PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
August 22, 2025Symmetry0 citationsOpen Access

Using Causality-Driven Graph Representation Learning for APT Attacks Path Identification

View Full Paper
XCXiang ChengMKMengmeng KuangHYHongyu Yang

Key Points

  • The new method achieves over 97% precision in detecting anomalies using advanced graph representations, showing strong effectiveness.
  • Recall rates exceed 99.5%, highlighting the model's low false negative rate, which is critical for cybersecurity applications.
  • Observational analysis using causal autoencoder techniques improves the understanding of attack paths in systems vulnerable to APT attacks.
  • The approach emphasizes causal relationships over traditional surface associations, potentially revolutionizing detection accuracy.

Abstract

In the cybersecurity attack and defense space, the “attacker” and the “defender” form a dynamic and symmetrical adversarial pair. Their strategy iterations and capability evolutions have long been in a symmetrical game of mutual restraint. We will introduce modern Intrusion Detection Systems (IDSs) from the defender’s side to counter the techniques designed by the attacker (APT attack). One major challenge faced by IDS is to identify complex attack paths from a vast provenance graph. By constructing an attack behavior tracking graph, the interactions between system entities can be recorded, but the malicious activities of attackers are often hidden among a large number of normal system operations. Although traditional methods can identify attack behaviors, they only focus on the surface association relationships between entities and ignore the deep causal relationships, which limits the accuracy and interpretability of detection. Existing graph anomaly detection methods usually assign the same weight to all interactions, while we propose a Causal Autoencoder for Graph Explanation (CAGE) based on reinforcement learning. This method extracts feature representations from the traceability graph through a graph attention network(GAT), uses Q-learning to dynamically evaluate the causal importance of edges, and highlights key causal paths through a weight layering strategy. In the DARPA TC project, the experimental results conducted on the selected three datasets indicate that the precision of this method in the anomaly detection task remains above 97% on average, demonstrating excellent accuracy. Moreover, the recall values all exceed 99.5%, which fully proves its extremely low rate of missed detections.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Cheng et al. (2025) studied this question.

synapsesocial.com/papers/68af55c6ad7bf08b1eadbbadhttps://doi.org/10.3390/sym17091373
Ask AI
Helpful
Bookmark
Share
View Full Paper