Pith. sign in

Paper Citation Record · LEDGER

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection

As of 7 August 2026, this Paper Citation Record lists 97 of 97 outbound references and 0 inbound Pith citation observations for arXiv:2507.10873.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2507.10873 v1

Coverage vector

measured 97 of 97 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-06T17:30:02.816653Z

measured 97 of 97 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-07T06:34:17.273281+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

97 of 97 outbound references displayed

  • verified exact0
  • verified fuzzy48
  • unresolved49
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 6d12d57c-732d-4028-bb67-b64018d2764d · outbound

This paper cites Fbi releases annual internet crime report,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Fbi releases annual internet crime report,

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:55.132008Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:55.132008Z digest=sha256:798288f62bb2dd1270a2a81636ae2023bf6660593c8b077d19dd793983b06088

Observation 6523c75f-9cfe-42da-92f3-d0a52837aad7 · outbound

This paper cites Cyberattacks cost victims more than quadruple the amount hackers pay to execute attacks,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Cyberattacks cost victims more than quadruple the amount hackers pay to execute attacks,

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:55.197894Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:55.197894Z digest=sha256:c6fc54522d5ba482edc2f8b0acb6719a3c945c16ca85395df8b8153a7b1cb3ec

Observation c17ede2a-c9e1-49c8-822b-7d938506974b · outbound

This paper cites Intrusion detection system market size, share, and growth analysis,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Intrusion detection system market size, share, and growth analysis,

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:55.258642Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:55.258642Z digest=sha256:4f049c68c3b00104bcf7434964594d9de630277eb9dc66d916037bfe83c6f0a9

Observation 30d7a3d9-e0ae-4819-b412-a6bf108b836e · outbound

This paper cites Sok: History is a vast early warning system: Auditing the provenance of system intrusions,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Sok: History is a vast early warning system: Auditing the provenance of system intrusions,

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:55.314421Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:55.314421Z digest=sha256:0650e40de1fcf69138689174416b7eaba50f427c14dd2cceaa12be1233334417

Observation d0509619-1a87-4c5e-a810-63ec329f3739 · outbound

This paper cites Backtracking intrusions,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Backtracking intrusions,

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:55.365365Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:55.365365Z digest=sha256:4cf8eb69037b92abf7e1f3aa57df35b8db95799344778eb2efe735f8ecbd35a2

Observation fa19b7f0-ed25-469c-b907-7e7333aa9f03 · outbound

This paper cites Nodoze: Combatting threat alert fatigue with automated provenance triage,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Nodoze: Combatting threat alert fatigue with automated provenance triage,

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:55.442449Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:55.442449Z digest=sha256:f7c2bd215f3896194f28f42b3cb53ce982b991c69cc19d71aabf2c50258bc8fb

Observation 4ca6dab6-1426-4e26-948c-0241dca3ba8d · outbound

This paper cites Transparent computing engagement 3,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Transparent computing engagement 3,

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:55.493585Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:55.493585Z digest=sha256:451e2c922f9fee0c94176e6baba83af82865f19a9206b546f87fbca07e798efb

Observation b8b371cf-84b7-4ebc-9190-b5442c96057b · outbound

This paper cites Nodlink repo,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Nodlink repo,

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:55.577168Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:55.577168Z digest=sha256:66bf4b4ddce1ea352eed21c87273e1ddbbfaaee92e029fed37a64a2611836947

Observation e6953084-7cd4-4583-b7f8-b72aa8f8e028 · outbound

This paper cites ATLASv2: ATLAS Attack Engagements, Version 2.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection ATLASv2: ATLAS Attack Engagements, Version 2

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:55.639072Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:55.639072Z digest=sha256:7a69926ea54d350ba8a2da329bbe59fa487f808725019cc0b4f2f94d107dbe0f

Observation b982eecd-4760-44d5-bcba-b5d324018a40 · outbound

This paper cites Nodlink: An online system for fine-grained apt attack detection and investigation,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Nodlink: An online system for fine-grained apt attack detection and investigation,

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:55.723736Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:55.723736Z digest=sha256:adb96d2f7d7178b18c65c8b09f1fe45fe89bcd866db9a77456dc8a612d62f4a7

Observation 8cc19acd-c948-4b19-bd9d-17406118ca7a · outbound

This paper cites AIRTAG: Towards automated attack investigation by unsupervised learning with log texts,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection AIRTAG: Towards automated attack investigation by unsupervised learning with log texts,

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:55.796781Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:55.796781Z digest=sha256:c3fd322eac85209de0e7702fbdb529b08614b14401b1aed63e0ef1ec02d4de73

Observation aeea8833-ba95-4413-9f7e-44784368702c · outbound

This paper cites Flash: A comprehensive approach to intrusion detection via provenance graph representation learning,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Flash: A comprehensive approach to intrusion detection via provenance graph representation learning,

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:55.838261Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:55.838261Z digest=sha256:6b0627628a56b7fd5c9336d961e4aa9cc8920ea98de5d4b51e9a1add4e51c3ea

