PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
August 17, 2025Journal of Cybersecurity and Privacy15 citationsOpen Access

Leveraging Large Language Models for Scalable and Explainable Cybersecurity Log Analysis

View Full Paper
GPGiulia PalmaGCGaia CecchiMCMario Caronna

Key Points

  • The LLM achieved an F1-score of 0.928, outperforming traditional models like XGBoost and LightGBM.
  • LLM demonstrated superior performance with a comprehensive evaluation pipeline for cybersecurity log classification.
  • Observational analysis using LLMs integrates domain-specific techniques for automated benchmarking in cybersecurity.
  • These findings suggest that LLMs can transform operational cybersecurity, especially for small and medium enterprises.

Abstract

The increasing complexity and volume of cybersecurity logs demand advanced analytical techniques capable of accurate threat detection and explainability. This paper investigates the application of Large Language Models (LLMs), specifically qwen2.5:7b, gemma3:4b, llama3.2:3b, qwen3:8b and qwen2.5:32b to cybersecurity log classification, demonstrating their superior performance compared to traditional machine learning models such as XGBoost, Random Forest, and LightGBM. We present a comprehensive evaluation pipeline that integrates domain-specific prompt engineering, robust parsing of free-text LLM outputs, and uncertainty quantification to enable scalable, automated benchmarking. Our experiments on a vulnerability detection task show that the LLM achieves an F1-score of 0.928 (0.913, 0.942 95% CI), significantly outperforming XGBoost (0.555 0.520, 0.590) and LightGBM (0.432 0.380, 0.484). In addition to superior predictive performance, the LLM generates structured, domain-relevant explanations aligned with classical interpretability methods. These findings highlight the potential of LLMs as interpretable, adaptive tools for operational cybersecurity, making advanced threat detection feasible for SMEs and paving the way for their deployment in dynamic threat environments.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Palma et al. (2025) studied this question.

synapsesocial.com/papers/68a36f900a429f7973332788https://doi.org/10.3390/jcp5030055
Ask AI
Helpful
Bookmark
Share
View Full Paper

Also Consider

Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context:

  1. 1Leveraging Large Language Models and BERT for Log Parsing and Anomaly Detection2024 · 18 citations
  2. 2Explainability for Large Language Models: A Survey2024 · 623 citations
  3. 3Affordance-Compiled Intelligence: Observable-Only Cognitive Impedance Matching for No-Meta LLM-Integrated Systems2020 · 3,064 citations
  4. 4From Supervised to Generative: A Novel Paradigm for Tabular Deep Learning with Large Language Models2024 · 13 citations
  5. 5LightGBM: A Highly Efficient Gradient Boosting Decision Tree2017 · 9,490 citations