{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,11]],"date-time":"2026-05-11T11:19:46Z","timestamp":1778498386408,"version":"3.51.4"},"publisher-location":"Singapore","reference-count":37,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819203741","type":"print"},{"value":"9789819203758","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-981-92-0375-8_30","type":"book-chapter","created":{"date-parts":[[2026,5,11]],"date-time":"2026-05-11T11:01:19Z","timestamp":1778497279000},"page":"494-510","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["PG-MoE: Provenance-Based Intrusion Detection via\u00a0Graph Mixture-of-Experts and\u00a0Spatio-Temporal Contrastive Learning"],"prefix":"10.1007","author":[{"given":"Xuebo","family":"Qiu","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mingqi","family":"Lv","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yimei","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qijie","family":"Song","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tieming","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2026,5,12]]},"reference":[{"key":"30_CR1","unstructured":"Adam, K.D.B.J., et\u00a0al.: A method for stochastic optimization. arXiv preprint arXiv:1412.69801412(6) (2014)"},{"key":"30_CR2","doi-asserted-by":"crossref","unstructured":"Chen, M., et\u00a0al.: Deep contrastive graph learning with clustering-oriented guidance. In: Proceedings of the AAAI Conference on Artificial Intelligence, vol.\u00a038, pp. 11364\u201311372 (2024)","DOI":"10.1609\/aaai.v38i10.29016"},{"key":"30_CR3","doi-asserted-by":"crossref","unstructured":"Chen, T., Chen, X., Du, X., et\u00a0al.: AdaMV-MoE: Adaptive multi-task vision mixture-of-experts. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp. 17346\u201317357 (2023)","DOI":"10.1109\/ICCV51070.2023.01591"},{"key":"30_CR4","doi-asserted-by":"crossref","unstructured":"Chen, T., et\u00a0al.: XGBoost: a scalable tree boosting system. In: ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (2016)","DOI":"10.1145\/2939672.2939785"},{"key":"30_CR5","doi-asserted-by":"crossref","unstructured":"Chen, T., Dong, C., Lv, M., et\u00a0al.: APT-KGL: An intelligent apt detection system based on threat knowledge and heterogeneous provenance graph learning. IEEE Trans. Dependable Secure Comput. 1\u201315 (2022)","DOI":"10.1109\/TDSC.2022.3229472"},{"key":"30_CR6","doi-asserted-by":"crossref","unstructured":"Cheng, Z., Lv, Q., Liang, J., et\u00a0al.: Kairos: practical intrusion detection and investigation using whole-system provenance. In: 2024 IEEE Symposium on Security and Privacy (SP), pp. 3533\u20133551. IEEE (2024)","DOI":"10.1109\/SP54263.2024.00005"},{"key":"30_CR7","unstructured":"Corporation, M.: Mitre att&ck. https:\/\/attack.mitre.org (2015)"},{"key":"30_CR8","unstructured":"Darpa: Transparent computing engagement 3 data release (2017). https:\/\/github.com\/darpa-i2o\/Transparent-Computing\/blob\/master\/README-E3.md"},{"key":"30_CR9","unstructured":"Du, N., Huang, Y., Dai, A.M., et\u00a0al.: Glam: efficient scaling of language models with mixture-of-experts. In: International Conference on Machine Learning (2022)"},{"key":"30_CR10","doi-asserted-by":"crossref","unstructured":"Goyal, A., Han, X., Wang, G., Bates, A.: Sometimes, you aren\u2019t what you do: mimicry attacks against provenance graph host intrusion detection systems. In: 30th Network and Distributed System Security Symposium (2023)","DOI":"10.14722\/ndss.2023.24207"},{"key":"30_CR11","doi-asserted-by":"crossref","unstructured":"Goyal, A., et\u00a0al.: R-caid: embedding root cause analysis within provenance-based intrusion detection. In: 2024 IEEE Symposium on Security and Privacy (SP), pp. 3515\u20133532. IEEE (2024)","DOI":"10.1109\/SP54263.2024.00253"},{"key":"30_CR12","unstructured":"Hamilton, W., Ying, Z., Leskovec, J.: Inductive