Not All Relations Are Equal: Relation-Balanced and Calibrated Graph Learning for Provenance-Based Intrusion Detection
Read the original on arXiv Machine Learning →The paper introduces RECAL, an unsupervised framework that applies relation-balanced masked graph learning and error calibration to provenance-based intrusion detection. By addressing the large statistical heterogeneity among relations—where frequencies can differ by about 140,000×—RECAL better captures rare interaction patterns and normal error variations. On three DARPA E3 datasets, it achieves near-perfect F1 scores and dramatically reduces false positive rates compared to existing baselines.
Machine-generated by The Flow from the publisher's headline and feed description — not written or checked by a human. The full article lives at arXiv Machine Learning.