[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-82014-en":3,"doc-seo-82014-105":30,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},82014,7971461740886,"Theodore","https://ap-avatar.wpscdn.com/davatar_3d24733baf745e90a7e4bdd5f77d97b2",8,"Research & Report","Controllability-Aware Adversarial Examples Against LLM-Based Network Traffic Classifiers","Large language models (LLMs) are increasingly used as network intrusion detection classifiers, yet adversarial robustness under realistic attacker constraints is not well understood. A controllability-aware black-box transfer framework partitions flow features into directly controllable (DC), indirectly controllable (IC), and uncontrollable (UC) groups, then restricts perturbations to DC while freezing IC/UC. Finite-difference PGD, greedy coordinate-wise, and NES examples are generated with a shared XGBoost surrogate and transferred across multiple IDS benchmarks and 27 LLM configurations, showing substantial, dataset- and comparator-dependent LLM vulnerability.","Controllability-Aware Adversarial Examples Against LLM-Based Network Traffic Classifiers  \nZhenpeng Li  \narXiv :2607 .07739v 1 [ cs .CR] 8 Jul 2026  \nAbstract—Large language models (LLMs) are increasingly explored as network intrusion detection classifiers, but their adversarial robustness under realistic attacker constraints remains unclear. We present a controllability-aware black-box transfer framework for LLM-based network traffic classifiers. The framework partitions flow features into directly controllable (DC), indirectly controllable (IC), and uncontrollable (UC) groups according to network communication semantics, then restricts perturbations to DC features while freezing IC/UC features. Using a shared XGBoost surrogate, we generate finitedifference PGD, greedy coordinate-wise, and NES adversarial examples and transfer them to seven LLM targets and two conventional ML targets across five IDS benchmarks from 1999 to 2022. Across 27 valid LLM configurations and over 500,000 adversarial examples, we find that LLM transfer vulnerability is substantial but dataset- and comparator-dependent. Compared with LightGBM, LLMs are more vulnerable on RT-IoT2022 and CIC-IDS-2018, comparable on NSL-KDD and UNSW-NB15, and less vulnerable on HIKARI-2021; compared with the averaged ML baseline, LLMs show higher ASR on all five datasets. We further observe a consistent cross-architecture transfer hierarchy: gradient-and score-based perturbations transfer more effectively than greedy perturbations across all 27 LLM cells and 9/10 ML cells. Cross-surrogate validation with tree, neural, and linear surrogates yields similar LLM ASR, reducing evidence that the findings are XGBoost-specific. Constraint violation rate is 0% by construction.  \nIndex Terms—Adversarial machine learning, large language models, network intrusion detection, transfer attacks, semantic constraints.  \nI. INTRODUCTION  \nThe use of large language models for network intrusion detection is an active research direction, driven by their ability to process heterogeneous flow features as natural language descriptions [1], [2] . While production deployment remains limited, commercial systems such as Microsoft Copilot for Security already integrate LLMs into security operations pipelines, processing network telemetry alongside threat intelligence. Whether LLM-based classifiers can be evaded through controllability-constrained traffic modifications is therefore a concrete security question: production-integrated LLMs processing live network telemetry can be targeted by adversaries with access only to public data and a local classifier.  \nAdversarial robustness of traditional ML-based intrusion detection systems (IDS) has been studied extensively [3],[4], [5] . However, existing work suffers from two limitations when applied to the LLM-IDS setting. First, most attacks  \nZ. Li is with Guangzhou Health Science College, GuangYuanZhong Road 248, Guangzhou, Guangdong 510405, China (e-mail: [2025301001@gzws.edu.cn](2025301001@gzws.edu.cn)). Corresponding author. Manuscript received—; revised—; accepted—.  \nperturb arbitrary features without respecting the attacker’s operational constraints—an attacker cannot control response bytes from a remote server, nor dictate aggregated statistics computed by network monitors. Second, no prior work evaluates whether adversarial transferability—the dominant practical attack vector—behaves differently when the target is a Transformer-based language model versus a gradient-boosted tree or neural network.  \nWe address both gaps through three contributions:  \n(C1) Controllability-Aware Attack Framework. We formalize an attacker capability taxonomy that classifies network flow features into Directly Controllable (DC), Indirectly Controllable (IC), and Uncontrollable (UC) categories, grounded in the physical semantics of network communication (Section III) . Adversarial perturbations are restricted to DC features, producing examples that are more realistic","cbCaia5BDt6otKeG","https://ap.wps.com/l/cbCaia5BDt6otKeG","pdf",521763,5,1,13,"English","en",105,"# Introduction\n# Related Work","[{\"question\":\"What is the controllability-aware framework proposed for LLM-based network traffic classifiers?\",\"answer\":\"It groups network flow features into directly controllable (DC), indirectly controllable (IC), and uncontrollable (UC) based on communication semantics, and restricts adversarial perturbations to DC features while freezing IC/UC features.\"},{\"question\":\"How are adversarial examples generated and transferred in the study?\",\"answer\":\"Using a shared XGBoost surrogate, the framework generates finite-difference PGD, greedy coordinate-wise, and NES adversarial examples and transfers them to multiple LLM targets and conventional ML targets under a black-box transfer threat model.\"},{\"question\":\"What determines the level of LLM vulnerability reported in the results?\",\"answer\":\"The vulnerability is substantial but depends on the dataset and comparator; LLMs show higher ASR versus the averaged ML baseline on all five datasets, while comparisons against LightGBM vary by dataset and show a consistent cross-architecture transfer hierarchy.\"}]",1784177578,33,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"controllability-aware-adversarial-examples-against-llm-based-network-traffic-classifiers","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/controllability-aware-adversarial-examples-against-llm-based-network-traffic-classifiers/82014/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":24,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-04","2026-07-16",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What is the controllability-aware framework proposed for LLM-based network traffic classifiers?","Question",{"text":76,"@type":77},"It groups network flow features into directly controllable (DC), indirectly controllable (IC), and uncontrollable (UC) based on communication semantics, and restricts adversarial perturbations to DC features while freezing IC/UC features.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"How are adversarial examples generated and transferred in the study?",{"text":81,"@type":77},"Using a shared XGBoost surrogate, the framework generates finite-difference PGD, greedy coordinate-wise, and NES adversarial examples and transfers them to multiple LLM targets and conventional ML targets under a black-box transfer threat model.",{"name":83,"@type":74,"acceptedAnswer":84},"What determines the level of LLM vulnerability reported in the results?",{"text":85,"@type":77},"The vulnerability is substantial but depends on the dataset and comparator; LLMs show higher ASR versus the averaged ML baseline on all five datasets, while comparisons against LightGBM vary by dataset and show a consistent cross-architecture transfer hierarchy.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":93},[94,98,102,106,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":20,"slug":138},19,"General","general"]