Traffic-Aware Randomized Smoothing for LLM-Based Network Intrusion Detection
TA-RS limits smoothing noise to attacker-controllable traffic features, and its certified accuracy depends heavily on noise-augmented fine-tuning.
The paper says standard randomized smoothing performs poorly on clean-trained LLM intrusion detectors, falling to 14-33% certified accuracy in three of four tested model-dataset pairs. With noise-augmented fine-tuning, TA-RS reaches 55-100% certified accuracy on CIC-IDS-2018 and HIKARI-2021 at the stated attack threshold. Its gains over isotropic smoothing are partly from avoiding noise on features an attacker cannot control, which otherwise drives high abstention. RT-IoT2022 is the weak case: the default recipe fails, but stronger noise augmentation recovers certified accuracy to 76% for LLaMA3-8B and 69% for Qwen3-8B. ArXiv · AI/CL/LG's note
The paper says standard randomized smoothing performs poorly on clean-trained LLM intrusion detectors, falling to 14-33% certified accuracy in three of four tested model-dataset pairs. With noise-augmented fine-tuning, TA-RS reaches 55-100% certified accuracy on CIC-IDS-2018 and HIKARI-2021 at the stated attack threshold. Its gains over isotropic smoothing are partly from avoiding noise on features an attacker cannot control, which otherwise drives high abstention. RT-IoT2022 is the weak case: the default recipe fails, but stronger noise augmentation recovers certified accuracy to 76% for LLaMA3-8B and 69% for Qwen3-8B. ArXiv · AI/CL/LG's note
score 4