{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,30]],"date-time":"2026-01-30T09:47:32Z","timestamp":1769766452341,"version":"3.49.0"},"reference-count":46,"publisher":"MDPI AG","issue":"4","license":[{"start":{"date-parts":[[2023,10,19]],"date-time":"2023-10-19T00:00:00Z","timestamp":1697673600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Cryptography"],"abstract":"<jats:p>Security log collection and storage are essential for organizations worldwide. Log analysis can help recognize probable security breaches and is often required by law. However, many organizations commission log management to Cloud Service Providers (CSPs), where the logs are collected, processed, and stored. Existing methods for log anomaly detection rely on unencrypted (plaintext) data, which can be a security risk. Logs often contain sensitive information about an organization or its customers. A more secure approach is always to keep logs encrypted (ciphertext). This paper presents \u201cSigML++\u201d, an extension of \u201cSigML\u201d for supervised log anomaly detection on encrypted data. SigML++ uses Fully Homomorphic Encryption (FHE) according to the Cheon\u2013Kim\u2013Kim\u2013Song (CKKS) scheme to encrypt the logs and then uses an Artificial Neural Network (ANN) to approximate the sigmoid (\u03c3(x)) activation function probabilistically for the intervals [\u221210,10] and [\u221250,50]. This allows SigML++ to perform log anomaly detection without decrypting the logs. Experiments show that SigML++ can achieve better low-order polynomial approximations for Logistic Regression (LR) and Support Vector Machine (SVM) than existing methods. This makes SigML++ a promising new approach for secure log anomaly detection.<\/jats:p>","DOI":"10.3390\/cryptography7040052","type":"journal-article","created":{"date-parts":[[2023,10,19]],"date-time":"2023-10-19T05:43:28Z","timestamp":1697694208000},"page":"52","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["SigML++: Supervised Log Anomaly with Probabilistic Polynomial Approximation"],"prefix":"10.3390","volume":"7","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6374-7249","authenticated-orcid":false,"given":"Devharsh","family":"Trivedi","sequence":"first","affiliation":[{"name":"Stevens Institute of Technology, Hoboken, NJ 07030, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6717-8848","authenticated-orcid":false,"given":"Aymen","family":"Boudguiga","sequence":"additional","affiliation":[{"name":"CEA-List, Universit\u00e9 Paris-Saclay, 91191 Gif-sur-Yvette, France"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nesrine","family":"Kaaniche","sequence":"additional","affiliation":[{"name":"T\u00e9l\u00e9com SudParis, Institut Polytechnique de Paris, 91000 \u00c9vry, France"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nikos","family":"Triandopoulos","sequence":"additional","affiliation":[{"name":"Stevens Institute of Technology, Hoboken, NJ 07030, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2023,10,19]]},"reference":[{"key":"ref_1","unstructured":"(2023, October 16). Cloud Object Storage\u2014Amazon S3\u2014Amazon Web Services. Available online: https:\/\/aws.amazon.com\/s3\/."},{"key":"ref_2","unstructured":"(2023, October 16). Azure Blob Storage | Microsoft Azure. Available online: https:\/\/azure.microsoft.com\/en-us\/products\/storage\/blobs\/."},{"key":"ref_3","unstructured":"(2023, October 16). S.3195\u2014Consumer Online Privacy Rights Act, Available online: https:\/\/www.congress.gov\/bill\/117th-congress\/senate-bill\/3195."},{"key":"ref_4","unstructured":"(2023, October 16). TITLE 1.81.5. California Consumer Privacy Act of 2018 [1798.100\u20131798.199.100], Available online: https:\/\/leginfo.legislature.ca.gov\/faces\/codes_displayText.xhtml?division=3.&part=4.&lawCode=CIV&title=1.81.5."},{"key":"ref_5","unstructured":"(2023, October 16). EUR-Lex\u201402016R0679-20160504\u2014EN\u2014EUR-Lex. Available online: https:\/\/eur-lex.europa.eu\/eli\/reg\/2016\/679\/2016-05-04."