors solely on benign traffic in an unsupervised setting. Experiments on synthetic and real datasets show that FastText embeddings consistently yield high detection rates with controlled false positives.
arXiv:2606. 05844v1 Announce Type: cross Abstract: Rule-based Intrusion Detection and Prevention Systems (IDPS) offer precise attack detection as well as mitigation, however their manually crafted, signature-driven rules limit adaptability to emerging and zero-day threats.
The paper presents a fast machine unlearning method that uses Hessian analysis to identify correlated training data and applies a closed‑form update rule. This approach achieves an 82× speedup over traditional influence‑function unlearning while maintaining or slightly improving model accuracy. Experiments on seven dataset‑architecture pairs, including CIFAR‑100 with ResNet‑50, show strong forgetting performance and low vulnerability to membership inference attacks.
arXiv:2601. 07177v5 Announce Type: replace-cross Abstract: Federated learning (FL) addresses privacy and data-silo issues in the training of large language models (LLMs).
arXiv:2608. 00732v1 Announce Type: new Abstract: Backdoor attacks pose a serious threat to deep neural networks, especially when training relies on third-party data, allowing adversaries to inject malicious behaviors through data poisoning.