Sep 2026· Zenodo (CERN European Organization for Nuclear Research)
Abstract
Large language models now write detection rules, and the work evaluating them asks whether the rules catch attacks. It does not ask what they cost on a quiet day. That cost sits in the exclusion clause the "alert when X, except when Y" half of a rule, which encodes local knowledge of what is benign here. Prior work reports that generated rules reach only 8.9% exclusion parity with human rules, but it compares rule text and never runs the rules, so the operational cost of that gap is unknown. We run them: 626 SigmaHQ rules, 384,191 benign Windows events from a public seven-host corpus, and an open-source engine. Deleting the exclusions multiplies alert volume by 3.6x to 29x on telemetry that contains no attack. Nine LLM configurations across five model families, writing rules for the same requirements from the same threat description, all raise more benign alerts than the human rule 1.4x to 34.6x on an identical requirement set. The quietest arms are quiet for the wrong reason: they stay silent on 40–67% of requirements, which on an attack-free corpus is indistinguishable from broken. Quietness and silence rank as near mirror images (Spearman rho = -0.852, n = 9, p < 0.01), so a false-positive rate reported without a silence rate is not interpretable and no prior work reports one. The exclusions models do write are guesses shaped like knowledge: they name what a threat report implies and miss what only operating a fleet teaches. All rules, data, and code are public, and the study re-runs end to end in under an hour on a laptop.
The results are packaged in the Greenfield Startup Model (GSM), which explains the priority of startups to release the product as quickly as possible, and the need to shorten time-to-market, by speeding up the development through low-precision engineering activities.
Carmine Giardino, Nicolò Paternoster, M. Unterkalmsteiner et al.· IEEE Transactions on Softwar...· 178 citations· ⚡14
Software startup companies develop innovative, software-intensive products within limited timeframes and with few resources, searching for sustainable and scalable business models.
M. Unterkalmsteiner, P. Abrahamsson, Xiaofeng Wang et al.· e-Informatica Software Engin...· 157 citations· ⚡17
This study conducts a case survey study based on the secondary data of the major pivots happened in 49 software startups, and demonstrates that customer need pivot is the most common among all pivot types.
Sohaib Shahid Bajwa, Xiaofeng Wang, Anh Nguyen-Duc et al.· Empirical Software Engineeri...· 127 citations· ⚡15
The comparison of adopter and non-adopter sample reveals three potential adoption inhibitor, security, data privacy, and portability, which underlines the importance of the technical and security perspectives for research investigating the adoption of technology.
Nattakarn Phaphoom, Xiaofeng Wang, S. Samuel et al.· Journal of Systems and Softw...· 111 citations· ⚡8
The ongoing work building a Raspberry Pi cluster consisting of 300 nodes is presented, with potential use cases being an inexpensive and green test bed for cloud computing research and a robust and mobile data center for operating in adverse environments.
P. Abrahamsson, S. Helmer, Nattakarn Phaphoom et al.· IEEE International Conferenc...· 110 citations· ⚡7
The results indicate that software developers are a slightly happy population, but the need for limiting the unhappiness of developers remains, and 219 factors representing causes of unhappiness while developing software are identified.
D. Graziotin, Fabian Fagerholm, Xiaofeng Wang et al.· International Conference on...· 84 citations· ⚡6
Related blog posts
MIT News · Artificial Intelligence· news.mit.eduSep 14, 2026
The “HardFlow” algorithm could help generative AI models produce high-quality outputs that obey strict requirements when “pretty close” doesn’t cut it.
AI may appear weightless, but every model depends on physical infrastructure. To understand responsible AI, we need to look beyond algorithms and consider the entire lifecycle of the hardware behind them. The post Responsible AI Must Consider Its Afterlife appeared first on GPT-Lab.