},{"key":"ref_6","unstructured":"Durumeric, Z., Ma, Z., Springall, D., Barnes, R., Sullivan, N., Bursztein, E., Bailey, M., Halderman, J.A., and Paxson, V. (March, January 26). The Security Impact of HTTPS Interception. Proceedings of the 24th Annual Network and Distributed System Security Symposium, NDSS, San Diego, CA, USA."},{"key":"ref_7","unstructured":"(2023, October 16). Principles for the Processing of User Data by Kaspersky Security Solutions and Technologies | Kaspersky. Available online: https:\/\/usa.kaspersky.com\/about\/data-protection."},{"key":"ref_8","unstructured":"Nakashima, E. (2023, October 16). Israel hacked Kaspersky, then Tipped the NSA That Its Tools Had Been Breached. Available online: https:\/\/www.washingtonpost.com\/world\/national-security\/israel-hacked-kaspersky-then-tipped-the-nsa-that-its-tools-had-been-breached\/2017\/10\/10\/d48ce774-aa95-11e7-850e-2bdd1236be5d_story.html."},{"key":"ref_9","unstructured":"Perlroth, N., and Shane, S. (2023, October 16). How Israel Caught Russian Hackers Scouring the World for U.S. Secrets. Available online: https:\/\/www.nytimes.com\/2017\/10\/10\/technology\/kaspersky-lab-israel-russia-hacking.html."},{"key":"ref_10","unstructured":"Temperton, J. (2023, October 16). AVG Can Sell Your Browsing and Search History to Advertisers. Available online: https:\/\/www.wired.co.uk\/article\/avg-privacy-policy-browser-search-data."},{"key":"ref_11","unstructured":"Taylor, S. (2023, October 16). Is Your Antivirus Software Spying On You? | Restore Privacy. Available online: https:\/\/restoreprivacy.com\/antivirus-privacy\/."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Karande, V., Bauman, E., Lin, Z., and Khan, L. (2017, January 2\u20136). SGX-Log: Securing system logs with SGX. Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security, Abu Dhabi, United Arab Emirates.","DOI":"10.1145\/3052973.3053034"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Paccagnella, R., Datta, P., Hassan, W.U., Bates, A., Fletcher, C., Miller, A., and Tian, D. (2020, January 23\u201326). Custos: Practical tamper-evident auditing of operating systems using trusted execution. Proceedings of the Network and Distributed System Security Symposium, San Diego, CA, USA.","DOI":"10.14722\/ndss.2020.24065"},{"key":"ref_14","unstructured":"Cheon, J.H., and Takagi, T. (2016, January 4\u20138). Faster Fully Homomorphic Encryption: Bootstrapping in Less Than 0. 1 Seconds. In Proceedings of the Advances in Cryptology\u2014ASIACRYPT 2016, Hanoi, Vietnam."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Brakerski, Z. (2012, January 19\u201323). Fully Homomorphic Encryption Without Modulus Switching from Classical GapSVP. Proceedings of the 32nd Annual Cryptology Conference on Advances in Cryptology\u2014CRYPTO 2012, Santa Barbara, CA, USA.","DOI":"10.1007\/978-3-642-32009-5_50"},{"key":"ref_16","unstructured":"Fan, J., and Vercauteren, F. (2023, October 16). Somewhat Practical Fully Homomorphic Encryption. Cryptology ePrint Archive, Report 2012\/144. Available online: https:\/\/eprint.iacr.org\/2012\/144."},{"key":"ref_17","unstructured":"Cheon, J.H., Kim, A., Kim, M., and Song, Y. (2023, October 16). Homomorphic Encryption for Arithmetic of Approximate Numbers. Cryptology ePrint Archive, Report 2016\/421. Available online: https:\/\/eprint.iacr.org\/2016\/421."},{"key":"ref_18","unstructured":"Frery, J., Stoian, A., Bredehoft, R., Montero, L., Kherfallah, C., Chevallier-Mames, B., and Meyre, A. (2023). Privacy-Preserving Tree-Based Inference with Fully Homomorphic Encryption. arXiv."