Empirical evaluation on LID-DS-2021 shows CWE-level generalization of syscall anomaly detectors succeeds for CWE-307 (F1=0.6976 at FPR=0.05) but fails for CWE-89 and CWE-434 (F1<=0.21), with transfer strongly dependent on source normal-profile breadth.
Title resolution pending
1 Pith paper cite this work. Polarity classification is still indexing.
1
Pith paper citing it
fields
cs.CR 1years
2026 1verdicts
UNVERDICTED 1representative citing papers
citing papers explorer
-
From CVE to CWE: Syscall-Based HIDS Generalisation
Empirical evaluation on LID-DS-2021 shows CWE-level generalization of syscall anomaly detectors succeeds for CWE-307 (F1=0.6976 at FPR=0.05) but fails for CWE-89 and CWE-434 (F1<=0.21), with transfer strongly dependent on source normal-profile breadth.