Observation 623022e4-8378-4c6e-b6d3-8181a22b4456 · outbound

This paper cites {MAGIC}: Detecting advanced persistent threats via masked graph representation learning,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection {MAGIC}: Detecting advanced persistent threats via masked graph representation learning,

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:55.889328Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:55.889328Z digest=sha256:3adc56a3135b148fbd42bde34a389aa976b4f2fa618e845943e8c7b7d1d154a3

Observation 545c9ecc-2e4e-49f6-9572-478f6de31323 · outbound

This paper cites ORTHRUS: Achieving High Quality of At- tribution in Provenance-based Intrusion Detection Systems,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection ORTHRUS: Achieving High Quality of At- tribution in Provenance-based Intrusion Detection Systems,

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:55.947179Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:55.947179Z digest=sha256:0b620a8a66202b631f72e4fbfbcd4cf8d184e081517d3270da5bf86de20f74e5

Observation bf5e56bc-4f91-4d76-8e2b-b6d8ea91d891 · outbound

This paper cites Constructing knowledge graph from cyber threat intelligence using large language model,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Constructing knowledge graph from cyber threat intelligence using large language model,

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:56.065803Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:56.065803Z digest=sha256:1d280b461331e986c34ec4e0af74c70045124559052446bd3d867e514881b2c8

Observation 7a406207-4c56-40e2-ae19-6cb03fdc8a7d · outbound

This paper cites Ctikg: Llm-powered knowledge graph construc- tion from cyber threat intelligence,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Ctikg: Llm-powered knowledge graph construc- tion from cyber threat intelligence,

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:56.103099Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:56.103099Z digest=sha256:ed5d165c66341fcdb2b55b33897518b41c646fe99cbb27d2bce6f8552c995cc0

Observation 93335473-a017-433b-8f41-3ab5b9979eeb · outbound

This paper cites Towards a scalable ai- driven framework for data-independent cyber threat intelligence infor- mation extraction,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Towards a scalable ai- driven framework for data-independent cyber threat intelligence infor- mation extraction,

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:56.187713Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:56.187713Z digest=sha256:17fd021803520659be65594d78085cb605d261756e5e16f70184a4e49f70834d

Observation fd88ed37-f2a7-497e-82d0-64acd31024f0 · outbound

This paper cites FADE: Few-shot/zero-shot Anomaly Detection Engine using Large Vision-Language Model.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection FADE: Few-shot/zero-shot Anomaly Detection Engine using Large Vision-Language Model

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:56.288957Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:56.288957Z digest=sha256:d0edd1751b2a97f03a49f8258532dbb2bc7558f3fc56cf10227c52abb8075b35

Observation b3e86ec5-7273-4cfe-b4ed-bdb0816f2efc · outbound

This paper cites Ad-llm: Benchmarking large language models for anomaly detection,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Ad-llm: Benchmarking large language models for anomaly detection,

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:56.333428Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:56.333428Z digest=sha256:be26bd2ad30fa6ebb4cae685fdcf46feb55572bf585b3468d1980eb35031db9a

Observation e96cca0f-90d4-465e-92f9-d8d967935606 · outbound

This paper cites Large Language Models for Forecasting and Anomaly Detection: A Systematic Literature Review.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Large Language Models for Forecasting and Anomaly Detection: A Systematic Literature Review

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:56.413683Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:56.413683Z digest=sha256:c37c8416c48edc117e03956df9a616ec0c38e280a47ded949ef42540a626403e

Observation 5ebc9c72-4215-4167-a6e4-2c4fba8df154 · outbound

This paper cites Anomaly Detection of Tabular Data Using LLMs.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Anomaly Detection of Tabular Data Using LLMs

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:56.482589Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:56.482589Z digest=sha256:89c5b1d08284305d66c76a74dfa38aba4e859a9388c7f8f1ec47f6c84936e03d

Observation 331f0a74-7f7d-4b0e-a2f1-f3b7fed78823 · outbound

This paper cites Summarization is (Almost) Dead.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Summarization is (Almost) Dead

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:56.545032Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:56.545032Z digest=sha256:f5245762785546f8d7d7fb0e6465613126975b9d41dd1e80fc194c56ab936b8d

Observation 0ce1a4af-8ee7-45cd-b8cf-ae2d2638b62b · outbound

This paper cites Lost in the middle: How language models use long contexts,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Lost in the middle: How language models use long contexts,

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:56.614158Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:56.614158Z digest=sha256:b1d1bf8a183269e122ec06e06bc2fb59e6144fa70dc302086b9b7d7907f79173

Observation 74a3cc14-fef0-4b38-964a-d0098fadd308 · outbound

This paper cites UNICORN: Runtime Provenance-Based Detector for Advanced Persistent Threats.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection UNICORN: Runtime Provenance-Based Detector for Advanced Persistent Threats

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:56.676292Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:56.676292Z digest=sha256:545ca273d3c4ad6aa3f49efa0dcf082092c9251782b6ae4b0c9346d6746bc759

