論文の概要: Reliable Remediation Impact Prediction for Black-Box Security Ratings
- arxiv url: http://arxiv.org/abs/2607.16357v1
- Date: Fri, 17 Jul 2026 09:58:38 GMT
- ステータス: 翻訳完了
- システム内更新日: 2026-07-21 18:48:37.130039
- Title: Reliable Remediation Impact Prediction for Black-Box Security Ratings
- Title(参考訳): ブラックボックスセキュリティレーティングの信頼性向上効果予測
- Authors: Nada Hanad, Mehdi Acheli, Ali NourEldin, Mohamed Sellami, Walid Gaaloul,
- Abstract要約: そこで本稿では,修正スコアによる影響予測のためのサロゲートに基づくアプローチを提案する。
商用セキュリティ評価プラットフォームから5,188の組織構成の実際のデータセットに対するアプローチを評価した。
- 参考スコア(独自算出の注目度): 0.3044748118797888
- License: http://creativecommons.org/licenses/by/4.0/
- Abstract: Security rating platforms summarize externally observable cyber exposure and are expected to help organizations prioritize remediation. A platform may want to tell an organization how a candidate remediation action would affect its score, but repeatedly exposing exact score responses can reveal information about the hidden scoring engine. We propose a surrogate based approach for remediation score impact prediction that is designed to respect this opacity constraint. The surrogate predicts scores from organization configurations while explicitly representing checkpoint (i.e., a security check) applicability and the observed checkpoint set. A main challenge is that such predictions are not uniformly reliable: they depend on the amount and structure of the observable checkpoint evidence available for a given configuration. To address this, the approach combines applicability-aware surrogate construction, sensitivity analysis under controlled checkpoint restriction, a reliability layer for identifying unstable predictions, and score-impact prediction for supported remediation actions. Explicit modeling of checkpoint applicability is central throughout: it improves score prediction and provides the feature basis used by the reliability layer to identify unstable cases. We evaluate the approach on a real-world dataset of 5,188 organization configurations from a commercial security rating platform. The results show that the applicability-aware surrogate improves score prediction over simpler feature representations. For remediation, the surrogate predicts the score impact of supported actions, while the reliability layer helps identify cases in which these predicted impacts should be interpreted cautiously.
- Abstract(参考訳): セキュリティ評価プラットフォームは、外部から監視可能なサイバー暴露を要約し、組織が修復を優先するのに役立つと期待されている。
プラットフォームは、候補の修正アクションがそのスコアにどのように影響するかを組織に伝えたいかもしれませんが、正確なスコアのレスポンスを繰り返すと、隠れたスコアエンジンに関する情報が明らかになります。
本稿では,この不透明度制約を尊重するために設計された,修正スコア影響予測のためのサロゲートに基づくアプローチを提案する。
