Skip to content
Preprint

TGL-APT: Temporal Graph Learning with Graph Distillation for Efficient APT Investigation

Aug 2026 · 0 citations · 39 references
Computer Science

TL;DR

TGL-APT effectively balances detection performance, computational efficiency, and investigation capability for provenance-based APT analysis, and is demonstrated to reduce training time, detection latency, and memory usage compared with KAIROS.

Abstract

Advanced Persistent Threat (APT) attacks pose a critical challenge to modern systems, as their stealthy, multi-stage nature renders conventional detection methods ineffective. While provenance graphs provide rich behavioral context for attack investigation, attack-relevant evidence is often sparse and embedded in large volumes of routine system activity, making full-graph learning both computationally expensive and difficult to correlate over long attack sequences. We present TGL-APT, an adaptive investigation framework built on the observation that attack-relevant information is non-uniformly distributed and often mediated by structurally influential or behaviorally distinctive entities, which we characterize as information-bottleneck nodes. TGL-APT combines three complementary components: (1) information-bottleneck-guided graph distillation that suppresses provenance redundancy while bounding structural distortion and preserving causal reachability; (2) adaptive temporal graph learning that continuously refines the core node set as node relevance evolves; and (3) cross-spatiotemporal attack fingerprint alignment that associates fragmented suspicious activities across different entities and time windows. Finally, causal expansion and stage characterization reconstruct coherent attack processes for investigation. Experiments on three DARPA E3 datasets show F1-scores of 95.7%, 90.9%, and 88.9%, while reducing training time, detection latency, and memory usage by approximately 39%, 33%, and 22%, respectively, compared with KAIROS. These results demonstrate that TGL-APT effectively balances detection performance, computational efficiency, and investigation capability for provenance-based APT analysis.

View source

Similar papers

Open access Aug 2026

TGPA: Transferable graph prompt attack with hierarchical subgraph augmentation.

A novel transferable graph prompt attack, called TGPA, is proposed, which shifts the attack paradigm by introducing a hierarchical structural decoupling mechanism, which reduces the performance of pre-trained graph models with graph prompts by up to 28.9%, while guaranteeing robustness, stealthiness, and transferability.

Ju Jia, Haonan Wang, Tian Wu et al. · 0 citations
Jul 2026

SAGA: Synthetic Agentic Graph Architecture for Temporal Benchmark Generation

SAGA (Synthetic Agentic Graph Architecture), a system for generating large-scale, semantically rich temporal graphs via a four-phase pipeline, achieves structural realism, semantic richness, and automatic anomaly labeling in a unified framework.

Jiacheng Ding, Xiaofei Zhang · 0 citations
Book Open access Aug 2026

DyGADBench: A Comprehensive Benchmark for Anomaly Detection in Dynamic Graphs

Dynamic graph anomaly detection (DGAD) is critical for a wide range of applications where abnormal events are rare, evolving, and tightly coupled with temporal context. Despite rapid progress in modeling dynamic graphs, the evaluation of DGAD methods remains fragmented, leaving the strengths, limitations, and trade-offs of state-of-the-art models poorly understood. We introduce DyGADBench, a comprehensive benchmark designed specifically for Dy namic G raph A nomaly D etection. It defines a diverse set of injected anomaly patterns spanning localized, global, and temporally persistent behaviors, reflecting a wide range of real-world scenarios; introduces a unifying taxonomy that organizes DGAD methods along core design axes, clarifying architectural and temporal modeling choices; and provides a unified and reproducible evaluation pipeline. We conduct an extensive empirical study of state-of-the-art DGAD models. Our findings reveal that detection difficulty increases consistently with anomaly complexity, from simple localized irregularities to coordinated and temporally persistent structures. We uncover a fundamental tension between architectural biases: methods emphasizing local structural information perform well on structure-dominated anomalies, while methods leveraging global temporal context excel on long-range anomalies, yet no approach reliably handles both. Moreover, scalability emerges as a critical bottleneck, with many high-performing methods incurring prohibitive computational or memory costs on large dynamic graphs. Together, these findings provide systematic insights into the interplay between anomaly characteristics, model design, and scalability, and point toward key directions for future research in dynamic graph anomaly detection. DyGADBench is publicly available at: https://github.com/Dastamn/dgadb.

Mohamed Nazim Mezhoudi, Guillaume Lachaud, Yanlei Diao et al. · 0 citations
#natural language process... Preprint Aug 2026

BEACON: Behavior-Anchored Cross-Source Knowledge Graph Construction for Cyber Threat Intelligence

BEACON is an LLM-driven framework for cross-source CTI knowledge graph construction that constructs and releases two human-annotated datasets from 34 sources and outperforms all baselines by at least 23% and 9%, respectively.

Changze Li, Yutong Cheng, Tsania Camila Finnisa et al. · 0 citations
Conference Open access 2026

CAPG-v2: Impact-Weighted, Multi-Path Vulnerability Prioritization over CVE-Centric Attack-Position Graphs

: Vulnerability management routinely relies on per-CVE (Common Vulnerabilities and Exposures) severity scores or exploitability scores, yet real intrusions are multi-step: attackers chain exploits across hosts to reach high-impact goals. Attack graphs capture these dependencies, but many prioritization methods still under-represent two practical realities: (i) overlap the same CVE can appear on many distinct attack paths, so patching it can block multiple routes; and (ii) impact heterogeneity different goals (e.g., domain admin vs. data exfiltration) imply different losses. Building on CAPG, a recent CVE representation designed to construct attack-position graphs, we introduce CAPG-v2: a lightweight extension that adds probabilistic semantics and goal impact annotations, enabling impact-weighted and overlap-aware prioritization. We formalize (a) a path-based score that aggregates across distinct goal-reaching paths and (b) an enumeration-free Monte Carlo marginal expected-loss reduction score that avoids explicit path enumeration. Rather than treating vulnerabilities as isolated items, CAPG-v2 supports patch prioritization as a graph-aware risk-reduction problem in which remediation decisions are guided by attacker behavior, shared attack routes, and the business impact of reachable goals. We further provide JSON artifacts and a reference evaluator to support replication and extension.

Noufal Issa, Damas P. Gruska, Loubna Ali · 0 citations

LADE: LLM-Assisted Advanced Persistent Threat Detection and Explanation

Experimental results show that LLMs, when guided by rubric-based prompts and supplemented with ATT&CK domain knowledge, achieve robust performance across detection, localization, and TTP mapping tasks.

Joon-Young Gwak, Aubrey Strier, Zhaohan Xi et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.