Malicious Domain Detection on Out-of-Distribution Gray Data through Graph Contrastive Learning with Structure Aggregation
Hongjie Gu, Daojing He, Xun Zhou
摘要
Graph-based threat detection methods model Indicators of Compromise (IoC) using heterogeneous graphs and train node classifiers to identify malicious domains. Despite their promising performance, these approaches still face two major challenges. Firstly, the high cost of node annotation leads to a lack of evaluation on extensive gray data (unlabeled data). Secondly, the previous observations reveal a significant distribution shift in the Domain Maliciousness Graph (DMG), where structural differences between labeled and unlabeled domains hinder model performance. Existing graph learning methods have not yet considered both of these challenges simultaneously. To fill the gap, we frame the problem as semi-supervised graph node classification under out-of-distribution (OOD) constraints. We introduce graph aggregative contrastive learning (GRAVEL), which leverages the inherent structure of DMG to enhance detection performance on OOD unlabeled domains. GRAVEL is pre-trained end-to-end on abundant in-distribution malicious and benign samples, then fine-tuned with scarce OOD malicious data via mixup. During pre-training, label propagation seeds pseudo-labels, and a label-guided aggregation classifier is used to warm up the model, after which multi-view contrastive learning sharpens features for unlabeled domains. Extensive industrial evaluations demonstrate that GRAVEL improves F1 by 5–20% across diverse benchmarks for OOD malicious domain detection, consistently outperforming state-of-the-art baselines.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Structural Entropy Guided Unsupervised Graph Out-Of-Distribution DetectionYue Hou, He Zhu, Ruomei Liu, Yingke Su 等AAAI 2025 · 被引用 6 次
- Cross-Domain Graph Anomaly Detection via Anomaly-Aware Contrastive AlignmentQizhou Wang, Guansong Pang, Mahsa Salehi, Wray L. Buntine 等AAAI 2023 · 被引用 51 次
- MARIO: Model Agnostic Recipe for Improving OOD Generalization of Graph Contrastive LearningYun Zhu, Haizhou Shi, Zhenshuo Zhang, Siliang TangWWW 2024 · 被引用 18 次
- Open-World Semi-Supervised Learning for Node ClassificationYanling Wang, Jing Zhang, Lingxi Zhang, Lixin Liu 等ICDE 2024 · 被引用 3 次
- Unsupervised Graph Poisoning Attack via Contrastive Loss Back-propagationSixiao Zhang, Hongxu Chen, Xiangguo Sun, Yicong Li 等WWW 2022 · 被引用 52 次
