Interpretable and Robust Behavior Abstraction via Environment-Disentangled Heterogeneous Graph
Zhibin Ni, Hai Wan, Xibin Zhao
Abstract
To identify the root causes of attacks, behavior abstraction (BA) converts audit logs into multiple behavior graphs and finds similar ones, which has proven effective in bridging the semantic gap and reducing manual workload. Existing works fail to achieve both interpretability and generalization, while also exhibiting limited robustness when facing adversarial attacks. In this paper, we give the first attempt at interpretable and robust behavior abstraction and propose a novel method called Environment-Disentangled Heterogeneous Graph Neural Network (EDHGNN). Motivated by Information Bottleneck (IB) principle, we propose a Heterogeneous Subgraph Disentanglement (HSD) module to disentangle label-relevant and environmental subgraphs through single optimization. We also introduce an Adapted Graph-Level Attention (AGLA) module to extract minimal sufficient representations from label-relevant subgraphs, a Label-Guided Graph Reconstructor (LGGR) to maximize environmental information coverage via reconstruction, and a Relevance Discriminator (RD) to enhance disentanglement quality. Additionally, we construct a new dataset contains ground-truth explanations and 4,160 behavior graphs. Extensive experiments demonstrate that EDHGNN outperforms the state-of-the-art methods in terms of interpretability and robustness against adversarial attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7ab938b2-b89f-40be-89d6-549fce881409Builds on22
- HOLMES: Real-Time APT Detection through Correlation of Suspicious Information FlowsSadegh Momeni Milajerdi, Rigel Gjomemo, Birhanu Eshete, R. Sekar et al.S&P 2019 · 550 citations
- Tactical Provenance Analysis for Endpoint Detection and Response SystemsWajih Ul Hassan, Adam Bates, Daniel MarinoS&P 2020 · 317 citations
- POIROT: Aligning Attack Behavior with Kernel Audit Records for Cyber Threat HuntingSadegh M. Milajerdi, Birhanu Eshete, Rigel Gjomemo, V. N. VenkatakrishnanCCS 2019 · 313 citations
- SLEUTH: Real-time Attack Scenario Reconstruction from COTS Audit DataMd Nahid Hossain, Sadegh M. Milajerdi, Junao Wang, Birhanu Eshete et al.USENIX Security 2017 · 291 citations
- Interpretable and Generalizable Graph Learning via Stochastic Attention MechanismSiqi Miao, Mia Liu, Pan LiICML 2022 · 288 citations
Related papers
- Robust Heterogeneous Graph Classification for Molecular Property Prediction with Information BottleneckZhibin Ni, Chang Liu, Hai Wan, Xibin ZhaoAAAI 2025 · 3 citations
- Robust Heterogeneous Graph Neural Networks against Adversarial AttacksMengmei Zhang, Xiao Wang, Meiqi Zhu, Chuan Shi et al.AAAI 2022 · 55 citations
- Towards Robust Heterogeneous Graph Explanations under Structural PerturbationsYifan Lu, Pengfei Jiao, Xuan Guo, Ziyun Zou et al.WWW 2026
- ST-TGExplainer: Disentangling Stability and Transition Patterns for Temporal GNN InterpretabilityHongjiang Chen, Xin Zheng, Pengfei Jiao, Huan Liu et al.ICML 2026
- xFraud: Explainable Fraud Transaction DetectionSusie Xi Rao, Shuai Zhang, Zhichao Han, Zitao Zhang et al.VLDB 2022 · 67 citations
