SearcharxivSearch

arXiv subjects

Lorenzo Guerra

Publications and source records attributed to Lorenzo Guerra.

11 recordsLinked to original sources

How Benchmarks and Evaluation Protocols Shape Conclusions in Provenance-Based Intrusion Detection

Provenance-based intrusion detection systems (PIDS) frequently report strong performance, but the conclusions drawn from these results can be highly sensitive to benchmarking choices and evaluation protocols. We investigate this dependency by re-evaluating representative PIDS on public datasets that meet our audit, labeling, and calibration requirements. Focusing primarily on the audited DARPA TC E3 datasets, we apply a unified protocol with temporally separated test periods and validation-only checkpoint selection and threshold calibration, and ask which architectural claims are empirically supported. We find that alerting success and investigation utility can diverge sharply, as several systems surface attacks without providing enough process-level context to support forensic investigation. Across the four primary datasets, a simple allowlist built from executable names and paths observed during training matches or exceeds the selected learned baselines on key operating-point metrics, showing that comparable performance on these metrics is achievable using lexical novelty alone. Quantifying semantic signal quality through feature completeness and field entropy helps explain why several audited E3 datasets support alerting performance without reliably separating model architectures. In contrast, Theia provides the richest semantic signal and shows the clearest improvements in ranking and node-level recovery for our reference model. Overall, these findings reinforce the importance of interpreting architectural claims in PIDS together with the benchmark properties and evaluation protocol that produced them.

cs.CR

Self-Supervised Learning of Graph Representations for Network Intrusion Detection

Detecting intrusions in network traffic is a challenging task, particularly under limited supervision and constantly evolving attack patterns. While recent works have leveraged graph neural networks for network intrusion detection, they often decouple representation learning from anomaly detection, limiting the utility of the embeddings for identifying attacks. We propose GraphIDS, a self-supervised intrusion detection model that unifies these two stages by learning local graph representations of normal communication patterns through a masked autoencoder. An inductive graph neural network embeds each flow with its local topological context to capture typical network behavior, while a Transformer-based encoder-decoder reconstructs these embeddings, implicitly learning global co-occurrence patterns via self-attention without requiring explicit positional information. During inference, flows with unusually high reconstruction errors are flagged as potential intrusions. This end-to-end framework ensures that embeddings are directly optimized for the downstream task, facilitating the recognition of malicious traffic. On diverse NetFlow benchmarks, GraphIDS achieves strong performance, reaching up to 99.98% PR-AUC and 99.61% macro F1-score.

cs.LG

On the base size and minimal degree of transitive groups

Let $G$ be a permutation group, and denote with $μ(G)$ and $b(G)$ its minimal degree and base size respectively. We show that for every $\varepsilon>0$, there exists a transitive permutation group $G$ of degree $n$ with \[ μ(G)b(G) \geq n^{2-\varepsilon}. \] We also identify some classes of transitive and intransitive groups whose base size and minimal degree have a smaller upper bound, shared with primitive groups.

math.GR

The Atiyah-Sutcliffe conjecture and $E_n$-algebras

We show that a certain conjecture by Atiyah and Sutcliffe implies the existence of an $ E_3 $-algebra (respectively $ E_2 $-algebra) structure on the disjoint union of all complex (respectively real) full flag manifolds modulo symmetric groups. Moreover, we show that these structures are liftings of exotic $ E_3 $ (respectively $ E_2 $) structures on the free $ E_\infty $-algebras on $ BU(1)+ $ (respectively $ BO(1)+ $), that do not extend to $ E_4 $ (respectively $ E_3 $) structures. We also provide some (co)homological calculations supporting the conjecture.

math.AT

AI-Driven Intrusion Detection Systems (IDS) on the ROAD Dataset: A Comparative Analysis for Automotive Controller Area Network (CAN)

