Interpretable and Robust Behavior Abstraction via Environment-Disentangled Heterogeneous Graph
Zhibin Ni, Hai Wan, Xibin Zhao
摘要
To identify the root causes of attacks, behavior abstraction (BA) converts audit logs into multiple behavior graphs and finds similar ones, which has proven effective in bridging the semantic gap and reducing manual workload. Existing works fail to achieve both interpretability and generalization, while also exhibiting limited robustness when facing adversarial attacks. In this paper, we give the first attempt at interpretable and robust behavior abstraction and propose a novel method called Environment-Disentangled Heterogeneous Graph Neural Network (EDHGNN). Motivated by Information Bottleneck (IB) principle, we propose a Heterogeneous Subgraph Disentanglement (HSD) module to disentangle label-relevant and environmental subgraphs through single optimization. We also introduce an Adapted Graph-Level Attention (AGLA) module to extract minimal sufficient representations from label-relevant subgraphs, a Label-Guided Graph Reconstructor (LGGR) to maximize environmental information coverage via reconstruction, and a Relevance Discriminator (RD) to enhance disentanglement quality. Additionally, we construct a new dataset contains ground-truth explanations and 4,160 behavior graphs. Extensive experiments demonstrate that EDHGNN outperforms the state-of-the-art methods in terms of interpretability and robustness against adversarial attacks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper22
- HOLMES: Real-Time APT Detection through Correlation of Suspicious Information FlowsSadegh Momeni Milajerdi, Rigel Gjomemo, Birhanu Eshete, R. Sekar 等S&P 2019 · 被引用 550 次
- Tactical Provenance Analysis for Endpoint Detection and Response SystemsWajih Ul Hassan, Adam Bates, Daniel MarinoS&P 2020 · 被引用 317 次
- POIROT: Aligning Attack Behavior with Kernel Audit Records for Cyber Threat HuntingSadegh M. Milajerdi, Birhanu Eshete, Rigel Gjomemo, V. N. VenkatakrishnanCCS 2019 · 被引用 313 次
- SLEUTH: Real-time Attack Scenario Reconstruction from COTS Audit DataMd Nahid Hossain, Sadegh M. Milajerdi, Junao Wang, Birhanu Eshete 等USENIX Security 2017 · 被引用 291 次
- Interpretable and Generalizable Graph Learning via Stochastic Attention MechanismSiqi Miao, Mia Liu, Pan LiICML 2022 · 被引用 288 次
相关 Paper
- Robust Heterogeneous Graph Classification for Molecular Property Prediction with Information BottleneckZhibin Ni, Chang Liu, Hai Wan, Xibin ZhaoAAAI 2025 · 被引用 3 次
- Robust Heterogeneous Graph Neural Networks against Adversarial AttacksMengmei Zhang, Xiao Wang, Meiqi Zhu, Chuan Shi 等AAAI 2022 · 被引用 55 次
- Towards Robust Heterogeneous Graph Explanations under Structural PerturbationsYifan Lu, Pengfei Jiao, Xuan Guo, Ziyun Zou 等WWW 2026
- ST-TGExplainer: Disentangling Stability and Transition Patterns for Temporal GNN InterpretabilityHongjiang Chen, Xin Zheng, Pengfei Jiao, Huan Liu 等ICML 2026
- xFraud: Explainable Fraud Transaction DetectionSusie Xi Rao, Shuai Zhang, Zhichao Han, Zitao Zhang 等VLDB 2022 · 被引用 67 次
