Malicious Domain Detection on Out-of-Distribution Gray Data through Graph Contrastive Learning with Structure Aggregation
Hongjie Gu, Daojing He, Xun Zhou
Abstract
Graph-based threat detection methods model Indicators of Compromise (IoC) using heterogeneous graphs and train node classifiers to identify malicious domains. Despite their promising performance, these approaches still face two major challenges. Firstly, the high cost of node annotation leads to a lack of evaluation on extensive gray data (unlabeled data). Secondly, the previous observations reveal a significant distribution shift in the Domain Maliciousness Graph (DMG), where structural differences between labeled and unlabeled domains hinder model performance. Existing graph learning methods have not yet considered both of these challenges simultaneously. To fill the gap, we frame the problem as semi-supervised graph node classification under out-of-distribution (OOD) constraints. We introduce graph aggregative contrastive learning (GRAVEL), which leverages the inherent structure of DMG to enhance detection performance on OOD unlabeled domains. GRAVEL is pre-trained end-to-end on abundant in-distribution malicious and benign samples, then fine-tuned with scarce OOD malicious data via mixup. During pre-training, label propagation seeds pseudo-labels, and a label-guided aggregation classifier is used to warm up the model, after which multi-view contrastive learning sharpens features for unlabeled domains. Extensive industrial evaluations demonstrate that GRAVEL improves F1 by 5–20% across diverse benchmarks for OOD malicious domain detection, consistently outperforming state-of-the-art baselines.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 6015a734-199b-4b4d-a54c-79085ea9e0eeRelated papers
- Structural Entropy Guided Unsupervised Graph Out-Of-Distribution DetectionYue Hou, He Zhu, Ruomei Liu, Yingke Su et al.AAAI 2025 · 6 citations
- Cross-Domain Graph Anomaly Detection via Anomaly-Aware Contrastive AlignmentQizhou Wang, Guansong Pang, Mahsa Salehi, Wray L. Buntine et al.AAAI 2023 · 51 citations
- MARIO: Model Agnostic Recipe for Improving OOD Generalization of Graph Contrastive LearningYun Zhu, Haizhou Shi, Zhenshuo Zhang, Siliang TangWWW 2024 · 18 citations
- Open-World Semi-Supervised Learning for Node ClassificationYanling Wang, Jing Zhang, Lingxi Zhang, Lixin Liu et al.ICDE 2024 · 3 citations
- Unsupervised Graph Poisoning Attack via Contrastive Loss Back-propagationSixiao Zhang, Hongxu Chen, Xiangguo Sun, Yicong Li et al.WWW 2022 · 52 citations
