Skip to content

Author

Gerhard Wunder

2 papers indexed here

We haven’t gathered this author’s papers yet. Follow them and we’ll fetch their work.

Not the right person? Other researchers publish under this name.

Conference Jul 2026

Diffu Vader: Validity-Constrained Discrete Diffusion for Flow-Level NIDS Red Teaming

Machine-learning-based network intrusion detection systems (NIDS) are increasingly evaluated with synthetic adversarial traffic, yet reported evasion rates often do not distinguish between structurally infeasible flow records and feasible network behavior. In generative NIDS research, synthetic data is more often used for augmentation than for validity-constrained adversarial generation. DiffuVader addresses this gap with a family-conditioned discrete diffusion model over a structured four-token state space. Generated samples require no gradient, query-feedback, or surrogate access and are evaluated against frozen detectors using valid evasion rate (VER), which credits only structurally valid, family-plausible samples. Evaluation uses the network-layer partition of the O-RAN testbed corpus NetsLab5GORAN-IDD under a session-disjoint chronological split with five sampling-seed uncertainty estimates. DiffuVader achieves 99.99% validity and plausibility while matching weighted replay in full-token distributional fidelity without direct row replay. A token-marginal control shows that token support alone is insufficient and learned cross-group structure is required for valid flow recovery. Per-family and duplicate analyses separate detector blindness from generator capability. Despite replay-scale fidelity, valid evasion is not reducible to exact decoded-row replay. Offline hardening exposes a trade-off between attack robustness and generated-benign calibration.

Hamed Fard, Ilya Komarov, Gerhard Wunder · 0 citations
Preprint Jul 2026

Prompt Compression via Activation Aggregation

Large language models process prompts by propagating activations through dozens of layers before generating a response. We ask whether the task-relevant information contained in an instruction prompt can be compressed into a single activation vector and re-injected into the model, replacing the original token sequence? We show this is achievable using a learned weighted sum of activations extracted at an intermediate layer and injected at an early layer of the target LLM. The compressed vector preserves task-relevant information, incurring an accuracy drop of under $2\%$ relative to full prompt processing. Beyond its practical implications, including reducing per-query computation for fixed instruction prompts without reprocessing the original token sequence, our analysis reveals structure in the activation space of LLMs: (i) mid-layer representations transfer meaningfully to early layers, suggesting a degree of cross-layer compatibility in how information is encoded; (ii) a single activation vector encodes a quantifiable and recoverable amount of semantic information; (iii) a weighted sum of activations is a robust representation compressor.

Thibaud Ardoin, Semira Einsele, Evis Bregu et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.