arXiv Machine Learning

Not All Relations Are Equal: Relation-Balanced and Calibrated Graph Learning for Provenance-Based Intrusion Detection

The paper introduces RECAL, an unsupervised framework that applies relation-balanced masked graph learning and error calibration to provenance-based intrusion detection. By addressing the large statistical heterogeneity among relations—where frequencies can differ by about 140,000×—RECAL better captures rare interaction patterns and normal error variations. On three DARPA E3 datasets, it achieves near-perfect F1 scores and dramatically reduces false positive rates compared to existing baselines.

arXiv Machine Learning
Aug 4

How Benchmarks and Evaluation Protocols Shape Conclusions in Provenance-Based Intrusion Detection

arXiv:2608. 01454v1 Announce Type: cross Abstract: Provenance-based intrusion detection systems (PIDS) frequently report strong performance, but the conclusions drawn from these results can be highly sensitive to benchmarking choices and evaluation protocols.

By Lorenzo Guerra, Thomas Chapuis, Guillaume Duc, Pavlo Mozharovskyi, Van-Tam Nguyen
arXiv AI
Aug 11

Defending Retrieval-Augmented Intrusion Detection Against Knowledge Poisoning and Prompt Injection

arXiv:2608. 08100v1 Announce Type: cross Abstract: Retrieval-Augmented Generation (RAG) enables large language models to classify network flows and generate human-readable incident reports by retrieving semantically similar historical traffic from a vector knowledge base.

By Kaysarul Anas Apurba, Md. Hasibul Hasan, Mahedee Zaman Moon, Sk. Md. Mizanur Rahman, Atsuo Inomata