Observation bf37aa4d-06d2-4aae-a1aa-1a02a9152312 · outbound

This paper cites {PROGRAPHER}: An anomaly detection system based on provenance graph embedding,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection {PROGRAPHER}: An anomaly detection system based on provenance graph embedding,

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:56.739178Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:56.739178Z digest=sha256:75d52ec9b8839f36ac9fe3abb768329a2e69eba93ac2ef6661d4c0a8737d4d7e

Observation 11ef014e-e86d-4c34-8c6d-cd3d309f6229 · outbound

This paper cites Masked au- toencoders are scalable vision learners,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Masked au- toencoders are scalable vision learners,

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:56.785201Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:56.785201Z digest=sha256:67ab601476de1e3e5315c0caea0afff038bbe7ab49c992557d03295b5ca15694

Observation 60c9746d-03ac-447f-bc67-64260f9c7636 · outbound

This paper cites Madeline: Continuous and low-cost monitoring with graph-free representations to combat cyber threats,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Madeline: Continuous and low-cost monitoring with graph-free representations to combat cyber threats,

Reference 27

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:12.562372Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:29:56.865512Z digest=sha256:822b6446912118145d6b3caca68669749fd95d42b1926ccdbb3a4747f133d965

Observation cc1c0220-5d7e-4535-94a3-fb112c784bac · outbound

This paper cites Retrieval- augmented generation for knowledge-intensive nlp tasks,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Retrieval- augmented generation for knowledge-intensive nlp tasks,

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:56.925805Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:56.925805Z digest=sha256:45217aaa529c6ae928a5d09ceca2dd43362a4a87d79080ebd4b840d2ea78f07d

Observation 51002c21-5f6b-4241-8a21-0d8ffcbff21e · outbound

This paper cites Enterprise tactics,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Enterprise tactics,

Reference 29

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:12.503913Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:29:57.014605Z digest=sha256:46a4225bc513af90def866aba19de6ccdde93fcf7855211c98d1dd241b559fe8

Observation bc32f1d4-dc46-47d5-a50b-267e33b5b469 · outbound

This paper cites Sometimes, you aren’t what you do: Mimicry attacks against provenance graph host intrusion detection systems,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Sometimes, you aren’t what you do: Mimicry attacks against provenance graph host intrusion detection systems,

Reference 30

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:12.476864Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:29:57.113337Z digest=sha256:65f7c8fc423f28431b80a4c5d385197f3124670a4b515200e0c193af6674c6e3

Observation 3b481f37-8303-48ef-a26a-8ba2125f3ffe · outbound

This paper cites Winodws event tracing,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Winodws event tracing,

Reference 31

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:12.423358Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:29:57.158829Z digest=sha256:5a76ed8645f01f8f91d1d346cac70d878a359ef1b00d88eafa28e27fa354e411

Observation 755523ac-d889-40ce-a0a1-2f104bcdf38f · outbound

This paper cites Linux audit,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Linux audit,

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:57.198668Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:57.198668Z digest=sha256:97900d24cd3322d283aff851f153dc0a98de5d994ce153c69d6491c2403cebc7

Observation 9c29804e-a6de-465c-ac18-235013060c9c · outbound

This paper cites Dtrace on freebsd,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Dtrace on freebsd,

Reference 33

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:12.325727Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:29:57.248180Z digest=sha256:771f1631c61bb99ed1441d7915cda23116c79fea01fca9c3c53c184ebc2ad562

Observation a002069e-9c4c-46d4-ae91-0803156ac044 · outbound

This paper cites Cyber kill chain,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Cyber kill chain,

Reference 34

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:12.288133Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:29:57.315933Z digest=sha256:1cf48109d497ca1ad2ec4762b9560ba62e19a286a4905d90e5f184c4fd30a61e

Observation cc6477c2-121c-4282-8096-f91c6c1b3068 · outbound

This paper cites Are we there yet? an industrial viewpoint on provenance-based endpoint detection and response tools,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Are we there yet? an industrial viewpoint on provenance-based endpoint detection and response tools,

Reference 35

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:12.260681Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:29:57.398158Z digest=sha256:08a2ac9e135b8d3d0688b7b53b281439b40163abe262883aa8066e83cb31f384

Observation c1032364-5510-4dbb-b061-5e3c2452bacb · outbound

This paper cites Provenance-aware tracing ofworm break-in and contaminations: A process coloring approach,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Provenance-aware tracing ofworm break-in and contaminations: A process coloring approach,

Reference 36

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:12.077735Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:29:57.478180Z digest=sha256:678a8a574089484adc34cf0672fd27490d2efc22d3ff7213015e2271dd775063

Observation 32c66bed-caba-470f-aee0-6ff34b60efd1 · outbound

This paper cites High fidelity data reduction for big data security dependency analyses,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection High fidelity data reduction for big data security dependency analyses,

Reference 37

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:11.864469Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:29:57.571013Z digest=sha256:aa769e09b35bdddbc62a76955fe7c93d366f5533002336e0b58aa817b51a88a2

Observation a95a7223-8937-4830-b9d2-edec0269356a · outbound

This paper cites Can data provenance put an end to the data breach?.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Can data provenance put an end to the data breach?

