{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:XHUD5P6I4IDEPBEUO5ABAND35E","short_pith_number":"pith:XHUD5P6I","schema_version":"1.0","canonical_sha256":"b9e83ebfc8e206478494774010347be912e405a5e648b8bed095f42e3eee7b3e","source":{"kind":"arxiv","id":"2408.08902","version":1},"attestation_state":"computed","paper":{"title":"Audit-LLM: Multi-Agent Collaboration for Log-based Insider Threat Detection","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Chengyu Song, Hongyu Kuang, Jianming Zheng, Jinzhi Liao, Linru Ma, Lin Yang","submitted_at":"2024-08-12T11:33:45Z","abstract_excerpt":"Log-based insider threat detection (ITD) detects malicious user activities by auditing log entries. Recently, large language models (LLMs) with strong common sense knowledge have emerged in the domain of ITD. Nevertheless, diverse activity types and overlong log files pose a significant challenge for LLMs in directly discerning malicious ones within myriads of normal activities. Furthermore, the faithfulness hallucination issue from LLMs aggravates its application difficulty in ITD, as the generated conclusion may not align with user commands and activity context. In response to these challeng"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2408.08902","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2024-08-12T11:33:45Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"4e4bb69f6f0df6ff74df988a7253fbb76f5fb8225e5ed248d81fe4dd5b48564b","abstract_canon_sha256":"3f4035f137c3128597054b51cce062c05bf6d3aca0c66ecfd084140a387d69c0"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T08:56:25.319160Z","signature_b64":"+OvSFp6HSOVdAJzGrTsYGEJE01eUEKg4G4aYQ4hJQEvNo1zCzqsefzhYXptGmQo0gCP8mvi5LLT3Zb9DdsNMBg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"b9e83ebfc8e206478494774010347be912e405a5e648b8bed095f42e3eee7b3e","last_reissued_at":"2026-07-05T08:56:25.318619Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T08:56:25.318619Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Audit-LLM: Multi-Agent Collaboration for Log-based Insider Threat Detection","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Chengyu Song, Hongyu Kuang, Jianming Zheng, Jinzhi Liao, Linru Ma, Lin Yang","submitted_at":"2024-08-12T11:33:45Z","abstract_excerpt":"Log-based insider threat detection (ITD) detects malicious user activities by auditing log entries. Recently, large language models (LLMs) with strong common sense knowledge have emerged in the domain of ITD. Nevertheless, diverse activity types and overlong log files pose a significant challenge for LLMs in directly discerning malicious ones within myriads of normal activities. Furthermore, the faithfulness hallucination issue from LLMs aggravates its application difficulty in ITD, as the generated conclusion may not align with user commands and activity context. In response to these challeng"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2408.08902","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2408.08902/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2408.08902","created_at":"2026-07-05T08:56:25.318683+00:00"},{"alias_kind":"arxiv_version","alias_value":"2408.08902v1","created_at":"2026-07-05T08:56:25.318683+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2408.08902","created_at":"2026-07-05T08:56:25.318683+00:00"},{"alias_kind":"pith_short_12","alias_value":"XHUD5P6I4IDE","created_at":"2026-07-05T08:56:25.318683+00:00"},{"alias_kind":"pith_short_16","alias_value":"XHUD5P6I4IDEPBEU","created_at":"2026-07-05T08:56:25.318683+00:00"},{"alias_kind":"pith_short_8","alias_value":"XHUD5P6I","created_at":"2026-07-05T08:56:25.318683+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":7,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.10281","citing_title":"Benchmarking and Exploring the Capabilities of LLMs for Attack Investigations","ref_index":50,"is_internal_anchor":false},{"citing_arxiv_id":"2607.00440","citing_title":"Minos: A Multi-Agent Collaborative Framework for Provenance-Based Backward Tracking","ref_index":25,"is_internal_anchor":false},{"citing_arxiv_id":"2604.16359","citing_title":"LLM4Log: A Systematic Review of Large Language Model-based Log Analysis","ref_index":156,"is_internal_anchor":false},{"citing_arxiv_id":"2603.04474","citing_title":"From Spark to Fire: Modeling and Mitigating Error Cascades in LLM-Based Multi-Agent Collaboration","ref_index":39,"is_internal_anchor":false},{"citing_arxiv_id":"2603.18196","citing_title":"Retrieval-Augmented LLMs for Security Incident Analysis","ref_index":6,"is_internal_anchor":false},{"citing_arxiv_id":"2604.16359","citing_title":"LLM4Log: A Systematic Review of Large Language Model-based Log Analysis","ref_index":156,"is_internal_anchor":false},{"citing_arxiv_id":"2605.08316","citing_title":"AI-Driven Security Alert Screening and Alert Fatigue Mitigation in Security Operations Centers: A Comprehensive Survey","ref_index":137,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/XHUD5P6I4IDEPBEUO5ABAND35E","json":"https://pith.science/pith/XHUD5P6I4IDEPBEUO5ABAND35E.json","graph_json":"https://pith.science/api/pith-number/XHUD5P6I4IDEPBEUO5ABAND35E/graph.json","events_json":"https://pith.science/api/pith-number/XHUD5P6I4IDEPBEUO5ABAND35E/events.json","paper":"https://pith.science/paper/XHUD5P6I"},"agent_actions":{"view_html":"https://pith.science/pith/XHUD5P6I4IDEPBEUO5ABAND35E","download_json":"https://pith.science/pith/XHUD5P6I4IDEPBEUO5ABAND35E.json","view_paper":"https://pith.science/paper/XHUD5P6I","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2408.08902&json=true","fetch_graph":"https://pith.science/api/pith-number/XHUD5P6I4IDEPBEUO5ABAND35E/graph.json","fetch_events":"https://pith.science/api/pith-number/XHUD5P6I4IDEPBEUO5ABAND35E/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/XHUD5P6I4IDEPBEUO5ABAND35E/action/timestamp_anchor","attest_storage":"https://pith.science/pith/XHUD5P6I4IDEPBEUO5ABAND35E/action/storage_attestation","attest_author":"https://pith.science/pith/XHUD5P6I4IDEPBEUO5ABAND35E/action/author_attestation","sign_citation":"https://pith.science/pith/XHUD5P6I4IDEPBEUO5ABAND35E/action/citation_signature","submit_replication":"https://pith.science/pith/XHUD5P6I4IDEPBEUO5ABAND35E/action/replication_record"}},"created_at":"2026-07-05T08:56:25.318683+00:00","updated_at":"2026-07-05T08:56:25.318683+00:00"}