SecBFF: Topology-Aware Security LLMs
Abstract
Large Language Models (LLMs) have emerged as powerful tools for reasoning over temporal event sequences in security applications. However, they are not designed to directly leverage the broader interaction topology among the entities involved, and therefore miss structural signals that are often highly indicative of anomalous behavior. To address this challenge, we propose SecBFF, a framework that makes LLMs topology-aware and improving predictive performance. A key feature of SecBFF is that it is effective even when topological information covers only a small fraction of the data. SecBFF uses Topology-Injected Masked Fine-Tuning, a strategy in which the LLM learns to condition its temporal reasoning on continuous topological tokens, without costly vocabulary modifications. Across three real-world tasks spanning Cyber-Security, Blockchain and Access Violation, SecBFF significantly improves existing approaches on both real-time and full-sequence classification. We further show that SecBFF is more robust to variation in event-sequence length.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.