Reference 38

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:11.676377Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:29:57.637912Z digest=sha256:8fc5fa8e4928b284ca8b83d52f00789b4e1dc4fea557456ac3f4d7f74d01fbaf

Observation efbaca8d-d3a6-4b6a-a653-5e9d6da35801 · outbound

This paper cites Towards a timely causality analysis for enterprise security,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Towards a timely causality analysis for enterprise security,

Reference 39

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:11.531480Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:29:57.694250Z digest=sha256:09628b8cdfa2fb1f84049ff18a47cd59e247a5dc93fbb260840f14641534a497

Observation 21994383-d6a5-4a8d-ae78-7cc93587e33a · outbound

This paper cites Holmes: real-time apt detection through correlation of suspicious information flows,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Holmes: real-time apt detection through correlation of suspicious information flows,

Reference 40

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:11.394444Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:29:57.767033Z digest=sha256:95e36b893cfb040319673fb176322f991bb5366cba82a96b30afc340ddafa375

Observation cbeebed0-74d1-48ee-a866-766b6bff6071 · outbound

This paper cites Combating dependence ex- plosion in forensic analysis using alternative tag propagation semantics,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Combating dependence ex- plosion in forensic analysis using alternative tag propagation semantics,

Reference 41

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:11.269314Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:29:57.842744Z digest=sha256:b24d9900369d3a11f65be369515f3aa1741dfd2fe9f152d861b55ffedc87c0d3

Observation a636947d-19e2-49b2-a320-d78491761ad7 · outbound

This paper cites Nodemerge: Template based efficient data reduction for big-data causality analysis,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Nodemerge: Template based efficient data reduction for big-data causality analysis,

Reference 42

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:11.093865Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:29:57.892251Z digest=sha256:a399d439eb674c1c74162f37cf0cb8ca35407b0008d9ddff0889a7db514e9020

Observation b2ac9bd9-f63d-4626-966c-5eaf91cde3ea · outbound

This paper cites {SEAL}: Storage- efficient causality analysis on enterprise logs with query-friendly com- pression,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection {SEAL}: Storage- efficient causality analysis on enterprise logs with query-friendly com- pression,

Reference 43

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:11.001851Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:29:57.993856Z digest=sha256:c53e4ec9f76df93377ac425fff2e2725e4ad19b15cd2437dafacf53c47ec1909

Observation 1ab11741-c766-43ea-97c8-65bc9d4804af · outbound

This paper cites The case for learned provenance graph storage systems,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection The case for learned provenance graph storage systems,

Reference 44

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:10.837763Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:29:58.044421Z digest=sha256:a6c2e488d8042f47fdfdc11b5acec763b34b401a48c62fa24ba59a4c138e9f40

Observation 4c64684a-b93e-422a-9db1-e5cb21cc8751 · outbound

This paper cites Tactical provenance analysis for endpoint detection and response systems,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Tactical provenance analysis for endpoint detection and response systems,

Reference 45

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:10.693697Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:29:58.126512Z digest=sha256:48378d235df9391585769e371938e87a5c373dfeda304a1ffa95f9993f12d01e

Observation c55b2174-36bc-4d45-b1ce-2c3e572f58c0 · outbound

This paper cites Alchemist: Fusing application and audit logs for precise attack provenance without instrumentation,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Alchemist: Fusing application and audit logs for precise attack provenance without instrumentation,

Reference 46

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:10.559253Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:29:58.196404Z digest=sha256:c4ce7a3d34fcca638b4be903e7bb931f10ee356b9481c59bb4adb27d3de9efd1

Observation a14968af-ddc0-4579-8a48-b001a6daf866 · outbound

This paper cites Kairos: Practical Intrusion Detection and Investigation using Whole-system Provenance.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Kairos: Practical Intrusion Detection and Investigation using Whole-system Provenance

Reference 47

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:58.331185Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:58.331185Z digest=sha256:5c9aeccebf9202d03ba0f72d29facc520efc5a25571c33a9834c662daa0096a4

Observation 2a0b26fc-6f60-4aae-b79f-1c7d60d56c35 · outbound

This paper cites R-caid: Embedding root cause analysis within provenance-based intrusion detection,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection R-caid: Embedding root cause analysis within provenance-based intrusion detection,

Reference 48

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:10.419230Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:29:58.397703Z digest=sha256:f75c450f736420fe1708ff1416e25cad3e7f99e5612ecddfc04737f0e7d40b0b

Observation cd355c83-bf6e-49ac-acd8-6374431c1444 · outbound

This paper cites Shadewatcher: Recommendation-guided cyber threat analysis using system audit records,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Shadewatcher: Recommendation-guided cyber threat analysis using system audit records,

Reference 49

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:10.202376Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:29:58.480167Z digest=sha256:3108ed5975b15d7a65f48d8b9afc330082ed7f212f25cfb932a37ce98fc99116

