APT-LLM turns process-event traces into sentences, embeds them with BERT-family models, and uses autoencoder reconstruction error to detect APTs, reporting AUC gains over OC-SVM, DBSCAN, and Isolation Forest.
A baseline for unsupervised advanced persistent threat detection in system-level provenance,
1 Pith paper cite this work. Polarity classification is still indexing.
1
Pith paper citing it
citation-role summary
dataset 1
citation-polarity summary
fields
cs.CR 1years
2025 1verdicts
REJECT 1roles
dataset 1polarities
use dataset 1representative citing papers
citing papers explorer
-
APT-LLM: Embedding-Based Anomaly Detection of Cyber Advanced Persistent Threats Using Large Language Models
APT-LLM turns process-event traces into sentences, embeds them with BERT-family models, and uses autoencoder reconstruction error to detect APTs, reporting AUC gains over OC-SVM, DBSCAN, and Isolation Forest.