Systems and methods for adaptive detection of security threats may include maintaining a natural language processing model trained to classify communications as attacks. The system may detect a missed attack corresponding to a communication processed by the natural language processing model, based on which the system determines to retrain the natural language processing model. The system may generate one or more training samples based on the communication processed by the natural language model, where the training samples include data corresponding to one or more behavioral dimensions from the communication. The system may retrain the natural language processing model using at least the one or more training samples, and deploy the retained natural language processing model for one or more subsequent communications, to detect an attack in at least one of the one or more subsequent communications.
Full Text
What is claimed is: