Evaluating Language Models For Threat Detection in IoT Security Logs

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Tejero-Fernández, Jorge J., Sánchez-Macián, Alfonso
Formato: Preprint
Publicado: 2025
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866912462076379136
author Tejero-Fernández, Jorge J.
Sánchez-Macián, Alfonso
author_facet Tejero-Fernández, Jorge J.
Sánchez-Macián, Alfonso
contents Log analysis is a relevant research field in cybersecurity as they can provide a source of information for the detection of threats to networks and systems. This paper presents a pipeline to use fine-tuned Large Language Models (LLMs) for anomaly detection and mitigation recommendation using IoT security logs. Utilizing classical machine learning classifiers as a baseline, three open-source LLMs are compared for binary and multiclass anomaly detection, with three strategies: zero-shot, few-shot prompting and fine-tuning using an IoT dataset. LLMs give better results on multi-class attack classification than the corresponding baseline models. By mapping detected threats to MITRE CAPEC, defining a set of IoT-specific mitigation actions, and fine-tuning the models with those actions, the models are able to provide a combined detection and recommendation guidance.
format Preprint
id arxiv_https___arxiv_org_abs_2507_02390
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Evaluating Language Models For Threat Detection in IoT Security Logs
Tejero-Fernández, Jorge J.
Sánchez-Macián, Alfonso
Cryptography and Security
Artificial Intelligence
Log analysis is a relevant research field in cybersecurity as they can provide a source of information for the detection of threats to networks and systems. This paper presents a pipeline to use fine-tuned Large Language Models (LLMs) for anomaly detection and mitigation recommendation using IoT security logs. Utilizing classical machine learning classifiers as a baseline, three open-source LLMs are compared for binary and multiclass anomaly detection, with three strategies: zero-shot, few-shot prompting and fine-tuning using an IoT dataset. LLMs give better results on multi-class attack classification than the corresponding baseline models. By mapping detected threats to MITRE CAPEC, defining a set of IoT-specific mitigation actions, and fine-tuning the models with those actions, the models are able to provide a combined detection and recommendation guidance.
title Evaluating Language Models For Threat Detection in IoT Security Logs
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2507.02390