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Boudguiga, A., Stan, O., Sedjelmaci, H., and Carpov, S. (2020, January 25\u201327). Homomorphic Encryption at Work for Private Analysis of Security Logs. Proceedings of the ICISSP, Valletta, Malta.","DOI":"10.5220\/0008969205150523"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Trivedi, D., Boudguiga, A., and Triandopoulos, N. (2023, January 29\u201330). SigML: Supervised Log Anomaly with Fully Homomorphic Encryption. Proceedings of the International Symposium on Cyber Security, Cryptology, and Machine Learning, Beer Sheva, Israel.","DOI":"10.1007\/978-3-031-34671-2_26"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Brakerski, Z., Gentry, C., and Vaikuntanathan, V. (2023, October 16). Fully Homomorphic Encryption without Bootstrapping. Available online: https:\/\/eprint.iacr.org\/2011\/277.","DOI":"10.1145\/2090236.2090262"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Trivedi, D. (2023, January 2\u20134). Brief Announcement: Efficient Probabilistic Approximations for Sign and Compare. Proceedings of the 25th International Symposium on Stabilization, Safety, and Security of Distributed Systems, Jersey City, NJ, USA.","DOI":"10.1007\/978-3-031-44274-2_21"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Zhao, J., Mortier, R., Crowcroft, J., and Wang, L. (2018, January 2\u20137). Privacy-preserving machine learning based data analytics on edge devices. Proceedings of the 2018 AAAI\/ACM Conference on AI, Ethics, and Society, New Orleans, LA, USA.","DOI":"10.1145\/3278721.3278778"},{"key":"ref_24","unstructured":"Wang, L. (2023, October 16). Owl: A General-Purpose Numerical Library in OCaml, Available online: http:\/\/xxx.lanl.gov\/abs\/1707.09616."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"323","DOI":"10.1109\/JSYST.2012.2221958","article-title":"Secure logging as a service\u2014Delegating log management to the cloud","volume":"7","author":"Ray","year":"2013","journal-title":"IEEE Syst. J."},{"key":"ref_26","unstructured":"(2023, October 16). The Tor Project | Privacy & Freedom Online. Available online: https:\/\/www.torproject.org\/."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Zawoad, S., Dutta, A.K., and Hasan, R. (2013, January 8\u201310). SecLaaS: Secure logging-as-a-service for cloud forensics. Proceedings of the 8th ACM SIGSAC Symposium on Information, Computer and Communications Security, Hangzhou, China.","DOI":"10.1145\/2484313.2484342"},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"148","DOI":"10.1109\/TDSC.2015.2482484","article-title":"Towards building forensics enabled cloud through secure logging-as-a-service","volume":"13","author":"Zawoad","year":"2015","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Rane, S., and Dixit, A. (2019, January 9\u201311). BlockSLaaS: Blockchain assisted secure logging-as-a-service for cloud forensics. Proceedings of the International Conference on Security & Privacy, Jaipur, India.","DOI":"10.1007\/978-981-13-7561-3_6"},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Bittau, A., Erlingsson, \u00da., Maniatis, P., Mironov, I., Raghunathan, A., Lie, D., Rudominer, M., Kode, U., Tinnes, J., and Seefeld, B. (2017, January 28\u201331). Prochlo: Strong privacy for analytics in the crowd. Proceedings of the 26th Symposium on Operating Systems Principles, Shanghai, China.","DOI":"10.1145\/3132747.3132769"},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"132084","DOI":"10.1109\/ACCESS.2021.3114581","article-title":"Privacy-Preserving Collective Learning With Homomorphic Encryption","volume":"9","author":"Paul","year":"2021","journal-title":"IEEE Access"},{"key":"ref_32","first-page":"2825","article-title":"Scikit-learn: Machine Learning in Python","volume":"12","author":"Pedregosa","year":"2011","journal-title":"J. Mach. Learn. Res."},{"key":"ref_33","first-page":"337","article-title":"Sur le calcul effectif des polynomes d\u2019approximation de Tschebyscheff","volume":"199","author":"Remez","year":"1934","journal-title":"CR Acad. Sci. Paris"},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1186\/s12920-018-0397-z","article-title":"Logistic regression over encrypted data from fully homomorphic encryption","volume":"11","author":"Chen","year":"2018","journal-title":"BMC Med. Genom."