Not All Relations Are Equal: Relation-Balanced and Calibrated Graph Learning for Provenance-Based Intrusion Detection

📅 2026-09-14
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
为解决现有方法在处理系统交互时忽略关系异质性的问题,提出RECAL框架,通过关系平衡的图学习和校准重建误差来提高检测准确性并减少误报。
📝 Abstract
Provenance-Based Intrusion Detection Systems (PIDSs) detect Advanced Persistent Threats (APTs) by analyzing system interactions. However, existing methods largely treat relations uniformly, overlooking statistical heterogeneity; in CADETS, relation frequencies differ by approximately $140{,}000\times$. This may cause PIDSs to focus more on frequent relations and overlook differences in normal error levels across relations, increasing the risk of false alarms and missed detections. We present RECAL, an unsupervised framework using relation-balanced masked graph learning to better capture rare interaction patterns. It further calibrates reconstruction errors against each relation's benign error distribution to produce comparable anomaly evidence, helping distinguish attacks from benign behavior and reduce false alarms. On three DARPA E3 datasets, RECAL achieves F1 scores of 99.99\%, 99.93\%, and 99.99\%, outperforming the best baseline on each dataset by 0.88, 0.82, and 0.42 percentage points, respectively. Compared with the baseline reporting the lowest FPR, RECAL reduces mean FPR by approximately $105\times$, $4\times$, and $41\times$.
Problem

Research questions and friction points this paper is trying to address.

Provenance-Based Intrusion Detection
Relation Heterogeneity
False Alarms
Missed Detections
Advanced Persistent Threats
Innovation

Methods, ideas, or system contributions that make the work stand out.

relation-balanced masked graph learning
anomaly evidence calibration
unsupervised framework
rare interaction patterns
🔎 Similar Papers
No similar papers found.