Next-generation cyberattack detection with large language models: anomaly analysis across heterogeneous logs

📅 2026-02-06
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the limitations of traditional intrusion detection systems, which struggle to effectively identify cross-heterogeneous-log cyberattacks due to high false-positive rates, semantic blind spots, and log scarcity. To overcome these challenges, the authors propose a two-stage training paradigm based on large language models (LLMs): first fine-tuning the base model Base-AMAN 3B for foundational security understanding, then distilling this knowledge into a lightweight AMAN 0.5B model for real-time detection. The work introduces LogAtlas, a privacy-preserving, well-annotated log dataset series, and highlights the inadequacy of conventional evaluation metrics in security contexts, advocating instead for task-oriented assessment. The resulting system achieves per-session inference in 0.3–0.5 seconds with daily operational costs under $50, demonstrating the practical feasibility and efficiency of LLMs in real-world cybersecurity applications.

Technology Category

Application Category

📝 Abstract
This project explores large language models (LLMs) for anomaly detection across heterogeneous log sources. Traditional intrusion detection systems suffer from high false positive rates, semantic blindness, and data scarcity, as logs are inherently sensitive, making clean datasets rare. We address these challenges through three contributions: (1) LogAtlas-Foundation-Sessions and LogAtlas-Defense-Set, balanced and heterogeneous log datasets with explicit attack annotations and privacy preservation; (2) empirical benchmarking revealing why standard metrics such as F1 and accuracy are misleading for security applications; and (3) a two phase training framework combining log understanding (Base-AMAN, 3B parameters) with real time detection (AMAN, 0.5B parameters via knowledge distillation). Results demonstrate practical feasibility, with inference times of 0.3-0.5 seconds per session and operational costs below 50 USD per day.
Problem

Research questions and friction points this paper is trying to address.

cyberattack detection
anomaly detection
heterogeneous logs
intrusion detection systems
log data scarcity
Innovation

Methods, ideas, or system contributions that make the work stand out.

large language models
anomaly detection
heterogeneous logs
knowledge distillation
cybersecurity benchmarking
💼 Related Jobs
No related jobs found.
Y
Yassine Chagna
School of Engineering, Coventry University, Coventry, UK
A
Antal Goldschmidt
School of Engineering, Coventry University, Coventry, UK