representation learning on large graphs. Adv. Neural Inf. Process. Syst. 30 (2017)"},{"key":"30_CR13","doi-asserted-by":"crossref","unstructured":"Han, X., et\u00a0al.: Unicorn: runtime provenance-based detector for advanced persistent threats. In: Network and Distributed System Security Symposium (2020)","DOI":"10.14722\/ndss.2020.24046"},{"issue":"1","key":"30_CR14","doi-asserted-by":"publisher","first-page":"79","DOI":"10.1162\/neco.1991.3.1.79","volume":"3","author":"RA Jacobs","year":"1991","unstructured":"Jacobs, R.A., Jordan, M.I., Nowlan, S.J., Hinton, G.E.: Adaptive mixtures of local experts. Neural Comput. 3(1), 79\u201387 (1991)","journal-title":"Neural Comput."},{"key":"30_CR15","unstructured":"Jia, Z., Xiong, Y., Nan, Y., Zhang, Y., Zhao, J., Wen, M.: Magic: detecting advanced persistent threats via masked graph representation learning (2023)"},{"issue":"3","key":"30_CR16","doi-asserted-by":"publisher","first-page":"535","DOI":"10.1109\/TBDATA.2019.2921572","volume":"7","author":"J Johnson","year":"2019","unstructured":"Johnson, J., Douze, M., J\u00e9gou, H.: Billion-scale similarity search with GPUs. IEEE Transactions on Big Data 7(3), 535\u2013547 (2019)","journal-title":"IEEE Transactions on Big Data"},{"key":"30_CR17","doi-asserted-by":"crossref","unstructured":"Li, S., Dong, F., Xiao, X., et\u00a0al.: Nodlink: an online system for fine-grained apt attack detection and investigation. arXiv preprint arXiv:2311.02331 (2023)","DOI":"10.14722\/ndss.2024.23204"},{"key":"30_CR18","doi-asserted-by":"crossref","unstructured":"Luo, Y., Li, S., Sui, Y., et\u00a0al.: Masked graph modeling with multi-view contrast. In: International Conference on Data Engineering (ICDE). IEEE (2024)","DOI":"10.1109\/ICDE60146.2024.00203"},{"key":"30_CR19","doi-asserted-by":"crossref","unstructured":"Lv, M., Gao, H., Qiu, X., et\u00a0al.: TREC: apt tactic\/technique recognition via few-shot provenance subgraph learning. In: Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security (2024)","DOI":"10.1145\/3658644.3690221"},{"key":"30_CR20","unstructured":"MacQueen, J.: Some methods for classification and analysis of multivariate observations. In: Proceedings of the Fifth Berkeley Symposium on Mathematical Statistics and Probability, Volume 1: Statistics. vol.\u00a05, pp. 281\u2013298 (1967)"},{"key":"30_CR21","doi-asserted-by":"crossref","unstructured":"Mo, Y., Wang, X., Fan, S., Shi, C.: Graph contrastive invariant learning from the causal perspective. In: Proceedings of the AAAI Conference on Artificial Intelligence, vol.\u00a038, pp. 8904\u20138912 (2024)","DOI":"10.1609\/aaai.v38i8.28738"},{"issue":"2","key":"30_CR22","doi-asserted-by":"publisher","first-page":"1883","DOI":"10.4249\/scholarpedia.1883","volume":"4","author":"LE Peterson","year":"2009","unstructured":"Peterson, L.E.: K-nearest neighbor. Scholarpedia 4(2), 1883 (2009)","journal-title":"Scholarpedia"},{"key":"30_CR23","doi-asserted-by":"crossref","unstructured":"Qiu, X., Lv, M., Chen, T., Zhu, T., Song, Q.: Provenance-based intrusion detection via multi-scale graph representation learning. In: International Conference on Information and Communications Security, pp. 531\u2013549. Springer (2025)","DOI":"10.1007\/978-981-95-3543-9_29"},{"key":"30_CR24","unstructured":"Rehman, M.U., et\u00a0al.: Flash: a comprehensive approach to intrusion detection via provenance graph representation learning. In: 2024 IEEE Symposium on Security and Privacy (SP), pp. 139\u2013139. IEEE Computer Society (2024)"},{"key":"30_CR25","unstructured":"Shen, S., Hou, L., Zhou, Y., et\u00a0al.: Mixture-of-experts meets instruction tuning: a winning combination for large language models. In: The Twelfth International Conference on Learning Representations"},{"key":"30_CR26","unstructured":"Veli\u010dkovi\u0107, P., Cucurull, G., Casanova, A., et\u00a0al.: Graph attention