SearcharxivSearch

arXiv subjects

Tobias Frey

Publications and source records attributed to Tobias Frey.

4 recordsLinked to original sources

Reducing Information Overload: Because Even Security Experts Need to Blink

Computer Emergency Response Teams (CERTs) face increasing challenges processing the growing volume of security-related information. Daily manual analysis of threat reports, security advisories, and vulnerability announcements leads to information overload, contributing to burnout and attrition among security professionals. This work evaluates 196 combinations of clustering algorithms and embedding models across five security-related datasets to identify optimal approaches for automated information consolidation. We demonstrate that clustering can reduce information processing requirements by over 90% while maintaining semantic coherence, with deep clustering achieving homogeneity of 0.88 for security bug report (SBR) and partition-based clustering reaching 0.51 for advisory data. Our solution requires minimal configuration, preserves all data points, and processes new information within five minutes on consumer hardware. The findings suggest that clustering approaches can significantly enhance CERT operational efficiency, potentially saving over 3.750 work hours annually per analyst while maintaining analytical integrity. However, complex threat reports require careful parameter tuning to achieve acceptable performance, indicating areas for future optimization. The code is made available at https://github.com/PEASEC/reducing-information-overload.

cs.CR

Multi-Level Fine-Tuning, Data Augmentation, and Few-Shot Learning for Specialized Cyber Threat Intelligence

Gathering cyber threat intelligence from open sources is becoming increasingly important for maintaining and achieving a high level of security as systems become larger and more complex. However, these open sources are often subject to information overload. It is therefore useful to apply machine learning models that condense the amount of information to what is necessary. Yet, previous studies and applications have shown that existing classifiers are not able to extract specific information about emerging cybersecurity events due to their low generalization ability. Therefore, we propose a system to overcome this problem by training a new classifier for each new incident. Since this requires a lot of labelled data using standard training methods, we combine three different low-data regime techniques - transfer learning, data augmentation, and few-shot learning - to train a high-quality classifier from very few labelled instances. We evaluated our approach using a novel dataset derived from the Microsoft Exchange Server data breach of 2021 which was labelled by three experts. Our findings reveal an increase in F1 score of more than 21 points compared to standard training methods and more than 18 points compared to a state-of-the-art method in few-shot learning. Furthermore, the classifier trained with this method and 32 instances is only less than 5 F1 score points worse than a classifier trained with 1800 instances.

cs.CR

Evaluating charge noise acting on semiconductor quantum dots in the circuit quantum electrodynamics architecture

We evaluate the charge noise acting on a GaAs/GaAlAs based semiconductor double quantum dot dipole-coupled to the voltage oscillations of a superconducting transmission line resonator. The in-phase ($I$) and the quadrature ($Q$) components of the microwave tone transmitted through the resonator are sensitive to charging events in the surrounding environment of the double dot with an optimum sensitivity of $8.5\times10^{-5} \mbox{e}/\sqrt{\mbox{Hz}}$. A low frequency $1/f$ type noise spectrum combined with a white noise level of $6.6\times10^{-6}$ $\mbox{e}^2/\mbox{Hz}$ above $1$ Hz is extracted, consistent with previous results obtained with quantum point contact charge detectors on similar heterostructures. The slope of the $1/f$ noise allows to extract a lower bound for the double-dot charge qubit dephasing rate which we compare to the one extracted from a Jaynes-Cummings Hamiltonian approach. The two rates are found to be similar emphasizing that charge noise is the main source of dephasing in our system.

cond-mat.mes-hall

Single-electron Double Quantum Dot Dipole-coupled to a Single Photonic Mode

We have realized a hybrid solid-state quantum device in which a single-electron semiconductor double quantum dot is dipole coupled to a superconducting microwave frequency transmission line resonator. The dipolar interaction between the two entities manifests itself via dispersive and dissipative effects observed as frequency shifts and linewidth broadenings of the photonic mode respectively. A Jaynes-Cummings Hamiltonian master equation calculation is used to model the combined system response and allows for determining both the coherence properties of the double quantum dot and its interdot tunnel coupling with high accuracy. The value and uncertainty of the tunnel coupling extracted from the microwave read-out technique are compared to a standard quantum point contact charge detection analysis. The two techniques are found to be consistent with a superior precision for the microwave experiment when tunneling rates approach the resonator eigenfrequency. Decoherence properties of the double dot are further investigated as a function of the number of electrons inside the dots. They are found to be similar in the single-electron and many-electron regimes suggesting that the density of the confinement energy spectrum plays a minor role in the decoherence rate of the system under investigation.

cond-mat.mes-hall