---
格式版本: 2
标题: "From Noise to Signal: Improving Security Log Anomaly Detection Using LLMs with Endpoint-Specific Logs"
原文链接: "https://arxiv.org/abs/2608.19938"
发布日期: "2026-08-20"
发布时间校准状态: "found"
发布时间需复核: "否"
发布时间来源: "rule:local:strict_original_body"
发布时间证据: "**\\[v1\\]** Thu, 20 Aug 2026 11:54:56 UTC (743 KB)"
发布时间校准原因: "规则确认唯一严格发布时间，来源 local:strict_original_body"
发布时间校准置信度: "high"
发布时间候选数量: 18
发布时间严格候选数量: 6
发布时间原页读取状态: "source template page reused from URL open"
发布时间未找到原因: ""
发布时间校准时间: "2026-08-21T16:17:32+08:00"
发布时间仲裁状态: "skipped"
发布时间仲裁尝试次数: 0
发布时间仲裁耗时毫秒: 0
发现时间: "2026-08-21T16:16:43+08:00"
入库时间: "2026-08-21T08:17:33.063Z"
来源平台: "arXiv 学术论文搜索"
搜索渠道: "source_template"
搜索词: "https://arxiv.org/search/?query=Meta&searchtype=all"
匹配关键词:
  - "performance"
  - "latency"
相关厂家:
  - "Meta"
相关专家:
  []
内容类型: "网页"
抓取工具: "Free Fetch + Defuddle"
清洗工具: "Defuddle Markdown + Defuddle/Readability 正文提取"
原始附件:
  []
AI优质: "否"
AI打分: 8
AI分档: "非优质"
AI质检状态: "不通过"
AI打分理由: "该资料为arXiv安全日志异常检测论文，涉及LLM与认证日志，与超节点/AI Rack/机柜级AI基础设施、高速互连、供电、液冷等关注主题完全无关，且来源为学术论文入口页，无商业或部署信号。"
AI质检模型: "ali-deepseek-v4-flash"
AI质检时间: "2026-08-21T16:17:37+08:00"
AI主题相关性: 2
AI来源权威性: 5
AI新颖性: 1
AI技术细节: 0
AI商业部署信号: 0
AI完整性: 0
AI摘要: "该研究提出一种基于指令的LLM分类框架，用于检测端点特定认证日志中的异常行为，并在自制测试床上评估三个指令微调模型。"
AI摘要模型: "ali-deepseek-v4-flash"
AI摘要时间: "2026-09-07T02:12:17.552Z"
采集批次: "2026年8月21日13点55分53秒"
采集批次ID: "20260821-135553-743"
去重键: "https://arxiv.org/abs/2608.19938"
---

## Computer Science > Cryptography and Security

## Title:From Noise to Signal: Improving Security Log Anomaly Detection Using LLMs with Endpoint-Specific Logs

Authors:[Christopher Henshaw](https://arxiv.org/search/cs?searchtype=author&query=Henshaw,+C), [Gour Karmakar](https://arxiv.org/search/cs?searchtype=author&query=Karmakar,+G)

[View PDF](https://arxiv.org/pdf/2608.19938)

> Abstract:Existing approaches to anomalous behaviour log detection, such as Wazuh rely primarily on predefined detection rules, while statistical anomaly detection approaches such as OpenSearch identify deviations from previously observed behavioural patterns. Recent research has investigated LLMs for log anomaly detection because of their ability to interpret semantic and contextual information. However, LLM-based approaches can be affected by prompt construction, noisy log data, and reliance on generic datasets that may lack endpoint-specific authentication behaviours. To address these limitations, this study develops a standardised instruction-based LLM classification framework for detecting anomalous authentication behaviours, including borderline cases. A controlled cybersecurity testbed was developed to generate endpoint-specific authentication data, producing a curated dataset comprising normal, borderline, and anomalous behavioural scenarios. Three instruction-tuned LLMs, Meta Llama 3.1 8B Instruct, Qwen 2.5 7B Instruct, and GPT-OSS 20B, were evaluated against Wazuh rule-based detection and OpenSearch Anomaly Detection using a common ground-truth severity framework. Meta Llama 3.1 8B Instruct achieved the strongest overall end-to-end detection performance, with an accuracy of 89.3%, recall of 88.2%, F1-score of 91.8%, and false negative rate of 11.8%. In comparison, Wazuh achieved an accuracy of 52.0% and false negative rate of 68.6%, while OpenSearch achieved an accuracy of 49.3% and false negative rate of 74.5%. Meta Llama also detected 80% of the borderline anomalous scenarios, compared with 20% for Wazuh and 15% for OpenSearch. Qwen achieved lower overall detection performance than Meta Llama but recorded the lowest average inference latency and 100% structured-response validity. GPT-OSS demonstrated strong classification performance when valid responses were produced.

| Comments: |  |
| --- | --- |
| Subjects: | Cryptography and Security (cs.CR); Machine Learning (cs.LG) |
| Cite as: | [arXiv:2608.19938](https://arxiv.org/abs/2608.19938) \[cs.CR\] |
|  | (or [arXiv:2608.19938v1](https://arxiv.org/abs/2608.19938v1) \[cs.CR\] for this version) |
|  | [https://doi.org/10.48550/arXiv.2608.19938](https://doi.org/10.48550/arXiv.2608.19938) |

## Submission history

From: Gour Karmakar \[[view email](https://arxiv.org/show-email/0bba88d9/2608.19938)\]  
**\[v1\]** Thu, 20 Aug 2026 11:54:56 UTC (743 KB)

[Which authors of this paper are endorsers?](https://arxiv.org/auth/show-endorsers/2608.19938) | Disable MathJax ([What is MathJax?](https://info.arxiv.org/help/mathjax.html))
