כתבה
arXiv cs.LG ·
בדיקה של שלושה צירים של LLM ו-ML קלאסי לזיהוי פריצה לרשת תחת שינוי תפוצה והתחמקות
A Three-Axis Stress Test of LLM vs Classical ML for Network Intrusion Detection under Distribution Shift and Adversarial Evasion
במאמר זה נבדקו LLM ו-ML קלאסי לזיהוי פריצה לרשת תחת שינוי תפוצה והתחמקות. התוצאות הראו שאין זוכה יחידה, והבחירה במודל תלויה בציר שבו נבדק.
תקציר מקורי באנגליתarXiv:2609.13511v1 Announce Type: new Abstract: Large language models are increasingly benchmarked against classical machine learning for network intrusion detection (NIDS), almost always using same-dataset evaluation, and that protocol turns out to be incomplete. Evaluating XGBoost and RoBERTa-LoRA on two independently collected NetFlow v2 networks across three axes (same-dataset performance, cross-dataset transfer, and adversarial evasion) reveals no universal winner. The two models are statistically tied same-dataset. XGBoost wins decisively under cross-dataset distribution shift, by 15 points of F1 and 25 points of balanced accuracy; on the target network RoBERTa-LoRA's false positive rate reaches 0.78, leaving it barely above chance despite a superficially moderate F1. RoBERTa-LoRA wi
קרא במקור המקורי
arxiv.org
פתח כתבה מקורית