Equation 4 · How AI and Cybersecurity Actually Work
What does this equation mean?
Read the formula alongside the article passage below. Each part has a deeper page with its role in the equation, the supporting passage and nearby citations.
This equation states an equality: the expressions on both sides have the same value under the article’s assumptions. Read the equation part by part below; each part has a contextual explanation and a link to its mathematical background.
Read it piece by piece
=
The expressions on both sides represent the same quantity under the stated assumptions.
See an illustrated explanation →Denominator: TPR × p + FPR × (1-p)
The complete quantity below the fraction bar; it must be nonzero for this division.
How to interpret it
With a fixed numerator, increasing a nonzero denominator reduces the fraction. Read it with the definitions, units, and assumptions supplied by the article.
What the article says around this equation
A simple way to see why the base rate of genuine misuse matters as much as the detector’s accuracy is the standard result relating a detector’s precision to how rare the thing it is looking for actually is. If a detection system has a true-positive rate and false-positive rate , and the true prevalence of the underlying misuse event in the traffic it sees is p , the fraction of flagged events that are genuinely misuse — the precision an analyst actually experiences — is . When p is small, which it almost always is for genuine, successful misuse against a well-defended system, precision collapses toward zero even for a detector with a very low…
Read the full surrounding passage
A simple way to see why the base rate of genuine misuse matters as much as the detector’s accuracy is the standard result relating a detector’s precision to how rare the thing it is looking for actually is. If a detection system has a true-positive rate and false-positive rate , and the true prevalence of the underlying misuse event in the traffic it sees is p , the fraction of flagged events that are genuinely misuse — the precision an analyst actually experiences — is . When p is small, which it almost always is for genuine, successful misuse against a well-defended system, precision collapses toward zero even for a detector with a very low false-positive rate, simply because the pool of benign traffic the false-positive rate applies to is so much larger than the pool of real events. Why this is worth stating formally rather than just asserting “false positives are a problem” : it shows that a headline detection accuracy figure (say, 99% true-positive rate) is close to meaningless on its own without the base rate and the false-positive rate reported alongside it, and it is exactly the kind of quantity a vendor claim can omit while still being technically accurate.
For background, read the article’s source list.
Return to How AI and Cybersecurity Actually Work