シュロゲートは、チェックポイント(セキュリティチェック)の適用性と観察されたチェックポイントセットを明確に表現しながら、組織構成からスコアを予測する。
主な課題は、そのような予測が一様に信頼性がないことである。それらは与えられた構成で利用可能な観測可能なチェックポイントの証拠の量と構造に依存している。
この問題に対処するため,本手法では,適用可能性を考慮したサロゲート構築,制御されたチェックポイント制限下での感度解析,不安定な予測を識別する信頼性層,支援された修復動作に対するスコア・インパクト予測を組み合わせる。
スコア予測を改善し、不安定なケースを特定するために信頼性層が使用する特徴ベースを提供する。
商用セキュリティ評価プラットフォームから5,188の組織構成の実際のデータセットに対するアプローチを評価した。
その結果,適用性を考慮したサロゲートは,より単純な特徴表現よりもスコア予測を改善することがわかった。
修復のために、サロゲートはサポートされたアクションのスコアの影響を予測し、信頼性層はこれらの予測された影響が慎重に解釈されるべきケースを特定するのに役立つ。
関連論文リスト
- Uncertainty-Driven Reliability: Selective Prediction and Trustworthy Deployment in Modern Machine Learning [1.2183405753834562]
この論文は、不確実性推定が機械学習(ML)システムの安全性と信頼性を高める方法について考察する。
まず、モデルのトレーニング軌道は、アーキテクチャの変更や損失を伴わずに活用できるような、豊富な不確実性信号を含むことを示す。
本稿では,タスク間で動作し,深層アンサンブルのコストを回避し,最先端の選択的予測性能を実現する軽量なポストホック禁忌手法を提案する。
論文 参考訳(メタデータ) (2025-08-11T02:33:53Z) - Statistical Inference for Responsiveness Verification [15.571656327462142]
本稿では,これらの特徴に対する介入に関して,予測の応答性に関する形式的検証手順を導入する。
ブラックボックスアクセスのみを用いて,モデルおよびデータセットの予測に対する応答性を推定する方法を述べる。
到達可能な点の均一なサンプルを生成することによって,これらの推定値を構成するアルゴリズムを開発する。
論文 参考訳(メタデータ) (2025-07-02T21:50:08Z) - Confidential Guardian: Cryptographically Prohibiting the Abuse of Model Abstention [65.47632669243657]
不正直な機関は、不確実性の観点からサービスを差別または不正に否定する機構を利用することができる。
我々は、ミラージュと呼ばれる不確実性誘導攻撃を導入することで、この脅威の実践性を実証する。
本研究では,参照データセット上のキャリブレーションメトリクスを分析し,人工的に抑制された信頼度を検出するフレームワークであるConfidential Guardianを提案する。
論文 参考訳(メタデータ) (2025-05-29T19:47:50Z) - Aurora: Are Android Malware Classifiers Reliable and Stable under Distribution Shift? [51.12297424766236]
AURORAは、その信頼性と運用上のレジリエンスに基づいて、マルウェア分類器を評価するためのフレームワークである。
AURORAは、ポイント・イン・タイムのパフォーマンスを超えるように設計されたメトリクスのセットによって補完される。
さまざまなドリフトのデータセットにわたるSOTAフレームワークの脆弱性は、ホワイトボードへの復帰の必要性を示唆している。
論文 参考訳(メタデータ) (2025-05-28T20:22:43Z) - PredictaBoard: Benchmarking LLM Score Predictability [50.47497036981544]
大きな言語モデル(LLM)は予測不能に失敗することが多い。
これは、安全なデプロイメントを保証する上で、大きな課題となる。
PredictaBoardは,新しいベンチマークフレームワークである。
論文 参考訳(メタデータ) (2025-02-20T10:52:38Z) - Criticality and Safety Margins for Reinforcement Learning [53.10194953873209]
我々は,定量化基盤真理とユーザにとっての明確な意義の両面から,批判的枠組みを定めようとしている。
エージェントがn連続的ランダム動作に対するポリシーから逸脱した場合の報酬の減少として真臨界を導入する。
我々はまた、真の臨界と統計的に単調な関係を持つ低オーバーヘッド計量であるプロキシ臨界の概念も導入する。
論文 参考訳(メタデータ) (2024-09-26T21:00:45Z) - Per-frame mAP Prediction for Continuous Performance Monitoring of Object
Detection During Deployment [6.166295570030645]
本稿では,デプロイメント中のパフォーマンスモニタリングに対するイントロスペクションアプローチを提案する。
フレーム当たりの平均精度がクリティカルしきい値以下になると予測する。
我々は,誤った判断を下すことによってリスクを低減する手法の能力を定量的に評価し,実証する。
論文 参考訳(メタデータ) (2020-09-18T06:37:52Z)
関連論文リストは本サイト内にある論文のタイトル・アブストラクトから自動的に作成しています。
指定された論文の情報です。
本サイトの運営者は本サイト(すべての情報・翻訳含む)の品質を保証せず、本サイト(すべての情報・翻訳含む)を使用して発生したあらゆる結果について一切の責任を負いません。