Observation e674b14c-49a4-48d4-afc8-cea022764d6c · outbound

This paper cites SIGL: securing software installations through deep graph learning,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection SIGL: securing software installations through deep graph learning,

Reference 50

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:09.784335Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:29:58.581410Z digest=sha256:5ffc096eeb9e71c75acabb50538dff7ebfd479858f0dd9e24f06b36c131aab6c

Observation 4e0ca736-a786-4bc4-acbe-51fb416f1b0a · outbound

This paper cites Darpa tc engagement 3 ground-truth,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Darpa tc engagement 3 ground-truth,

Reference 51

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:09.643516Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:29:58.661412Z digest=sha256:739887dc7c8f65c368cf67eb654fca0caea57baaecfa8ebfb6df74e97ec0a63d

Observation eb275d39-3a86-4342-8385-8eff66bc6596 · outbound

This paper cites A Comprehensive Overview of Large Language Models (LLMs) for Cyber Defences: Opportunities and Directions.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection A Comprehensive Overview of Large Language Models (LLMs) for Cyber Defences: Opportunities and Directions

Reference 52

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:58.767171Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:58.767171Z digest=sha256:43dfda7ec889723ae3ce432e282952b4ed360ff1ea892f95e81452593b52b575

Observation 50cf2013-9dd2-4a06-b1de-2683af952af4 · outbound

This paper cites AutoAttacker: A Large Language Model Guided System to Implement Automatic Cyber-attacks.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection AutoAttacker: A Large Language Model Guided System to Implement Automatic Cyber-attacks

Reference 53

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:58.851040Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:58.851040Z digest=sha256:25534ff0c6f2da670ef1c53dffd91fcc0f42158485f59fd92e17aae30dc678aa

Observation e00dd72d-9c72-4f3d-a575-cdf0b69b69b4 · outbound

This paper cites {PentestGPT}: Evaluating and harnessing large language models for automated penetration testing,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection {PentestGPT}: Evaluating and harnessing large language models for automated penetration testing,

Reference 54

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:09.436223Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:29:58.977515Z digest=sha256:499b7864404cca9bf14e862c742a1c1a23ee7ec2b63605b683a7e869c45e22c1

Observation a13b05ca-5738-4d33-9109-b90f79215757 · outbound

This paper cites Large language model guided protocol fuzzing,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Large language model guided protocol fuzzing,

Reference 55

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:59.047072Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:59.047072Z digest=sha256:febb7776c26b32f040a77fbfc623f1390be9bd4154b881f964700596acbee8b3

Observation fa90e2fd-1840-47a0-ab46-5aaa40e79302 · outbound

This paper cites Exploring {ChatGPT’s} capabilities on vulnerability management,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Exploring {ChatGPT’s} capabilities on vulnerability management,

Reference 56

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:09.208433Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:29:59.121697Z digest=sha256:7df641f06489097ad7cfd0dac86a87577cfaa3014eaa5a679614f7638e342109

Observation 9f848941-9faf-4cab-8752-77b90f8a62cb · outbound

This paper cites RACONTEUR: A Knowledgeable, Insightful, and Portable LLM-Powered Shell Command Explainer.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection RACONTEUR: A Knowledgeable, Insightful, and Portable LLM-Powered Shell Command Explainer

Reference 57

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:59.187409Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:59.187409Z digest=sha256:3e96bc2ff47e49cae4536d8af522a8b97d302658635309ebf022171e88337c26

Observation 8672f890-1202-4141-958f-caa8166b5092 · outbound

This paper cites Deeplog: Anomaly detection and diagnosis from system logs through deep learning,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Deeplog: Anomaly detection and diagnosis from system logs through deep learning,

Reference 58

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:59.259554Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:59.259554Z digest=sha256:660dee648a9a1e8f47f3bd245b9f6fdd8dc7d2b61c2f2510ad7a42a652277f3e

Observation 8173209c-0ee5-4ae3-bf7d-aae14f1b27b0 · outbound

This paper cites Log2vec: A heterogeneous graph embedding based approach for detecting cyber threats within enterprise,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Log2vec: A heterogeneous graph embedding based approach for detecting cyber threats within enterprise,

Reference 59

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:08.963852Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:29:59.331971Z digest=sha256:1cc84d262d46a8e7f63f602a595552cac89eab3c4a397eed9944687a6c8faa70

Observation cc428afa-144e-4f12-886a-9a40a3e882d4 · outbound

This paper cites {ATTACK2VEC}: Leveraging temporal word embeddings to understand the evolution of cyberattacks,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection {ATTACK2VEC}: Leveraging temporal word embeddings to understand the evolution of cyberattacks,

Reference 60

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:08.778686Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:29:59.388082Z digest=sha256:48fbcb5868df797b00aa01c059e81e00462f9e6b70f2be68d8650e004e094696

Observation 47815c30-c1c6-4137-b7f2-f6359a5f3231 · outbound

This paper cites Semantic anomaly detection with large language models,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Semantic anomaly detection with large language models,

