Skip to content
Book Open access

Lasso: Accurate and Efficient Detection of Long-Lived Sparse Items in High-Speed Data Streams

Aug 2026 · Proceedings of the 32nd ACM SIGKDD Conference on Knowledge Discovery and Data Mining V.2 · pp. 2754-2765 · 0 citations · 19 references

Abstract

In high-speed data streams, identifying long-lived (also referred to as persistent) sparse items is critical, as such patterns may indicate stealthy or low-rate threats yet remain largely underexplored. Although recent studies have begun to examine this problem, existing approaches either suffer from low lookup accuracy due to coarse update strategies or rely on complex data structures with costly update operations, overlooking the practical requirement of deployability. These limitations hinder scalability, particularly as programmable switches and FPGAs are increasingly adopted as data-processing substrates that sustain high-speed processing under strict resource and operational constraints. To address these challenges, we propose Lasso, a lightweight and hardware-conscious approach that achieves high detection accuracy under tight memory budgets while sustaining high processing throughput on industry-grade hardware, including Tofino-1 programmable switches and FPGA platforms. Lasso leverages the observation that long-lived sparse items exhibit a small gap between persistence and frequency, evicting items with large deviations to prioritize promising candidates. In addition, Lasso incorporates fine-grained, temporally aware protection to prevent long-lived items from being prematurely displaced by abundant short-lived items in highly skewed data streams. We further develop a formal analytical model to establish the theoretical soundness of Lasso. Extensive evaluations across CPU, Tofino, and FPGA platforms demonstrate that Lasso delivers high accuracy and throughput while operating within strict resource constraints.

Read PDF

Similar papers

Open access Aug 2026

Detecting Low-and-Slow Data Exfiltration: A Behavioural and Cumulative-Signal Approach to Identifying Slow-Moving Data Extraction

Most exfiltration controls are built to catch a single large transfer: a threshold on session size, a daily-volume cap, a DLP rule tuned to a file-size or record-count trigger. An adversary who instead moves data out in small increments over an extended period – kilobytes at a time, spread across days or weeks, often t...

Maharana Satyabrat · 0 citations
Preprint Aug 2026

FlashQuant: Sparse-Dense Fusion for Memory-Efficient Outlier-Aware LLM Inference

FlashQuant fuses the dense GEMM and sparse outlier SpMM paths into a single GPU kernel, enabling on-chip reuse of activation and output tiles across heterogeneous computations, and introduces three key techniques: sparse-dense tiling, which aligns outlier processing with dense GEMM tiles, and pipelined scheduling, whic...

Jun-Qing Lin, Jing-Wei Sun, Zhengding Hu et al. · 0 citations

of the 24th USENIX Conference on File and Storage Technologies

SolidAttention is introduced, an LLM inference engine which addresses limitations through a tight co-design of dynamic attention sparsity algorithms and SSD-based storage management and minimizes SSD-induced blocking latency.

Xin Zheng, Dong-Liang Wei, Jian-Xiang Gao et al. · 0 citations
Preprint Oct 2026

HiNa-MoE: High-Performance, Non-Intrusive MoE Inference on CPUs with Matrix Engines

Mixture-of-Experts (MoE) inference is increasingly deployed in local and on-premise environments, where expert parameters often exceed GPU memory capacity. In latency-sensitive, low-concurrency settings, repeatedly staging routed-expert weights from CPU memory to the GPU can be prohibitive, leaving routed-expert feed-f...

Wei-Ling Yang, Jun-Wen Zhang, De-Zun Dong et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.