The integration of digital devices in modern vehicles has revolutionized automotive technology, enhancing safety and the overall driving experience. The Controller Area Network (CAN) bus is a central system for managing in-vehicle communication between the electronic control units (ECUs). However, the CAN protocol poses security challenges due to inherent vulnerabilities, lacking encryption and authentication, which, combined with an expanding attack surface, necessitates robust security measures. In response to this challenge, numerous Intrusion Detection Systems (IDS) have been developed and deployed. Nonetheless, an open, comprehensive, and realistic dataset to test the effectiveness of such IDSs remains absent in the existing literature. This paper addresses this gap by considering the latest ROAD dataset, containing stealthy and sophisticated injections. The methodology involves dataset labelling and the implementation of both state-of-the-art deep learning models and traditional machine learning models to show the discrepancy in performance between the datasets most commonly used in the literature and the ROAD dataset, a more realistic alternative.

cs.CR

The mod-2 cohomology groups of low-dimensional unordered flag manifolds and Auerbach bases

Unordered flag manifolds are the manifolds of unordered $n$-tuple of mutually orthogonal lines in $\mathbb{R}^n$. In this paper, we develop some basic tools to compute the mod-$2$ cohomology groups of these spaces, and apply them for explicit computation for small $n$. We show that this computation improves the known estimate of the number of Auerbach bases of normed linear spaces of small dimensions.

math.AT

Cohomology of complete unordered flag manifolds

We consider quotients of complete flag manifolds in Cn and Rn by an action of the symmetric group on n objects. We compute their cohomology with field coefficients of any characteristic. Specifically, we show that these topological spaces exhibit homological stability and we provide a closed-form description of their stable cohomology rings. We also describe a simple algorithmic procedure to determine their unstable cohomology additively.

math.AT

The mod 2 cohomology of the infinite families of Coxeter groups of type B and D as almost Hopf rings

We describe a Hopf ring structure on the direct sum of the cohomology groups $\bigoplus_{n \geq 0} H^* \left( W_{B_n}; \mathbb{F}_2 \right)$ of the Coxeter groups of type $B_n$, and an almost-Hopf ring structure on the direct sum of the cohomology groups $\bigoplus_{n \geq 0} H^* \left( W_{D_n}; \mathbb{F}_2 \right)$ of the Coxeter groups of type $D_n$, with coefficient in the field with two elements $\mathbb{F}_2$. We give presentations with generators and relations, determine additive bases and compute the Steenrod algebra action. The generators are described both in terms of a geometric construction by De Concini and Salvetti and in terms of their restriction to elementary abelian 2-subgroups.

math.AT

On a notion of homotopy Segal $ E_\infty $-Hopf cooperad

We define a notion of homotopy Segal cooperad in the category of $ E_\infty $-algebras. This model of Segal cooperad that we define in the paper, which we call homotopy Segal $ E_\infty $-Hopf cooperad, covers examples given by the cochain complex of topological operads and provides a framework for the study of the homotopy of such objects. In a first step, we consider a category of Segal $ E_\infty $-Hopf cooperads, which consists of collections of $ E_\infty $-algebras indexed by trees and equipped with coproduct operators, corresponding to tree morphisms, together with facet operators, corresponding to subtree inclusions. The coproduct operators model coproducts of operations inside a tree. The facet operators are assumed to satisfy a Segal condition. The homotopy Segal cooperads that we aim to define are formed by integrating homotopies in the composition schemes of the coproduct operators. For this purpose, we replace the functorial structure that governs the composition of the coproduct operators by the structure of a homotopy functor which we shape on a cubical enrichment of the category of $ E_\infty $-algebras. We prove that every homotopy Segal $ E_\infty $-Hopf cooperad in our sense is weakly-equivalent to a strict Segal $ E_\infty $-Hopf cooperad. We also define a notion of homotopy morphism of homotopy Segal $ E_\infty $-Hopf cooperads. We prove that every homotopy Segal $ E_\infty $-Hopf cooperad admits a cobar construction and that every homotopy morphism of homotopy Segal $ E_\infty $-Hopf cooperads induces a morphism on this cobar construction, so that our approach provides a lifting to the context of $ E_\infty $-algebras of classical homotopy cooperad structures that are modeled on the bar duality of operads when we work in a category of differential graded modules.

math.AT