acceptodds
Under review as a conference paper at ICLR 2027

SecBFF: Topology-Aware Security LLMs

Abstract

Large Language Models (LLMs) have emerged as powerful tools for reasoning over temporal event sequences in security applications. However, they are not designed to directly leverage the broader interaction topology among the entities involved, and therefore miss structural signals that are often highly indicative of anomalous behavior. To address this challenge, we propose SecBFF, a framework that makes LLMs topology-aware and improving predictive performance. A key feature of SecBFF is that it is effective even when topological information covers only a small fraction of the data. SecBFF uses Topology-Injected Masked Fine-Tuning, a strategy in which the LLM learns to condition its temporal reasoning on continuous topological tokens, without costly vocabulary modifications. Across three real-world tasks spanning Cyber-Security, Blockchain and Access Violation, SecBFF significantly improves existing approaches on both real-time and full-sequence classification. We further show that SecBFF is more robust to variation in event-sequence length.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.