Study stress-tests LLM and classical ML for network intrusion detection
A new arXiv paper argues that comparing large language models with classical machine learning on network intrusion detection only within a single dataset gives an incomplete picture. The authors evaluate XGBoost and a RoBERTa-LoRA model under distribution shift and adversarial evasion to probe how each approach holds up outside the usual same-dataset setup. The work highlights robustness gaps that standard benchmarks tend to miss.