Deep Recurrent Hidden Markov Learning Framework for Multi-Stage Advanced Persistent Threat Prediction
This work addresses the challenge of stage-aware prediction for advanced persistent threats (APTs), which are multi-stage, stealthy, and difficult for existing intrusion detection systems to detect—particularly under sparse or incomplete observations where robust reasoning is lacking. The authors propose E-HiDNet, a novel framework that uniquely integrates deep semantic feature learning with probabilistic state-space modeling. It jointly employs CNNs and RNNs to extract spatiotemporal features from alert sequences and leverages a hidden Markov model to characterize latent APT attack stages and their stochastic transitions. An enhanced Viterbi algorithm enables uncertainty-aware inference even with incomplete observations. Evaluated on the S-DAPT-2026 dataset, the method achieves 98.8%–100% stage prediction accuracy when at least four observations are available, significantly outperforming conventional HMMs and maintaining high robustness under reduced training data.