{"id":"https://openalex.org/W4412446464","doi":"https://doi.org/10.1109/noms57970.2025.11073574","title":"Explainable Anomaly Detection in Network Traffic Using LLM","display_name":"Explainable Anomaly Detection in Network Traffic Using LLM","publication_year":2025,"publication_date":"2025-05-12","ids":{"openalex":"https://openalex.org/W4412446464","doi":"https://doi.org/10.1109/noms57970.2025.11073574"},"language":"en","primary_location":{"id":"doi:10.1109/noms57970.2025.11073574","is_oa":false,"landing_page_url":"https://doi.org/10.1109/noms57970.2025.11073574","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"NOMS 2025-2025 IEEE Network Operations and Management Symposium","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5084472511","display_name":"Kamil Je\u0159\u00e1bek","orcid":"https://orcid.org/0000-0002-5317-9222"},"institutions":[{"id":"https://openalex.org/I60587646","display_name":"Brno University of Technology","ror":"https://ror.org/03613d656","country_code":"CZ","type":"education","lineage":["https://openalex.org/I60587646"]}],"countries":["CZ"],"is_corresponding":true,"raw_author_name":"Kamil Jerabek","raw_affiliation_strings":["Brno University of Technology,Czech Republic"],"affiliations":[{"raw_affiliation_string":"Brno University of Technology,Czech Republic","institution_ids":["https://openalex.org/I60587646"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5087179836","display_name":"Josef Koumar","orcid":"https://orcid.org/0000-0002-3643-9723"},"institutions":[{"id":"https://openalex.org/I44504214","display_name":"Czech Technical University in Prague","ror":"https://ror.org/03kqpb082","country_code":"CZ","type":"education","lineage":["https://openalex.org/I44504214"]}],"countries":["CZ"],"is_corresponding":false,"raw_author_name":"Josef Koumar","raw_affiliation_strings":["Czech Technical University in Prague,Prague,Czech Republic"],"affiliations":[{"raw_affiliation_string":"Czech Technical University in Prague,Prague,Czech Republic","institution_ids":["https://openalex.org/I44504214"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5094198624","display_name":"Ji\u0159\u00ed Setinsk\u00fd","orcid":"https://orcid.org/0009-0008-6085-3642"},"institutions":[{"id":"https://openalex.org/I60587646","display_name":"Brno University of Technology","ror":"https://ror.org/03613d656","country_code":"CZ","type":"education","lineage":["https://openalex.org/I60587646"]}],"countries":["CZ"],"is_corresponding":false,"raw_author_name":"Ji\u0159\u00ed Setinsk\u00fd","raw_affiliation_strings":["Brno University of Technology,Czech Republic"],"affiliations":[{"raw_affiliation_string":"Brno University of Technology,Czech Republic","institution_ids":["https://openalex.org/I60587646"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5033867729","display_name":"Jaroslav Pe\u0161ek","orcid":"https://orcid.org/0000-0003-1634-9779"},"institutions":[{"id":"https://openalex.org/I44504214","display_name":"Czech Technical University in Prague","ror":"https://ror.org/03kqpb082","country_code":"CZ","type":"education","lineage":["https://openalex.org/I44504214"]}],"countries":["CZ"],"is_corresponding":false,"raw_author_name":"Jaroslav Pesek","raw_affiliation_strings":["Czech Technical University in Prague,Prague,Czech Republic"],"affiliations":[{"raw_affiliation_string":"Czech Technical University in Prague,Prague,Czech Republic","institution_ids":["https://openalex.org/I44504214"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5084472511"],"corresponding_institution_ids":["https://openalex.org/I60587646"],"apc_list":null,"apc_paid":null,"fwci":2.8599,"has_fulltext":false,"cited_by_count":1,"citation_normalized_percentile":{"value":0.9186161,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":91,"max":95},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"6"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12127","display_name":"Software System Performance and Reliability","score":0.9951000213623047,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/anomaly-detection","display_name":"Anomaly