惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
Visual Studio Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
N
Netflix TechBlog - Medium
博客园 - 叶小钗
大猫的无限游戏
大猫的无限游戏
S
SegmentFault 最新的问题
V
V2EX
IT之家
IT之家
J
Java Code Geeks
Hacker News - Newest:
Hacker News - Newest: "LLM"
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
GbyAI
GbyAI
D
Docker
S
Secure Thoughts
Recent Announcements
Recent Announcements
Webroot Blog
Webroot Blog
Application and Cybersecurity Blog
Application and Cybersecurity Blog
云风的 BLOG
云风的 BLOG
博客园_首页
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Security Archives - TechRepublic
Security Archives - TechRepublic
酷 壳 – CoolShell
酷 壳 – CoolShell
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
N
News | PayPal Newsroom
S
Security @ Cisco Blogs
I
InfoQ
Last Week in AI
Last Week in AI
SecWiki News
SecWiki News
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
W
WeLiveSecurity
T
Troy Hunt's Blog
Recent Commits to openclaw:main
Recent Commits to openclaw:main
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Attack and Defense Labs
Attack and Defense Labs
美团技术团队
T
The Blog of Author Tim Ferriss
Google DeepMind News
Google DeepMind News
Martin Fowler
Martin Fowler
B
Blog
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Scott Helme
Scott Helme
T
Tor Project blog
Know Your Adversary
Know Your Adversary
有赞技术团队
有赞技术团队
Hugging Face - Blog
Hugging Face - Blog
Recorded Future
Recorded Future
C
Cyber Attacks, Cyber Crime and Cyber Security
AI
AI
G
Google Developers Blog

