SoK : The Impact of Unlabelled Data in Cyberthreat Detection

dc.contributor.authorApruzzese, Giovanni
dc.contributor.authorLaskov, Pavel
dc.contributor.authorTastemirova, Aliya
dc.contributor.departmentDepartment of Computer Science
dc.date.accessioned2026-09-24T14:07:01Z
dc.date.available2026-09-24T14:07:01Z
dc.date.issued2022
dc.descriptionPublisher Copyright: © 2022 IEEE.en
dc.description.abstractMachine learning (ML) has become an important paradigm for cyberthreat detection (CTD) in the recent years. A substantial research effort has been invested in the development of specialized algorithms for CTD tasks. From the operational perspective, however, the progress of ML-based CTD is hindered by the difficulty in obtaining the large sets of labelled data to train ML detectors. A potential solution to this problem are semisupervised learning (SsL) methods, which combine small labelled datasets with large amounts of unlabelled data. This paper is aimed at systematization of existing work on SsL for CTD and, in particular, on understanding the utility of unlabelled data in such systems. To this end, we analyze the cost of labelling in various CTD tasks and develop a formal cost model for SsL in this context. Building on this foundation, we formalize a set of requirements for evaluation of SsL methods, which elucidates the contribution of unlabelled data. We review the state-of-the-art and observe that no previous work meets such requirements. To address this problem, we propose a framework for assessing the benefits of unlabelled data in SsL. We showcase an application of this framework by performing the first benchmark evaluation that highlights the tradeoffs of 9 existing SsL methods on 9 public datasets. Our findings verify that, in some cases, unlabelled data provides a small, but statistically significant, performance gain. This paper highlights that SsL in CTD has a lot of room for improvement, which should stimulate future research in this field.en
dc.description.versionPeer revieweden
dc.format.extent23
dc.format.extent4710380
dc.format.extent20-42
dc.format.extent
dc.identifier.citationApruzzese, G, Laskov, P & Tastemirova, A 2022, SoK : The Impact of Unlabelled Data in Cyberthreat Detection. in Proceedings - 7th IEEE European Symposium on Security and Privacy, Euro S and P 2022. Proceedings - 7th IEEE European Symposium on Security and Privacy, Euro S and P 2022, Institute of Electrical and Electronics Engineers Inc., pp. 20-42, 7th IEEE European Symposium on Security and Privacy, Euro S and P 2022, Genoa, Italy, 6/06/22. https://doi.org/10.1109/EuroSP53844.2022.00010en
dc.identifier.citationconferenceen
dc.identifier.doi10.1109/EuroSP53844.2022.00010
dc.identifier.isbn9781665416146
dc.identifier.other250863677
dc.identifier.other80146fa2-4cfe-45b8-a2f5-f9f7b26b00ea
dc.identifier.other85134037507
dc.identifier.urihttps://hdl.handle.net/20.500.11815/8359
dc.language.isoen
dc.publisherInstitute of Electrical and Electronics Engineers Inc.
dc.relation.ispartofseriesProceedings - 7th IEEE European Symposium on Security and Privacy, Euro S and P 2022; ()en
dc.relation.ispartofseriesProceedings - 7th IEEE European Symposium on Security and Privacy, Euro S and P 2022; ()en
dc.relation.urlhttps://www.scopus.com/pages/publications/85134037507en
dc.rightsinfo:eu-repo/semantics/openAccessen
dc.subjectcybersecurityen
dc.subjectlabellingen
dc.subjectmachine learningen
dc.subjectsemisupervised learningen
dc.subjectthreat detectionen
dc.subjectArtificial Intelligenceen
dc.subjectComputer Networks and Communicationsen
dc.subjectInformation Systemsen
dc.subjectInformation Systems and Managementen
dc.subjectSafety, Risk, Reliability and Qualityen
dc.titleSoK : The Impact of Unlabelled Data in Cyberthreat Detectionen
dc.type/dk/atira/pure/researchoutput/researchoutputtypes/contributiontobookanthology/conferenceen

Skrár

Original bundle

Niðurstöður 1 - 1 af 1
Nafn:
SoK_The_Impact_of_Unlabelled_Data_in_Cyberthreat_Detection.pdf
Stærð:
4.49 MB
Snið:
Adobe Portable Document Format