Traffic-Aware Randomized Smoothing for LLM IDS

Arxiv pdf 2026-07-01T00:00:00
arXiv Paper — PDF not available. Only the Executive Summary is available here. To read or download the full paper, visit the arXiv abstract page.

Abstract

Large language model (LLM)-based intrusion detection systems (IDS) are increasingly studied for security monitoring, yet their robustness against feasible traffic manipulation remains largely empirical. We present TrafficAware Randomized Smoothing (TA-RS), a classifier-agnostic certified defense that injects Gaussian noise exclusively into the directly controllable (DC) subspacefeatures a remote attacker can modifyduring both fine-tuning and certification, aligning the smoothing distribution with the attacker-controllable subspace. We identify a critical prerequisite: applying standard randomized smoothing to clean-trained LLM-IDS yields weak certified accuracy in three of four (model, dataset) pairs tested (1433%, at or below random) and only 57% in the fourth (43 pp below the noise-augmented result); noise-augmented fine-tuning recovers to 68100% on two of three benchmark datasets (at __ =0 _._ 25). At the L __ -equivalent threshold _R_ = __ _|F_ DC _|_ ( __ =0 _._ 05), TA-RS achieves 55100% certified accuracy on CIC-IDS-2018 and HIKARI-2021, with median certified radii ( _R_[] __ 0 _._ 450 _._ 96) exceeding _R_ by 1 _._ 85 __ (across __ =0 _._ 251 _._ 00). Against a fairly trained iso-trained RS baseline the residual advantage is dataset-dependent (419 pp on CIC-IDS-2018). The larger gapup to 72 pp against an isotropic RS baseline that shares the DC-noiseaugmented training recipeprimarily reflects the trainingcertification mismatch rather than DC alignment alone: isotropic test-time noise perturbs uncontrollable features the attacker cannot exploit, triggering abstention rates up to 68%. RT-IoT2022 probes the limits of the method: it fails under the default fine-tuning recipe but recovers to 76%/69% certified accuracy (LLaMA3-8B/Qwen3-8B) when noise augmentation is increased. The framework provides a principled basis for certified defenses in traffic-domain _Keywords:_ certified robustness, randomized smoothing, network intrusion detection, large language models, adversarial machine learning, traffic-aware noise

Loading executive summary...

LINK COPIED TO CLIPBOARD