Pith. sign in

REVIEW 8 cited by

Revolutionizing Cyber Threat Detection with Large Language Models: A privacy-preserving BERT-based Lightweight Model for IoT/IIoT Devices

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2306.14263 v2 pith:OM2QF2OK submitted 2023-06-25 cs.CR cs.AI

classification cs.CRcs.AI
keywords securitybertdetectionnetworkscyberdeviceslanguagemodelmodels
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

The field of Natural Language Processing (NLP) is currently undergoing a revolutionary transformation driven by the power of pre-trained Large Language Models (LLMs) based on groundbreaking Transformer architectures. As the frequency and diversity of cybersecurity attacks continue to rise, the importance of incident detection has significantly increased. IoT devices are expanding rapidly, resulting in a growing need for efficient techniques to autonomously identify network-based attacks in IoT networks with both high precision and minimal computational requirements. This paper presents SecurityBERT, a novel architecture that leverages the Bidirectional Encoder Representations from Transformers (BERT) model for cyber threat detection in IoT networks. During the training of SecurityBERT, we incorporated a novel privacy-preserving encoding technique called Privacy-Preserving Fixed-Length Encoding (PPFLE). We effectively represented network traffic data in a structured format by combining PPFLE with the Byte-level Byte-Pair Encoder (BBPE) Tokenizer. Our research demonstrates that SecurityBERT outperforms traditional Machine Learning (ML) and Deep Learning (DL) methods, such as Convolutional Neural Networks (CNNs) or Recurrent Neural Networks (RNNs), in cyber threat detection. Employing the Edge-IIoTset cybersecurity dataset, our experimental analysis shows that SecurityBERT achieved an impressive 98.2% overall accuracy in identifying fourteen distinct attack types, surpassing previous records set by hybrid solutions such as GAN-Transformer-based architectures and CNN-LSTM models. With an inference time of less than 0.15 seconds on an average CPU and a compact model size of just 16.7MB, SecurityBERT is ideally suited for real-life traffic analysis and a suitable choice for deployment on resource-constrained IoT devices.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 8 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Controllability-Aware Adversarial Examples Against LLM-Based Network Traffic Classifiers

    cs.CR 2026-07 conditional novelty 6.5 of 10

    Under DC-only transfer attacks, LLM IDS vulnerability is substantial but dataset- and comparator-dependent, with gradient/score attacks transferring better than greedy ones.

  2. MM-AttacKG: A Multimodal Approach to Attack Graph Construction with Large Language Models

    cs.CR 2025-06 conditional novelty 6.0 of 10

    MM-AttacKG is a pipeline that uses multimodal LLMs to extract threat information from images in cyber threat reports and merge it into text-derived attack graphs, improving entity, relation, and technique coverage.

  3. Non-Degenerate Risk Certification for Automated Security Decisions: A Decision-Contract Theory with ATT\&CK-Aligned Triage as a Worked Instance

    cs.CR 2026-08 conditional novelty 5.0 of 10

    The paper formalizes why unconditional risk bounds on automated decisions are vacuous and proposes an actionability certificate that jointly bounds error and floors automation, demonstrated on LLM security triage.

  4. Interpretable Anomaly-Based DDoS Detection in AI-RAN with XAI and LLMs

    cs.CR 2025-07 conditional novelty 4.0 of 10

    An LSTM trained on 5G key performance measurements detects DDoS attacks from user equipment with F1 above 0.96, while LIME, SHAP, and an LLM convert decisions into human-readable explanations and suggested mitigations.

  5. Forewarned is Forearmed: A Survey on Large Language Model-based Agents in Autonomous Cyberattacks

    cs.NI 2025-05 conditional novelty 4.0 of 10

    A review of LLM-based agents as autonomous cyberattackers, arguing that they lower attack costs, scale up threats, and outpace existing defenses.

  6. From Texts to Shields: Convergence of Large Language Models and Cybersecurity

    cs.CR 2025-05 unverdicted novelty 2.0 of 10

    A workshop report outlining how large language models and agentic AI can be applied to cybersecurity, together with open challenges and a proposed research roadmap.

  7. The Future of Internet of Things and Multimodal Language Models in 6G Networks: Opportunities and Challenges

    cs.CY 2025-04 conditional novelty 2.0 of 10

    A narrative survey arguing that combining IoT, multimodal language models, and 6G can improve smart applications, with a taxonomy of sensors, communication, processing, and security.

  8. Integrating Artificial Open Generative Artificial Intelligence into Software Supply Chain Security

    cs.CR 2024-12 reject novelty 2.0 of 10

    An under-specified evaluation of five open LLMs on vulnerability and deprecated-code detection reports moderate average scores (60.4 to 67.0) but lacks baselines, data, and reproducibility.

Pith tools