Reference 61

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:59.475590Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:59.475590Z digest=sha256:bd1e79d14e694677f8eb8ab3c4201bfe0af205a59cc5862631e7b013bf70116f

Observation 0ebfde0e-8156-416d-bf86-6f6f17022f13 · outbound

This paper cites tiktoken,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection tiktoken,

Reference 62

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:08.548005Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:29:59.548683Z digest=sha256:c98681134ebbe0791e9220f1892ad21f60f59563af6596e34e01db497393894e

Observation 3d985bc1-cec7-44e5-919f-670e01084ff8 · outbound

This paper cites NoLiMa: Long-Context Evaluation Beyond Literal Matching.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection NoLiMa: Long-Context Evaluation Beyond Literal Matching

Reference 63

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:59.630413Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:59.630413Z digest=sha256:f8f1791f31d6024598e28bd6a9a6bbf87a510ee4335609a081f82062482a1757

Observation c6ec1f36-3fc1-4e39-87c5-a10f0317f963 · outbound

This paper cites Fundamental limits of prompt compression: A rate-distortion framework for black-box language models,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Fundamental limits of prompt compression: A rate-distortion framework for black-box language models,

Reference 64

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:08.403909Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:29:59.673991Z digest=sha256:2915cd659927f9815e6ae10c848628fcfeed2737f860bf0d837bc227a1efdbdb

Observation 3e9b5f89-4d86-460f-b30e-e4fb93c622a8 · outbound

This paper cites A Systematic Survey of Prompt Engineering in Large Language Models: Techniques and Applications.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection A Systematic Survey of Prompt Engineering in Large Language Models: Techniques and Applications

Reference 65

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:59.766686Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:59.766686Z digest=sha256:42bae02a6e9496839c8b728d83e5fbc9ed5c6feaafb7374957b524079e48ed58

Observation 34dace7f-e0ec-452c-b684-9b55bb187ec7 · outbound

This paper cites Chain-of-thought prompting elicits reasoning in large language models,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Chain-of-thought prompting elicits reasoning in large language models,

Reference 66

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:59.821399Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:59.821399Z digest=sha256:7569b9f9a8ee12e7a32968ae35b213f7177941527ada03a5135c709aa231ebf0

Observation 37adf0a8-5c73-4ae2-9e9a-ac887b188d38 · outbound

This paper cites Self-Consistency Improves Chain of Thought Reasoning in Language Models.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Self-Consistency Improves Chain of Thought Reasoning in Language Models

Reference 67

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:59.893803Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:59.893803Z digest=sha256:c5206064d82aa5e69a6eeb3c5e98df57f562eb3d81a4c01aadaa92aee2b8b94e

Observation 61f762c5-d2ae-49be-8a2e-19e6c3018b46 · outbound

This paper cites Custos: Practical tamper-evident auditing of operating systems using trusted execution,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Custos: Practical tamper-evident auditing of operating systems using trusted execution,

Reference 68

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:08.204888Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:30:00.030936Z digest=sha256:5203c92bb3631c3e2db4a809740b1ce35e3b06256490e68d4f52cf7a38fbd025

Observation 5a51d194-754b-4757-8bc0-cff2a5b38694 · outbound

This paper cites Auditing frameworks need resource isolation: A systematic study on the super producer threat to system auditing and its mitigation,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Auditing frameworks need resource isolation: A systematic study on the super producer threat to system auditing and its mitigation,

Reference 69

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:07.998211Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:30:00.104146Z digest=sha256:1af16e4add6a91a72103ef9661f1a8d6ac04646960f28b30eb27ac30aabf4578

Observation eb7bc96a-190c-4e83-b42a-c7e80283763e · outbound

This paper cites Support vector method for novelty detection,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Support vector method for novelty detection,

Reference 70

Resolution
unresolved
no resolver link, observed 2026-08-06T17:30:00.181120Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:30:00.181120Z digest=sha256:2eaed485991b2f3c448f74a4640cb890c299adcf623efea12b131010ee57f754

Observation 5c7022b8-b34e-4229-b239-e6d9f0c42b9b · outbound

This paper cites Bert: Pre-training of deep bidirectional transformers for language understanding,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Bert: Pre-training of deep bidirectional transformers for language understanding,

Reference 71

Resolution
unresolved
no resolver link, observed 2026-08-06T17:30:00.248846Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:30:00.248846Z digest=sha256:e9d31de4e06096eb1eb33644c62fcb2e5b6405866a1ce114ea2865dbfe2fe25c

Observation c26624ca-fdd1-40d9-b51e-14501afc0029 · outbound

This paper cites bert-base-uncased,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection bert-base-uncased,

Reference 72

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:07.768556Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:30:00.328746Z digest=sha256:43856a5e5e2366bd325054deddb8c929d30cc3bfd4e59aa01f74df22e239a857

Observation 99832e11-fd86-4a71-8ce3-a65a9c4bb9ca · outbound

This paper cites RetroMAE: Pre-Training Retrieval-oriented Language Models Via Masked Auto-Encoder.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection RetroMAE: Pre-Training Retrieval-oriented Language Models Via Masked Auto-Encoder