detection","score":0.6714955568313599},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6576758623123169},{"id":"https://openalex.org/keywords/anomaly","display_name":"Anomaly (physics)","score":0.45249930024147034},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.41350215673446655},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.26064759492874146}],"concepts":[{"id":"https://openalex.org/C739882","wikidata":"https://www.wikidata.org/wiki/Q3560506","display_name":"Anomaly detection","level":2,"score":0.6714955568313599},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6576758623123169},{"id":"https://openalex.org/C12997251","wikidata":"https://www.wikidata.org/wiki/Q567560","display_name":"Anomaly (physics)","level":2,"score":0.45249930024147034},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.41350215673446655},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.26064759492874146},{"id":"https://openalex.org/C26873012","wikidata":"https://www.wikidata.org/wiki/Q214781","display_name":"Condensed matter physics","level":1,"score":0.0},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/noms57970.2025.11073574","is_oa":false,"landing_page_url":"https://doi.org/10.1109/noms57970.2025.11073574","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"NOMS 2025-2025 IEEE Network Operations and Management Symposium","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":18,"referenced_works":["https://openalex.org/W3198800015","https://openalex.org/W4205175770","https://openalex.org/W4385567765","https://openalex.org/W4387210439","https://openalex.org/W4389519589","https://openalex.org/W4394946189","https://openalex.org/W4399062286","https://openalex.org/W4402354012","https://openalex.org/W4404570461","https://openalex.org/W4405469618","https://openalex.org/W4407977840","https://openalex.org/W4409261757","https://openalex.org/W4412445116","https://openalex.org/W6856553793","https://openalex.org/W6868980394","https://openalex.org/W6874220539","https://openalex.org/W6874572380","https://openalex.org/W7061142228"],"related_works":["https://openalex.org/W2806741695","https://openalex.org/W4290647774","https://openalex.org/W3189286258","https://openalex.org/W3207797160","https://openalex.org/W3210364259","https://openalex.org/W4300558037","https://openalex.org/W2667207928","https://openalex.org/W2912112202","https://openalex.org/W4377864969","https://openalex.org/W3120251014"],"abstract_inverted_index":{"Network":[0],"anomaly":[1,39,60],"detection":[2,40],"is":[3],"essential":[4],"for":[5,77],"modern":[6],"cybersecurity,":[7],"yet":[8],"existing":[9],"systems":[10],"often":[11],"generate":[12],"numerous":[13],"alerts":[14],"without":[15],"clear":[16],"explanations,":[17],"leading":[18],"to":[19,42,92],"inefficiencies":[20],"and":[21,99],"high":[22],"false-positive":[23],"rates.":[24],"This":[25],"paper":[26],"proposes":[27],"a":[28],"novel":[29],"approach":[30,83],"that":[31],"integrates":[32],"Large":[33],"Language":[34],"Models":[35],"(LLMs)":[36],"with":[37],"an":[38],"framework":[41],"enhance":[43,93],"explainability":[44],"in":[45],"network":[46,86],"traffic":[47,87],"analysis.":[48],"Instead":[49],"of":[50],"directly":[51],"detecting":[52],"anomalies,":[53],"the":[54],"LLM":[55,72],"only":[56],"interprets":[57],"already":[58],"flagged":[59],"events,":[61],"providing":[62],"insights":[63],"into":[64],"their":[65],"potential":[66],"root":[67],"causes.":[68],"Our":[69],"method":[70],"reduces":[71],"over-usage":[73],"while":[74],"improving":[75],"decision-making":[76],"security":[78],"analysts.":[79],"We":[80],"evaluated":[81],"our":[82],"using":[84],"real-world":[85],"data,":[88],"demonstrating":[89],"its":[90],"ability":[91],"situational":[94],"awareness,":[95],"reduce":[96],"false":[97],"positives,":[98],"support":[100],"more":[101],"effective":[102],"cybersecurity":[103],"practices.":[104]},"counts_by_year":[{"year":2025,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
