SMETA-ZSL:Semantic Meta-Alignment for Zero-Shot Threat Classification
Ivan Alejandro Montoya Sanchez, Anantaa Kotal, Aritran Piplai
cs.LG, cs.AI, cs.CR
Submitted: 2026-07-10
Code: https://github.com/Security-And-Intelligence-Lab-UTEP/SMETA-ZSL
License: http://creativecommons.org/licenses/by/4.0/
The gist: Cybersecurity systems must adapt rapidly to emerging threats.
Terminology
Abstract
Cybersecurity systems must adapt rapidly to emerging threats. However, labeled data for new threat categories is unavailable when those threats first appear. Generalized zero-shot learning offers a natural solution by enabling recognition of unseen classes through auxiliary semantic knowledge rather than labeled examples. Large language models are particularly promising in this setting because they can convert unstructured CTI reports into semantic prototypes for emerging threats. However, applying language-driven zero-shot learning to cybersecurity is difficult due to strong semantic overlap between threat descriptions, heterogeneity between behavioral attributes and text, severe class imbalance, and open-set conditions where unseen threats are unknown during training. We propose SMETA-ZSL, that learns semantic prototypes from overlapping language descriptions through contrastive finetuning, aligns behavioral features through episodic meta-learning and knowledge distillation, and performs adaptive routing for generalization across seen-unseen classes. Across 7 benchmarks, SMETA-ZSL delivers the strongest overall generalized zero-shot performance under the strictest inductive setting, surpassing prior methods by 10.8 points on average, with gains up to 18.1 points. Github:https://github.com/Security-And-Intelligence-Lab-UTEP/SMETA-ZSL
Sources
- Evaluating LLM Generated Detection Rules in Cybersecurity
- Avast-CTU Public CAPE Dataset
- CTI-REALM: Benchmark to Evaluate Agent Performance on Security Detection Rule Generation Capabilities
- CLIP-driven Zero-shot Learning with Ambiguous Labels
- LLM-FS: Zero-Shot Feature Selection for Effective and Interpretable Malware Detection
- TabPFN: A Transformer That Solves Small Tabular Classification Problems in a Second
- Revisiting Concept Drift in Windows Malware Detection: Adaptation to Real Drifted Malware with Minimal Samples
- FALCON: Transforming Cyber Threat Intelligence into Deployable IDS Rules with Self-Reflection
- Generating Fake Cyber Threat Intelligence Using Transformer-Based Models
- Dual Expert Distillation Network for Generalized Zero-Shot Learning
- Fine-Grained Spoiler Detection from Large-Scale Review Corpora
- LLM Empowered Prototype Learning for Zero and Few-Shot Tasks on Tabular Data
- Zero-shot Meta-learning for Tabular Prediction Tasks with Adversarially Pre-trained Transformer
Related papers
- Polynomial-Augmented Neural Networks (PANNs) with Weak Orthogonality Constraints for Enhanced Function and PDE Approximation
- AIRL-S: Unifying Reinforcement Learning and Search-Based Test-Time Scaling via Adversarial Inverse Reinforcement Learning
- Transformers as Bayesian In-Context Experimenters: Smoothness-Adaptive Efficient ATE Estimation
- Convergence issues in Relational Concept Analysis based on AOC-posets
- Beliefs Beyond Posteriors: Local-Consistency Optimisation for Bayesian Neural Networks
- Understanding Diffusion Models via Ratio-Based Function Approximation with SignReLU Networks