Reference 73

Resolution
unresolved
no resolver link, observed 2026-08-06T17:30:00.412279Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:30:00.412279Z digest=sha256:6ad9b33d3898796bec07b08649921c580dedc53debffad40256527b9e84fe06e

Observation 8d3cd82d-e2ab-4432-be2e-9770047c3b9a · outbound

This paper cites Backtracking intrusions,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Backtracking intrusions,

Reference 74

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:07.669440Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:30:00.514080Z digest=sha256:08fa3cfa8fb1dd7d422b7bc225f55b9e517ae9507947025cf1a523f8b17a2be1

Observation 264a1406-3a78-4df1-b5ca-3cddd1e5527d · outbound

This paper cites Representative sam- pling for reliable data analysis: theory of sampling,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Representative sam- pling for reliable data analysis: theory of sampling,

Reference 75

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:07.506534Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:30:00.614753Z digest=sha256:599536192805a68a49444b5bd3650d635538d70d69bd154b1e1f239ab27e4acc

Observation 029e3d08-2928-4994-abc7-a1d8f112e856 · outbound

This paper cites ATLAS: A sequence-based learning approach for attack investigation,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection ATLAS: A sequence-based learning approach for attack investigation,

Reference 76

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:07.310877Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:30:00.709741Z digest=sha256:0ad5baf089d0c145cdafea176649947dce50f59e2d9c4ca89d493ca0b5800a57

Observation 692a6a49-6875-466f-8ed8-10c6f9a316ae · outbound

This paper cites Threatrace: Detecting and tracing host-based threats in node level through provenance graph learning,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Threatrace: Detecting and tracing host-based threats in node level through provenance graph learning,

Reference 77

Resolution
unresolved
no resolver link, observed 2026-08-06T17:30:00.791725Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:30:00.791725Z digest=sha256:95206fbf273a4bac10b388c560a2ef1948723b8ff7357e4f0891596250d7c93d

Observation 753570f1-183c-4067-b2cf-fff35d4eae1d · outbound

This paper cites Mitigating advanced and persistent threat (apt) damage by reasoning with provenance in large enterprise network (marple) program,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Mitigating advanced and persistent threat (apt) damage by reasoning with provenance in large enterprise network (marple) program,

Reference 78

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:07.144132Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:30:00.883684Z digest=sha256:c32e92607ad14ba78f4b1f3caf5b937a4ce9035b724f649ce8fb558686c3221d

Observation e50e8dec-88b4-4ef6-9dba-5761ca5dfe89 · outbound

This paper cites Atlasv2,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Atlasv2,

Reference 79

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:06.928481Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:30:00.985610Z digest=sha256:d3aaf88b2ca8c973802233ba02dcc7480c512dc3159f1366e4e59236fadf47a6

Observation a7444d72-e49e-49ab-ae43-04c093b4fc7e · outbound

This paper cites Flash repo,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Flash repo,

Reference 80

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:06.668629Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:30:01.065685Z digest=sha256:5e15db493d58da85f638666b1fab39746efd00a7145ec201b3c6c2bb384457bd

Observation a05f47ee-be04-4128-bb15-047193a9860c · outbound

This paper cites Magic repo,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Magic repo,

Reference 81

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:06.402552Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:30:01.196441Z digest=sha256:1225159be789c20ebfe45100eecc011bcdec7662c98a3b09bbbbff1c44975717

Observation f24993d7-3ba3-470b-8acf-bc5c0eee970f · outbound

This paper cites Orthrus repo,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Orthrus repo,

Reference 82

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:06.203612Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:30:01.278438Z digest=sha256:12abe18349d04b81bdbff47208e412e08c997adbfd3009fda0d101d4fba8afc1

Observation 2b2b42d8-8271-42bc-822c-d70abc547a4b · outbound

This paper cites Airtag repo,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Airtag repo,

Reference 83

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:05.960843Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:30:01.330764Z digest=sha256:e569f826b8b49f7c5d12e093f040c1af639a2dec5493b2a7c5db15f09de8111d

Observation 7778bf9a-0a31-403c-81b8-ca8c53d90919 · outbound

This paper cites Atlas dataset,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Atlas dataset,

Reference 84

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:05.721419Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:30:01.420613Z digest=sha256:f42fccf79f6202a1149698c140d86c724222b5072562b61372027f543b612dcd

Observation 29df7f98-d898-4900-8254-af9e293b2e0b · outbound

This paper cites DeepSeek-R1: Incentivizing Reasoning Capability in LLMs via Reinforcement Learning.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection DeepSeek-R1: Incentivizing Reasoning Capability in LLMs via Reinforcement Learning

Reference 85

Resolution
unresolved
no resolver link, observed 2026-08-06T17:30:01.535060Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:30:01.535060Z digest=sha256:eb7c1dec2abdb9621db519510309981ab86e11051a368226ab7dfce136e3ee70

