Slot: Provenance-Driven APT Detection through Graph Reinforcement Learning
Wei Qiao, Yebo Feng, Teng Li, Zhuo Ma, Yulong Shen, Jianfeng Ma, Yang Liu
Abstract
Advanced Persistent Threats (APTs) represent sophisticated cyberattacks characterized by their ability to remain undetected within the victim system for extended periods, aiming to exfiltrate sensitive data or disrupt operations. Existing detection approaches often struggle to effectively identify these complex threats, construct the attack chain for defense facilitation, or resist adversarial attacks. To overcome these challenges, we propose Slot, an advanced APT detection approach based on provenance graphs and graph reinforcement learning. Slot excels in uncovering multi-level hidden relationships, such as causal, contextual, and indirect connections, among system behaviors through provenance graph mining. Slot implements semi-supervised learning with limited labels through efficient label similarity computation, significantly enhancing both detection performance and model robustness. By pioneering the integration of graph reinforcement learning, Slot dynamically adapts to new user activities and evolving attack strategies, enhancing its resilience against adversarial attacks. Additionally, Slot automatically constructs the attack chain according to detected attacks with clustering algorithms, providing precise identification of attack paths and facilitating the development of defense strategies. Evaluations with real-world datasets demonstrate Slot's outstanding accuracy, efficiency, adaptability, and robustness in APT detection, with most metrics surpassing state-of-the-art methods. Additionally, case studies conducted to assess Slot's effectiveness in supporting APT defense further establish it as a practical and reliable tool for cybersecurity protection.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5330827e-56cc-4180-840b-d4cc6175c2c8Cited by top-tier papers4
- Beyond Nodes vs. Edges: A Multi-View Fusion Framework for Provenance-Based Intrusion DetectionFan Yang, Binyan Xu, Di Tang, Kehuan ZhangS&P 2026 · 2 citations
- Sentient: Detecting APTs via Capturing Indirect Dependencies and Behavioral LogicWenhao Yan, Ning An, Wei Qiao, Weiheng Wu et al.AAAI 2026 · 1 citation
- Angel or Demon: Investigating the Plasticity Interventions' Impact on Backdoor Threats in Deep Reinforcement LearningOubo Ma, Ruixiao Lin, Yang Dai, Jiahao Chen et al.ICML 2026 · 1 citation
- Cutting the Fuse: Actionable APT Attack Blocking in Provenance-based IDSWeiheng Wu, Wei Qiao, Teng Li, Yebo Feng et al.USENIX Security 2026
Builds on26
- Beyond Homophily in Graph Neural Networks: Current Limitations and Effective DesignsJiong Zhu, Yujun Yan, Lingxiao Zhao, Mark Heimann et al.NeurIPS 2020 · 1,490 citations
- HOLMES: Real-Time APT Detection through Correlation of Suspicious Information FlowsSadegh Momeni Milajerdi, Rigel Gjomemo, Birhanu Eshete, R. Sekar et al.S&P 2019 · 550 citations
- Large Scale Learning on Non-Homophilous Graphs: New Benchmarks and Strong Simple MethodsDerek Lim, Felix Hohne, Xiuyu Li, Sijia Linda Huang et al.NeurIPS 2021 · 534 citations
- GraphMAE: Self-Supervised Masked Graph AutoencodersZhenyu Hou, Xiao Liu, Yukuo Cen, Yuxiao Dong et al.KDD 2022 · 533 citations
- On Explainability of Graph Neural Networks via Subgraph ExplorationsHao Yuan, Haiyang Yu, Jie Wang, Kang Li et al.ICML 2021 · 498 citations
Related papers
- TREC: APT Tactic / Technique Recognition via Few-Shot Provenance Subgraph LearningMingqi Lv, Hongzhe Gao, Xuebo Qiu, Tieming Chen et al.CCS 2024 · 18 citations
- HyperDetector: Advanced Persistent Threat Detection via Hypergraph Neural Networks with Enhanced Global PerceptionZiyue Wu, Nan Wang, Jiqiang Liu, Hairong Dong et al.WWW 2026
- DUPIN: Attack Learning Is Still Needed! Demonstrating Few-Shot after Unsupervised Pretraining Is A Nimble Forensics LearnerChanwoo Bae, Hailun Ding, Shiqing Ma, Xiangyu ZhangUSENIX Security 2026 · 1 citation
- MAGIC: Detecting Advanced Persistent Threats via Masked Graph Representation LearningZian Jia, Yun Xiong, Yuhong Nan, Yao Zhang et al.USENIX Security 2024 · 92 citations
- Unicorn: Runtime Provenance-Based Detector for Advanced Persistent ThreatsXueyuan Han, Thomas F. J.-M. Pasquier, Adam Bates, James Mickens et al.NDSS 2020
