כתבה
arXiv cs.AI ·
בדיקה של 3 צירים של LLM נגד ML קלאסי לזיהוי פריצה לרשת תחת שינוי תפוצה והתחמקות עדפית
A Three-Axis Stress Test of LLM vs Classical ML for Network Intrusion Detection under Distribution Shift and Adversarial Evasion
במאמר זה נבדקה יכולתן של LLM ו-ML קלאסי לזיהוי פריצה לרשת, תחת שינוי תפוצה והתחמקות עדפית. התוצאות הראו שאין זוכה חד-משמעית. XGBoost ניצח בבדיקה תחת שינוי תפוצה, ו-RoBERTa-LoRA ניצחה בבדיקה תחת התחמקות עדפית. המאמר טוען שיש צורך בבדיקה של תכונות רב-ערכיות של מודלי NIDS.
תקציר מקורי באנגליתarXiv:2609.13511v1 Announce Type: cross Abstract: Large language models are increasingly benchmarked against classical machine learning for network intrusion detection (NIDS), almost always using same-dataset evaluation, and that protocol turns out to be incomplete. Evaluating XGBoost and RoBERTa-LoRA on two independently collected NetFlow v2 networks across three axes (same-dataset performance, cross-dataset transfer, and adversarial evasion) reveals no universal winner. The two models are statistically tied same-dataset. XGBoost wins decisively under cross-dataset distribution shift, by 15 points of F1 and 25 points of balanced accuracy; on the target network RoBERTa-LoRA's false positive rate reaches 0.78, leaving it barely above chance despite a superficially moderate F1. RoBERTa-LoRA
קרא במקור המקורי
arxiv.org
פתח כתבה מקורית