Observation d083c56b-190b-4321-80e5-0bbdf127b5bb · outbound

This paper cites The Llama 3 Herd of Models.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection The Llama 3 Herd of Models

Reference 86

Resolution
unresolved
no resolver link, observed 2026-08-06T17:30:01.634139Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:30:01.634139Z digest=sha256:afcb0ef02e3141b531ceff29ab321c6c2155127b45d7a7b06c40184c52a05a3a

Observation 0cdc90d4-c8ad-4a56-987b-d6b1ef6a9c98 · outbound

This paper cites Openai o3-mini,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Openai o3-mini,

Reference 87

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:05.515588Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:30:01.764153Z digest=sha256:5e2872d241ac992ee758edb241669167ac679094492191f03293ebc0570cc029

Observation c6d97db2-39a2-4894-be5a-b09f6bb0919b · outbound

This paper cites Sonar reasoning pro,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Sonar reasoning pro,

Reference 88

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:05.318796Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:30:01.829143Z digest=sha256:bdb0c1024302015ca949431ade42ba762648bb8ac98e2bf2e00b48b5cfd0725a

Observation c5113323-6e29-48b3-8951-d6deba6d9b03 · outbound

This paper cites all-MiniLM-L6-v2,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection all-MiniLM-L6-v2,

Reference 89

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:05.151212Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:30:01.932568Z digest=sha256:3db59ec4bb314d4eb57a94ff7318855e3d68adb30617410d7e6708fbb34ad3ea

Observation dccc9578-dceb-4cae-99e2-1e3dcc0cfa48 · outbound

This paper cites SemEval-2017 Task 1: Semantic Textual Similarity - Multilingual and Cross-lingual Focused Evaluation.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection SemEval-2017 Task 1: Semantic Textual Similarity - Multilingual and Cross-lingual Focused Evaluation

Reference 90

Resolution
unresolved
no resolver link, observed 2026-08-06T17:30:02.021302Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:30:02.021302Z digest=sha256:c6a939312c8c29bf8a740b9a36ab01b1a9f7990bc3df57e3ba61e25441f22f0f

Observation 53ef3339-c6cc-4ace-8b3a-48db4f1b85d6 · outbound

This paper cites (2025) Api pricing.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection (2025) Api pricing

Reference 91

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:04.934529Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:30:02.137618Z digest=sha256:a12d24be6c660158ac67ae0411dad99534aa18129b8dadc6d576820801d23c5b

Observation 602419b2-44a9-495f-b8f3-f11e16810ccb · outbound

This paper cites Attacks on deidentification’s defenses,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Attacks on deidentification’s defenses,

Reference 92

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:04.738393Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:30:02.256881Z digest=sha256:f5528b5be10502fa34c526748893816704529442bb2cf80d91c309d8098c7f5f

Observation 985fefb7-c75f-4fdc-a66a-c262d885aec3 · outbound

This paper cites LlamaFactory: Unified Efficient Fine-Tuning of 100+ Language Models.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection LlamaFactory: Unified Efficient Fine-Tuning of 100+ Language Models

Reference 93

Resolution
unresolved
no resolver link, observed 2026-08-06T17:30:02.345862Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:30:02.345862Z digest=sha256:1dea5cf169bb0503882da4dd73e7ae9ca35d894ae76ad0a72f3a033a2e8f7fff

Observation d9ca10db-f661-4016-92b3-beff54f075b1 · outbound

This paper cites s1: Simple test-time scaling.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection s1: Simple test-time scaling

Reference 94

Resolution
unresolved
no resolver link, observed 2026-08-06T17:30:02.499902Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:30:02.499902Z digest=sha256:64470c98735f8869d058cb3a7cad2326c8fcc3566d9742e3b45a391295d6c33f

Observation 7172ed78-bb13-4fd4-be47-6d7877ac3bd1 · outbound

This paper cites Persistent Pre-Training Poisoning of LLMs.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Persistent Pre-Training Poisoning of LLMs

Reference 95

Resolution
unresolved
no resolver link, observed 2026-08-06T17:30:02.613382Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:30:02.613382Z digest=sha256:66a5a35800eae51f849c185f674b3fe09caf20c21c415c609f52da24f6340aa1

Observation 130925ab-1efb-4e0e-a993-56414968dbcb · outbound

This paper cites Sok: Pragmatic assessment of machine learning for network intrusion detection,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Sok: Pragmatic assessment of machine learning for network intrusion detection,

Reference 96

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:04.575165Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:30:02.728879Z digest=sha256:9b0e6f92e6d2720a2c34f32ff46fc6304063fdc8f80eccf44653344c7db2b035

Observation 7d98fc00-c8fa-4411-be94-0ae4b934d7d7 · outbound

This paper cites A survey on data-driven network intrusion detection,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection A survey on data-driven network intrusion detection,

Reference 97

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:04.381432Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T17:30:02.816653Z digest=sha256:63b627aa6443532a78374f34a9f4caff252647705f71f0ee946ff8986cfb5133

Pith citing papers

No inbound Pith citation observations are available.