paper-with-me

홈 › Papers

Interpreting GNN-based IDS Detections Using Provenance Graph Structural Features

2023-06-01 · Kunal Mukherjee, Joshua Wiedemeier, Tianhao Wang, Muhyun Kim, Feng Chen, Murat Kantarcioglu, Kangkook Jee

Advanced cyber threats (e.g., Fileless Malware and Advanced Persistent Threat (APT)) have driven the adoption of provenance-based security solutions. These solutions employ Machine Learning (ML) models for behavioral modeling and critical security tasks such as malware and anomaly detection. However, the opacity of ML-based security models limits their broader adoption, as the lack of transparency in their decision-making processes restricts explainability and verifiability. We tailored our solution towards Graph Neural Network (GNN)-based security solutions since recent studies employ GNNs to comprehensively digest system provenance graphs for security critical tasks. To enhance the explainability of GNN-based security models, we introduce PROVEXPLAINER, a framework offering instance-level security-aware explanations using an interpretable surrogate model. PROVEXPLAINER's interpretable feature space consists of discriminant subgraph patterns and graph structural features, which can be directly mapped to the system provenance problem space, making the explanations human understandable. By considering prominent GNN architectures (e.g., GAT and GraphSAGE) for anomaly detection tasks, we show how PROVEXPLAINER synergizes with current state-of-the-art (SOTA) GNN explainers to deliver domain and instance-specific explanations. We measure the explanation quality using the fidelity+/fidelity- metric as used by traditional GNN explanation literature, and we incorporate the precision/recall metric where we consider the accuracy of the explanation against the ground truth. On malware and APT datasets, PROVEXPLAINER achieves up to 29%/27%/25% higher fidelity+, precision and recall, and 12% lower fidelity- respectively, compared to SOTA GNN explainers.

📄 PDF Abstract BibTeX arXiv:2306.00934

Code (0)

등록된 구현이 없습니다.

Tasks

Anomaly DetectionDecision MakingDescriptiveExplainable ModelsGraph Neural NetworkMalware ClassificationMalware Detection

Methods 이 논문이 사용한 방법론

Graph Neural Network 설명 없음

Similar Papers 제목 키워드 기반

Image Provenance Analysis via Graph Encoding with Vision Transformer

2024-08-26 · Keyang Zhang, Chenqi Kong, Shiqi Wang, Anderson Rocha 외

Recent advances in AI-powered image editing tools have significantly lowered the barrier to image modification, raising pressing security concerns those related to spreading misinformation and disinformation on social pl…

graph constructionMisinformation

Structural Pattern Mining in Inka Khipus: Unsupervised Clustering, Provenance Classification, and a Computational Validation of the Santa Valley Match

2026-06-30 · Maria Contreras arxiv

Khipus -- knotted cord devices -- were the primary recording medium of the Inka Empire (c. 1400-1532 CE), yet their system remains undeciphered. We present a reproducible machine-learning pipeline applied to the Open Khi…

Cryptographic Registry Provenance: Structural Defense Against Dependency Confusion in AI Package Ecosystems

2026-05-05 · Alan L. McCann arxiv

Dependency confusion attacks exploit a structural gap in software distribution: once a package is installed, there is no cryptographic proof of which registry distributed it. Every existing defense is configuration-based…

Detection Recovery in Online Multi-Object Tracking with Sparse Graph Tracker

2022-05-02 · Jeongseok Hyun, Myunggu Kang, Dongyoon Wee, Dit-yan Yeung

In existing joint detection and tracking methods, pairwise relational features are used to match previous tracklets to current detections. However, the features may not be discriminative enough for a tracker to identify …

motion predictionMulti-Object Trackingobject-detectionObject Detection+2

Latent Trees for Estimating Intensity of Facial Action Units

2015-06-01 · CVPR 2015 6 · Sebastian Kaltwang, Sinisa Todorovic, Maja Pantic

This paper is about estimating intensity levels of Facial Action Units (FAUs) in videos as an important and challenging step toward interpreting facial expressions. To address uncertainty in detections of facial landmark…