tag: Machine-Learning · 9 items
- Engineer — Skip
- SOC/IR — Learn: The finding that 98% of MISP events lack sector tagging quantifies a real operational gap in shared CTI value; the BERT-based approach achieving F1 0.89 for sector routing is worth tracking as a future tooling direction for CTI triage workflows.
- Leader — Learn: The statistic that nearly all shared CTI events go uncategorized by sector is a useful benchmark for conversations about the operational return on threat intel program investments; no action is required now, but it frames the value case for better-structured intel feeds.
- Engineer — Learn: Novel technique for running object detection on encrypted images without accuracy loss; worth tracking if building privacy-sensitive CV pipelines, but no production implementation or tooling is available yet.
- SOC/IR — Skip
- Leader — Skip
- Engineer — Skip
- SOC/IR — Learn: TTP-R1 automates mapping CTI prose to ATT&CK (sub-)techniques with meaningful F1 gains over LLM baselines; worth tracking if your team annotates CTI at scale, but no detection or hunt action follows from this research paper alone.
- Leader — Skip
- Engineer — Learn: Research-stage framework for privacy-preserving ML inference using partial homomorphic encryption; no production deployment target yet, but relevant for teams evaluating MLaaS privacy architectures.
- SOC/IR — Skip
- Leader — Learn: Emerging approach to MLaaS model-and-data confidentiality could inform vendor risk questions around proprietary model exposure; no near-term action required.
- Engineer — Learn: Academic research showing ordinary ambient sounds can backdoor speech recognition models at only 5% poisoning rate with no clean-accuracy drop — informs threat modeling for teams training or fine-tuning ASR models, but no specific product or actionable patch is involved.
- SOC/IR — Skip
- Leader — Skip
- Engineer — Skip
- SOC/IR — Learn: Research shows adding entropy-based features to supervised traffic classifiers reduces misclassifications in high-variability scenarios; worth evaluating if the team maintains its own ML-based detection pipeline.
- Leader — Skip
- Engineer — Skip
- SOC/IR — Learn: Academic research showing a feature-aggregation technique that improves IDS accuracy by up to 7% while cutting data volume significantly — worth tracking if evaluating or tuning ML-based network detection models, but no tooling or deployable artifact yet.
- Leader — Skip
- Engineer — Learn: Academic proposal for interpretable static PDF analysis using Tsetlin Machines; no tooling released or integrated into common pipelines, but the interpretability angle is worth tracking for teams building or evaluating ML-based malware classifiers.
- SOC/IR — Learn: The interpretability feature could eventually improve analyst trust in ML-based PDF triage, but no detection rules, IOCs, or deployable tooling accompany this research paper.
- Leader — Skip
- Engineer — Learn: Novel cross-level attack class that bridges electromagnetic/physical fault injection with algorithmic backdoors in embedded neural networks, bypassing input-space defenses. No immediate patch action — relevant if you design or deploy ML inference on embedded hardware, as it signals a new threat surface to consider during architecture review.
- SOC/IR — Skip
- Leader — Skip