Trust-Aware Iterative Monitoring for False Alarm Reduction in Intrusion Detection Systems
Bibliographic record
Abstract
In recent years with the advent of high frequency cyber activities, Intrusion Detection Systems (IDS) are an important means to keep digital environments safe from the neverending and continually escalating cyber threats.However, the main difficulty that IDS deployments encounter is the high level of false positive rates.Such false positives may cause human and computational resources to be wasted and their visibility of real threats tarnished, resulting in delayed or missed responses.The accurate prediction is not only capable of preventing infections spreading, but also endowed with potential properties of cyber forensics.Based on this research, the authors suggest a new solution, called the Iterative Monitoring Model (IMM) combined with a Trusted Trained Model (TTM) for improving the intrusion detection and substantially decreasing the false alarms.The IMM operates in perpetual learning and adaptation.Feedback from earlier detections is feedback into the training.By incorporating iterative learning and trust assessment, our model guarantees that the priority is assigned to the authentic alerts, while the misleading or legitimate anomalies are filtered.This two-model architecture increases the accuracy of detection mechanisms, builds trust in system outputs, and decreases the cognitive load on security operators.Experiments on benchmark datasets show that the proposed model outperforms traditional IDS solutions so that the false positives are improved by more than 40% with ahigh detection rate.Comparing IMM to state-of-the-art IDS models, experimental assessments showed that it improved accuracy by more than 3-4%, reaching 95.78% on the NSL-KDD dataset and 93.41% on the UNSW-NB15 dataset.With a recall of 96.42% on NSL-KDD and 94.04% on UNSW-NB15, this iterative adaptation makes sure that real dangers are almost never missed.The False Alarm Rate (FAR) drops to 2.13% on NSL-KDD and 3.45% on UNSW-NB15 because to this validation process, which is a 40% reduction compared to previous IDS solutions.Analysts can be assured that the warnings provided will be accurate because the accuracy is increased to 94.25% and 91.78%.In general, the contributions of this work are a scalable, adaptive, and reliable architecture to cyber security which can change the approach in the real time for managing network-based threats.
Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.
How this classification was reachedexpand
Full frame machine prediction
Teacher imitationNot calibrated prevalence, not ground truth. Human validation pending. The Gemma side is a direct model label for every work in the frame, read from the title-only record. The Codex side is a classifier learned from the 10,348 direct Codex labels and calibrated to design-weighted sample rates; fields without enough sample support carry no Codex call. Candidate is the union of the two sides; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels.
Distilled classifier scores by category (both heads)
| Category | Codex | Gemma |
|---|---|---|
| Metaresearch | 0.002 | 0.010 |
| Meta-epidemiology (narrow) | 0.001 | 0.001 |
| Meta-epidemiology (broad) | 0.001 | 0.001 |
| Bibliometrics | 0.001 | 0.000 |
| Science and technology studies | 0.001 | 0.001 |
| Scholarly communication | 0.001 | 0.002 |
| Open science | 0.002 | 0.001 |
| Research integrity | 0.001 | 0.002 |
| Insufficient payload (model declined to judge) | 0.001 | 0.000 |
Machine scores (provisional)
The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.
Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.
score_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from itClassification
machine, unvalidatedMachine predicted; a candidate call from one source (direct Gemma or distilled Codex), not a consensus.
How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".