Jadwal Sholat

Memuat jadwal sholat…

Ilmu Komputer & AI editorial

Open AccessOA2026

Identifying Security Platform Product Abuse with Machine Learning

A whole-system defense against living-off-the-land attacks in SaaS security platforms
Shaefer Drew; Michael Brautbar; Paul Knight; Edward Raff; Lana Peric-McDermott; Simran Sarin; Nickolas Machado; Hanna Albright; Vitaly Zaytsev· 2026· DOI 10.48550/arXiv.2609.21303

The core problem

Product abuse—the misuse of security platforms by threat actors—is a rare but growing problem in the SaaS industry. Sophisticated actors employ living-off-the-land (LOTL) techniques to evade traditional malware detection, either by misusing platform features within customer environments or by probing the product itself for bypasses. Detecting such abuse is challenging due to its intrinsic rarity (cold-start problem), the need to integrate multiple data modalities across disparate databases, and real-world deployment constraints including cost, user behavior, and performance. This work provides the first study of a whole-system defense for product abuse, specifically focusing on a deployed and operational capability. The authors address these challenges by designing a machine learning system that operates within operational limits while effectively identifying malicious behavior.

Innovation

The deployed system demonstrated significant improvements: a 35% increase in product abuse coverage and a 30% reduction in monthly alerts. This indicates that the machine learning approach not only detects more abuse incidents but also reduces noise, alleviating alert fatigue for security teams. The adaptability to changes in malicious actors' behavior was also validated, suggesting the system can evolve with emerging threats. A retrospective evaluation highlighted the value of explainable features and counterfactual performance on previously identified attacks, providing insights into why certain detections were made and how the model might perform under different conditions. These results underscore the effectiveness of the whole-system defense in a real-world operational setting.
Product abuse—the misuse of security platforms by threat actors—is a rare but growing problem in the SaaS industry. Sophisticated actors employ living-off-the-land (LOTL) techniques to evade traditional malware detection, either by misusing platform features within customer environments or by probing the product itself for bypasses. Detecting such abuse is challenging due to its intrinsic rarity (cold-start problem), the need to integrate multiple data modalities across disparate databases, and real-world deployment constraints including cost, user behavior, and performance. This work provides the first study of a whole-system defense for product abuse, specifically focusing on a deployed and operational capability. The authors address these challenges by designing a machine learning system that operates within operational limits while effectively identifying malicious behavior.
The proposed system collects and integrates data from multiple modalities—such as logs, user activity, and product telemetry—across different database types. To handle the cold-start problem due to the rarity of abuse events, the authors likely employ techniques such as anomaly detection, semi-supervised learning, or transfer learning. The system is designed with operational constraints in mind: cost efficiency, minimal impact on user experience, and real-time performance. The machine learning pipeline may include feature engineering from explainable features, model training with counterfactual evaluation, and continuous adaptation to evolving attacker behavior. The architecture is depicted in the Mermaid diagram below, illustrating data flow from various sources through preprocessing, feature extraction, model inference, and alert generation.

Why it matters

The study addresses key challenges in deploying machine learning for security: data integration across modalities, cold-start due to rare events, and operational constraints. The success in increasing coverage while reducing alerts suggests that the system effectively distinguishes between benign and malicious behavior, even for sophisticated LOTL attacks. The use of explainable features aids in trust and debugging, while counterfactual analysis provides a way to assess model robustness. However, limitations may include potential biases in data, the need for continuous retraining, and the cost of maintaining the infrastructure. Future work could explore scaling to other SaaS platforms and incorporating additional data sources. Overall, this research sets a precedent for whole-system defenses against product abuse, demonstrating that machine learning can be a practical and impactful solution in operational security platforms.

Who should read this

CS practitioners and researchers

Opening member content…