},{"key":"ref_35","unstructured":"(2023, October 16). Module: tf.keras.losses | TensorFlow v2.13.0. Available online: https:\/\/www.tensorflow.org\/api_docs\/python\/tf\/keras\/losses."},{"key":"ref_36","unstructured":"(2023, October 16). API Reference. Available online: https:\/\/scikit-learn.org\/stable\/modules\/classes.html#module-sklearn.metrics."},{"key":"ref_37","unstructured":"Huelse (2022, May 09). Huelse\/Seal-Python: Microsoft Seal 4.x for Python. Available online: https:\/\/github.com\/Huelse\/SEAL-Python."},{"key":"ref_38","unstructured":"Buitinck, L., Louppe, G., Blondel, M., Pedregosa, F., Mueller, A., Grisel, O., Niculae, V., Prettenhofer, P., Gramfort, A., and Grobler, J. (2013, January 23\u201327). API design for machine learning software: Experiences from the scikit-learn project. Proceedings of the ECML PKDD Workshop: Languages for Data Mining and Machine Learning, Prague, Czech Republic."},{"key":"ref_39","unstructured":"Canadian Institute for Cybersecurity (2023, October 16). NSL-KDD | Datasets | Research | Canadian Institute for Cybersecurity. Available online: https:\/\/www.unb.ca\/cic\/datasets\/nsl.html."},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Tavallaee, M., Bagheri, E., Lu, W., and Ghorbani, A.A. (2009, January 8\u201310). A detailed analysis of the KDD CUP 99 data set. Proceedings of the 2009 IEEE Symposium on Computational Intelligence for Security and Defense Applications, Ottawa, ON, Canada.","DOI":"10.1109\/CISDA.2009.5356528"},{"key":"ref_41","unstructured":"He, S., Zhu, J., He, P., and Lyu, M.R. (2008). Loghub: A Large Collection of System Log Datasets towards Automated Log Analytics. arXiv."},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"He, P., Zhu, J., Zheng, Z., and Lyu, M.R. (2017, January 25\u201330). Drain: An online log parsing approach with fixed depth tree. Proceedings of the 2017 IEEE International Conference on Web Services (ICWS), Honolulu, HI, USA.","DOI":"10.1109\/ICWS.2017.13"},{"key":"ref_43","unstructured":"Trivedi, D. (2023, October 16). GitHub-Devharsh\/Chiku: Polynomial Function Approximation Library in Python. Available online: https:\/\/github.com\/devharsh\/chiku."},{"key":"ref_44","doi-asserted-by":"crossref","unstructured":"Cheon, J.H., Kim, D., Kim, D., Lee, H.H., and Lee, K. (2019, January 8\u201312). Numerical method for comparison on homomorphically encrypted numbers. Proceedings of the International Conference on the Theory and Application of Cryptology and Information Security, Kobe, Japan.","DOI":"10.1007\/978-3-030-34621-8_15"},{"key":"ref_45","doi-asserted-by":"crossref","first-page":"3711","DOI":"10.1109\/TDSC.2021.3105111","article-title":"Minimax approximation of sign function by composite polynomial for homomorphic comparison","volume":"19","author":"Lee","year":"2021","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"ref_46","unstructured":"Boura, C., Gama, N., Georgieva, M., and Jetchev, D. (2023, October 16). CHIMERA: Combining Ring-LWE-Based Fully Homomorphic Encryption Schemes. Cryptology ePrint Archive, Report 2018\/758. Available online: https:\/\/eprint.iacr.org\/2018\/758."}],"container-title":["Cryptography"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2410-387X\/7\/4\/52\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T21:09:39Z","timestamp":1760130579000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2410-387X\/7\/4\/52"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,10,19]]},"references-count":46,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2023,12]]}},"alternative-id":["cryptography7040052"],"URL":"https:\/\/doi.org\/10.3390\/cryptography7040052","relation":{},"ISSN":["2410-387X"],"issn-type":[{"value":"2410-387X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,10,19]]}}}