cs.DS updates on arXiv.org

PAC Learning with Bandit Feedback: Sharp Sample Complexity in the Realizable Setting Algorithms with Polynomially-Improved Approximation Factors for the $2 \rightarrow q$ Norm, and Applications A computational phase transition for learning-to-sample from Ising models Covering vertices by sequential stars Fermi-Dirac machines as quantizations of neurons A Comprehensive Evaluation of Vertex Elimination Algorithms for Algorithmic Differentiation A Tight Bound on Localization of Electrical Flows Optimal Dimension-Free Sampling for Regularized Classification Reducing the Randomness in Partition Oracles for Bounded Degree Minor-Free Graphs Beyond the Half-Approximation: Fair and Efficient Online Class Matching Efficient Uniform Sampling of Surjections via their Profiles Tractable Maximization of Budgeted Phylogenetic Diversity on Networks Utilizing Node Scanwidth Fairness in Aggregation: Optimal Top-$k$ and Improved Full Ranking Learning-Augmented Online Scheduling with Parsimonious Preemption Entropy Equivalence Testing Lumberjack: Better Differentially Private Random Forests through Heavy Hitter Detection in Trees The Secretary Problem with a Stochastic Precursor Polynomial-Time Robust Multiclass Linear Classification under Gaussian Marginals Efficient Banzhaf-Based Data Valuation for $k$-Nearest Neighbors Classification Block-Sphere Vector Quantization An Approximation Algorithm for Graph Label Selection Iterative Chow Filtering for Learning with Distribution Shift Complexity of Non-Log-Concave Sampling in Fisher Information Stochastic Matching via Local Sparsification Finite Sample Bounds for Learning with Score Matching What is Learnable in Valiant's Theory of the Learnable? Provable Quantization with Randomized Hadamard Transform Min-Max Optimization Requires Exponentially Many Queries Fast and Compact Graph Cuts for the Boykov-Kolmogorov Algorithm A proximal gradient algorithm for composite log-concave sampling Adaptive Multi-Round Allocation with Stochastic Arrivals The tractability landscape of diffusion alignment: regularization, rewards, and computational primitives Mistake-Bounded Language Generation Positional LSH: Binary Block Matrix Approximation for Attention with Linear Biases Learning-Augmented Scalable Linear Assignment Problem Optimization via Neural Dual Warm-Starts A Note on Non-Negative $L_1$-Approximating Polynomials Curvature Beyond Positivity: Greedy Guarantees for Arbitrary Submodular Functions Convex Optimization with Nested Evolving Feasible Sets On the Complexity of the Matching Problem of Regular Expressions with Backreferences Simple KNN-Based Outlier Detection Achieves Robust Clustering Online Allocation with Unknown Shared Supply Equivalence of Coarse and Fine-Grained Models for Learning with Distribution Shift Accelerated Relax-and-Round for Concave Coverage Problems Contrastive Identification and Generation in the Limit Quantizing With Randomized Hadamard Transforms: Efficient Heuristic Now Proven Nearly Optimal Attention Coresets On Computing Total Variation Distance Between Mixtures of Product Distributions Exact and Approximate Algorithms for Polytree Learning Provable Accuracy Collapse in Embedding-Based Representations under Dimensionality Mismatch New Bounds for Kernel Sums via Fast Spherical Embeddings Unlearning Offline Stochastic Multi-Armed Bandits Matroid Algorithms Under Size-Sensitive Independence Oracles On the Learning Curves of Revenue Maximization Asymptotically Robust Learning-Augmented Algorithms for Preemptive FIFO Buffer Management Flashback: A Reversible Bilateral Run-Peeling Decomposition of Strings Incremental Strongly Connected Components with Predictions Characterizing Admissible Objective Functions for Hierarchical Clustering Well-Conditioned Oblivious Perturbations in Linear Space Mathematical Foundations for Peer-to-Peer Lattice Computation Graph Neural Network-Informed Predictive Flows for Faster Ford-Fulkerson and PAC-Learnability A weighted angle distance on strings Towards Universal Convergence of Backward Error in Linear System Solvers Constant-Factor Approximations for Doubly Constrained Fair k-Center, k-Median and k-Means Tight Bounds for Learning Polyhedra with a Margin Efficiency of Proportional Mechanisms in Online Auto-Bidding Advertising Skyline-First Traversal as a Control Mechanism for Multi-Criteria Graph Search Constant-Factor Approximation for the Uniform Decision Tree Limited Perfect Monotonical Surrogates constructed using low-cost recursive linkage discovery with guaranteed output Query Lower Bounds for Diffusion Sampling Early Pruning for Public Transport Routing Adapting Dijkstra for Buffers and Unlimited Transfers Exploiting Low-Rank Structure in Max-K-Cut Problems Partial Optimality in the Preordering Problem High-accuracy log-concave sampling with stochastic queries Learning to Approximate Uniform Facility Location via Graph Neural Networks Linear Regression with Unknown Truncation Beyond Gaussian Features Adaptive Power Iteration Method for Differentially Private PCA Finite and Corruption-Robust Regret Bounds in Online Inverse Linear Optimization under M-Convex Action Sets Learning Mixture Models via Efficient High-dimensional Sparse Fourier Transforms Variance Computation for Weighted Model Counting with Knowledge Compilation Approach Deterministic Coreset for Lp Subspace Online Algorithms for Repeated Optimal Stopping: Balancing Baseline Guarantees and Regret Learned Static Function Data Structures Optimal hypersurface decision trees A Perfectly Truthful Calibration Measure The Geometry of LLM Quantization: GPTQ as Babai's Nearest Plane Algorithm Best Agent Identification for General Game Playing A Faster Generalized Two-Stage Approximate Top-K Fast and Simple Densest Subgraph with Predictions Smoothed Analysis of Learning from Positive Samples Ineffectiveness for Search and Undecidability of PCSP Meta-Problems Sample-Efficient Optimization over Generative Priors via Coarse Learnability Efficient distributional regression trees learning algorithms for calibrated non-parametric probabilistic forecasts Testing Noise Assumptions of Learning Algorithms Testing Support Size More Efficiently Than Learning Histograms Sharper Bounds for Chebyshev Moment Matching, with Applications Expander Hierarchies for Normalized Cuts on Graphs Multilayer Correlation Clustering Efficient Parameter Estimation of Truncated Boolean Product Distributions Faster Hamiltonian Monte Carlo by Learning Leapfrog Scale: a self-calibrated randomized solution
Setting the threshold for high throughput detectors: A mathematical approach for ensembles of dynamic, heterogeneous, probabilistic anomaly detectors
Robert A. Bridges, Jessie D. Jamieson, Joel W. Reed · 2017-10-26 · via cs.DS updates on arXiv.org

Anomaly detection (AD) has garnered ample attention in security research, as such algorithms complement existing signature-based methods but promise detection of never-before-seen attacks. Cyber operations manage a high volume of heterogeneous log data; hence, AD in such operations involves multiple (e.g., per IP, per data type) ensembles of detectors modeling heterogeneous characteristics (e.g., rate, size, type) often with adaptive online models producing alerts in near real time. Because of high data volume, setting the threshold for each detector in such a system is an essential yet underdeveloped configuration issue that, if slightly mistuned, can leave the system useless, either producing a myriad of alerts and flooding downstream systems, or giving none. In this work, we build on the foundations of Ferragut et al. to provide a set of rigorous results for understanding the relationship between threshold values and alert quantities, and we propose an algorithm for setting the threshold in practice. Specifically, we give an algorithm for setting the threshold of multiple, heterogeneous, possibly dynamic detectors completely a priori, in principle. Indeed, if the underlying distribution of the incoming data is known (closely estimated), the algorithm provides provably manageable thresholds. If the distribution is unknown (e.g., has changed over time) our analysis reveals how the model distribution differs from the actual distribution, indicating a period of model refitting is necessary. We provide empirical experiments showing the efficacy of the capability by regulating the alert rate of a system with $\approx$2,500 adaptive detectors scoring over 1.5M events in 5 hours. Further, we demonstrate on the real network data and detection framework of Harshaw et al. the alternative case, showing how the inability to regulate alerts indicates the detection model is a bad fit to the data.