A simple lexical allowlist matches or beats learned provenance-based detectors on three of four audited E3 datasets, showing that measured PIDS gains often reflect benchmark shortcuts rather than richer modeling.
Graph neural networks for intrusion detection: A survey,
1 Pith paper cite this work. Polarity classification is still indexing.
1
Pith paper citing it
citation-role summary
background 1
citation-polarity summary
fields
cs.CR 1years
2026 1verdicts
CONDITIONAL 1roles
background 1polarities
unclear 1representative citing papers
citing papers explorer
-
How Benchmarks and Evaluation Protocols Shape Conclusions in Provenance-Based Intrusion Detection
A simple lexical allowlist matches or beats learned provenance-based detectors on three of four audited E3 datasets, showing that measured PIDS gains often reflect benchmark shortcuts rather than richer modeling.