{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T19:03:54Z","timestamp":1782846234385,"version":"3.54.5"},"reference-count":0,"publisher":"ECMS","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026,6,23]]},"abstract":"<jats:p>Bot traffic in e-commerce HTTP data incurs costs and is increasingly difficult to identify, while reliable \u201cbot vs. human\u201d ground-truth labels are rarely available for the most problematic agents. In this paper, we propose a reproducible and auditable evaluation setting with the use of large language models (LLMs) to generate web traffic categorization pipeline specifications from log data. LLMs are not used as black-box detectors, or for code generation. Instead, we formulate a controlled specification task: given an anonymized HTTP log sample, each LLM produces a structured JSON specification of a bot-categorization pipeline (token taxonomy and precedence, normalization, feature definitions, and deterministic silver-label rules). The specification is then compiled into a deterministic pipeline and evaluated automatically on a full day of production e-commerce server logs without using ground-truth labels. We assess risk-oriented clustering robustness via bootstrap stability and compare induced behavioral structure across specifications using Adjusted Mutual Information (AMI). Results show that several models recover highly similar session-clustering structure, although they differ substantially in risk-tier policies when clusters are mapped to operational tiers (HIGH risk, MEDIUM risk, LOW risk, OTHER, NOISE) using deterministic, interpretable rules. This reveals specification bias as a practical deployment concern: models may agree on behavioral structure while disagreeing on what should be treated as high risk.<\/jats:p>","DOI":"10.7148\/2026-0694","type":"proceedings-article","created":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T18:08:43Z","timestamp":1782842923000},"page":"694-703","source":"Crossref","is-referenced-by-count":0,"title":["Using llms to generate auditable pipeline specifications for risk-tier assignment from http server logs"],"prefix":"10.7148","author":[{"given":"Grazyna","family":"Suchacka","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Grzegorz","family":"Chodak","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jacek","family":"Iwanski","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"4144","published-online":{"date-parts":[[2026,6,23]]},"event":{"name":"40th ECMS International Conference on Modelling and Simulation"},"container-title":["ECMS 2026 Proceedings edited by Filippo Sanfilippo, Florenc Demrozi, Fabio Sgarbossa, Mohammad Poursina"],"original-title":[],"deposited":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T18:08:46Z","timestamp":1782842926000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.scs-europe.net\/dlib\/2026\/ecms2026acceptedpapers\/0694_dis_ecms2026_0122.pdf"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,23]]},"references-count":0,"URL":"https:\/\/doi.org\/10.7148\/2026-0694","relation":{},"subject":[],"published":{"date-parts":[[2026,6,23]]}}}