MiST: Mid-Training LLMs for Cybersecurity

arXiv:2609.18496 · cs.CR, cs.AI · Submitted 2026-09-16 · Read on arXiv

cs.CR, cs.AI

Submitted: 2026-09-16

Updated: 2026-09-16

Code: https://github.com/XuanwuAI/SecEval

License: http://creativecommons.org/licenses/by/4.0/

The gist: Cybersecurity combines high-stakes analysis with complex technical language, making it an impactful and challenging domain for LLMs.

Terminology

Abstract

Cybersecurity combines high-stakes analysis with complex technical language, making it an impactful and challenging domain for LLMs. We present MiST (Mid-trained Security Transformer), a suite of 8B and 32B models that achieve strong performance on public cybersecurity benchmarks. We use mid-training as an intermediate adaptation stage between general pre-training and cybersecurity training. Rather than performing continual pre-training over large volumes of raw domain text, we curate a compact, expert-vetted seed corpus, and transform it into high-quality domain-specific synthetic training data. The final MiST checkpoints improve mean cybersecurity accuracy by +13.1 and +8.6 absolute percentage points over the corresponding Qwen baselines for 8B and 32B, respectively, corresponding to relative gains of +27.0% and +15.8%. Ablation results further show that these cybersecurity gains arise in the mid-training and supervised fine-tuning stages through a combination of the synthetic data generation flows. Furthermore, we show that MiST provides a stronger initialization for downstream task-specific fine-tuning adaptation and reinforcement learning.

Sources

Related papers