0% Complete
صفحه اصلی
/
دومین همایش بین المللی هوش مصنوعی
Federated LLM-Based SIEM with Meta-Model Aggregation: Enabling Collaborative, Scalable, and Privacy-Preserving Threat Detection
نویسندگان :
Masoud GanjKhani
1
Alireza Shameli-Sendi
2
1- دانشگاه شهید بهشتی
2- دانشگاه شهید بهشتی
کلمات کلیدی :
Federated SIEM،LLM،MITRE ATT&CK،Privacy-Preserving Classification،Knowledge Sharing
چکیده :
The escalating sophistication of cyber threats necessitates a paradigm shift from traditional, isolated Security Information and Event Management (SIEM) systems toward intelligent, collaborative defense frameworks. This paper presents a novel Federated Large Language Model (LLM)-Based SIEM architecture that combines privacy-preserving federated learning principles with the advanced reasoning capabilities of LLMs for distributed network intrusion detection. Our approach enables multiple security nodes to collaboratively learn and improve detection accuracy by sharing abstracted attack patterns rather than sensitive raw traffic data, thereby ensuring strict privacy preservation. To provide structured threat intelligence and standardized attack taxonomy, all network intrusions are classified according to the MITRE ATT&CK framework, enabling alignment with industry-standard threat modeling and facilitating interoperability with existing security infrastructure. Experimental validation demonstrates that the proposed system achieves 79.4% overall accuracy with a 7.2% improvement across five federated learning cycles, successfully detecting 11 distinct attack categories mapped to MITRE ATT&CK techniques, including Reconnaissance (Port Scan - 97.1%), Resource Hijacking (DoS/DDoS), Credential Access (Brute Force - 100%), and Initial Access (SQL Injection, Phishing). The distributed architecture comprises three autonomous nodes sharing a centralized knowledge base that accumulates 98 validated detection rules through collaborative learning, with Brute Force attacks achieving perfect 100% detection accuracy. This work demonstrates that LLM-based federated learning can deliver competitive detection performance while maintaining data sovereignty and providing interpretable, MITRE-aligned threat intelligence for modern SIEM deployments.
لیست مقالات
لیست مقالات بایگانی شده
Strategies and Future Horizons of Innovative Entrepreneurship in AI-Based Programming
Milad Ghiasspour
Hybrid ANN and Ant Colony Algorithm for IoT Data Classification
Khadejeh Nemati - Safouro Ashoori - Moohamad hadi Amini
Performance Analysis of Variational Quantum Classifiers for Classification Tasks in the NISQ Era
Saghar Kiani - Paria Kamalpour - Sarina Ghafouri - Niloofar Mirzaei Chahardeh
Cross-Dataset Empirical Evaluation of NSGA-II for Multi-Objective Feature Selection in Intrusion Detection Systems
Mahdis Rahmani - Fereshteh-Azadi Parand
Development and Validation of an Explainable Machine Learning Framework for Decision Support in Student Admission Management
Hananeh Teshnehlab - Mohammad Reza Ayatollahzadeh Shirazi
AI-Driven Materials Genome: Accelerated Discovery of Multi-Functional Sensing Materials
Farzane Hasheminia - Sadegh Sadeghzadeh - Behrouz Minaei-Bidgoli
Title Generation for the Qur'anic chapters by summarizing them
Masoume Maleki - Alireza Talebpour - Mostafa Moradi
White blood cell image analysis using CNN model
Fahimeh Jahanbakhshi - Hamid Latifi
Comparative Study of Criminal Responsibility of AI in the Legal Framework of Iran and Saudi Arabia
Zahra Meghdadi - Mahdi Pourcheriki
Inferring organizational duties from Persian administrative and employment laws using Large Language Models (LLMs) and few-shot learning
Hojjat Hajizadeh Nowkhandan - Mohsen Kahani
بیشتر
ثمین همایش، سامانه مدیریت کنفرانس ها و جشنواره ها - نگارش 44.5.0