Research

Paper

AI LLM March 24, 2026

CSTS: A Canonical Security Telemetry Substrate for AI-Native Cyber Detection

Authors

Abdul Rahman

Abstract

AI-driven cybersecurity systems often fail under cross-environment deployment due to fragmented, event-centric telemetry representations. We introduce the Canonical Security Telemetry Substrate (CSTS), an entity-relational abstraction that enforces identity persistence, typed relationships, and temporal state invariants. Across heterogeneous environments, CSTS improves cross-topology transfer for identity-centric detection and prevents collapse under schema perturbation. For zero-day detection, CSTS isolates semantic orientation instability as a modeling, not schema, phenomenon, clarifying layered portability requirements.

Metadata

arXiv ID: 2603.23459
Provider: ARXIV
Primary Category: cs.CR
Published: 2026-03-24
Fetched: 2026-03-25 06:02

Related papers

Raw Data (Debug)
{
  "raw_xml": "<entry>\n    <id>http://arxiv.org/abs/2603.23459v1</id>\n    <title>CSTS: A Canonical Security Telemetry Substrate for AI-Native Cyber Detection</title>\n    <updated>2026-03-24T17:30:03Z</updated>\n    <link href='https://arxiv.org/abs/2603.23459v1' rel='alternate' type='text/html'/>\n    <link href='https://arxiv.org/pdf/2603.23459v1' rel='related' title='pdf' type='application/pdf'/>\n    <summary>AI-driven cybersecurity systems often fail under cross-environment deployment due to fragmented, event-centric telemetry representations. We introduce the Canonical Security Telemetry Substrate (CSTS), an entity-relational abstraction that enforces identity persistence, typed relationships, and temporal state invariants. Across heterogeneous environments, CSTS improves cross-topology transfer for identity-centric detection and prevents collapse under schema perturbation. For zero-day detection, CSTS isolates semantic orientation instability as a modeling, not schema, phenomenon, clarifying layered portability requirements.</summary>\n    <category scheme='http://arxiv.org/schemas/atom' term='cs.CR'/>\n    <category scheme='http://arxiv.org/schemas/atom' term='cs.LG'/>\n    <published>2026-03-24T17:30:03Z</published>\n    <arxiv:comment>21 pages including 1 appendix</arxiv:comment>\n    <arxiv:primary_category term='cs.CR'/>\n    <author>\n      <name>Abdul Rahman</name>\n    </author>\n  </entry>"
}