networks. In: International Conference on Learning Representations (2018)"},{"key":"30_CR27","first-page":"50825","volume":"36","author":"H Wang","year":"2023","unstructured":"Wang, H., Jiang, Z., You, Y., et al.: Graph mixture of experts: learning on large-scale graphs with explicit diversity modeling. Adv. Neural. Inf. Process. Syst. 36, 50825\u201350837 (2023)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"30_CR28","first-page":"3972","volume":"17","author":"S Wang","year":"2022","unstructured":"Wang, S., Wang, Z., et al.: THREATRACE: detecting and tracing host-based threats in node level through provenance graph learning. TIFS 17, 3972\u20133987 (2022)","journal-title":"TIFS"},{"issue":"1","key":"30_CR29","doi-asserted-by":"publisher","first-page":"551","DOI":"10.1109\/TDSC.2020.2971484","volume":"19","author":"C Xiong","year":"2022","unstructured":"Xiong, C., Zhu, T., Dong, W., et al.: Conan: a practical real-time apt detection system with high accuracy and efficiency. IEEE Trans. Dependable Secure Comput. 19(1), 551\u2013565 (2022)","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"30_CR30","doi-asserted-by":"crossref","unstructured":"Xu, Y., Huang, S., Zhang, H., et\u00a0al.: Why does dropping edges usually outperform adding edges in graph contrastive learning? In: Proceedings of the AAAI Conference on Artificial Intelligence, vol.\u00a039, pp. 21824\u201321832","DOI":"10.1609\/aaai.v39i20.35488"},{"key":"30_CR31","doi-asserted-by":"crossref","unstructured":"Xu, Y., Shi, B., Ma, T., et\u00a0al.: CLDG: Contrastive learning on dynamic graphs. In: International Conference on Data Engineering (ICDE), pp. 696\u2013707. IEEE (2023)","DOI":"10.1109\/ICDE55515.2023.00059"},{"key":"30_CR32","first-page":"5812","volume":"33","author":"Y You","year":"2020","unstructured":"You, Y., Chen, T., Sui, Y., et al.: Graph contrastive learning with augmentations. Adv. Neural. Inf. Process. Syst. 33, 5812\u20135823 (2020)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"30_CR33","doi-asserted-by":"crossref","unstructured":"Zhang, Z., Qi, P., Wang, W.: Dynamic malware analysis with feature engineering and feature learning. In: Proceedings of the AAAI Conference on Artificial Intelligence, vol.\u00a034, pp. 1210\u20131217 (2020)","DOI":"10.1609\/aaai.v34i01.5474"},{"key":"30_CR34","doi-asserted-by":"crossref","unstructured":"Zhao, Y., Zheng, G., Mukherjee, S., et\u00a0al.: Admoe: anomaly detection with mixture-of-experts from noisy labels. In: Proceedings of the AAAI Conference on Artificial Intelligence, vol.\u00a037, pp. 4937\u20134945 (2023)","DOI":"10.1609\/aaai.v37i4.25620"},{"key":"30_CR35","doi-asserted-by":"crossref","unstructured":"Zhong, M., et\u00a0al.: A survey on graph neural networks for intrusion detection systems: methods, trends and challenges. Comput. Secur. 103821 (2024)","DOI":"10.1016\/j.cose.2024.103821"},{"key":"30_CR36","first-page":"7103","volume":"35","author":"Y Zhou","year":"2022","unstructured":"Zhou, Y., Lei, T., Liu, H., et al.: Mixture-of-experts with expert choice routing. Adv. Neural. Inf. Process. Syst. 35, 7103\u20137114 (2022)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"30_CR37","doi-asserted-by":"crossref","unstructured":"Zhu, T., Yu, J., Xiong, C., et\u00a0al.: Aptshield: a stable, efficient and real-time apt detection system for linux hosts. IEEE Trans. Dependable Secure Comput. 1\u201318 (2023)","DOI":"10.1109\/TDSC.2023.3243667"}],"container-title":["Lecture Notes in Computer Science","Database Systems for Advanced Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-92-0375-8_30","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,11]],"date-time":"2026-05-11T11:01:47Z","timestamp":1778497307000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-92-0375-8_30"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"ISBN":["9789819203741","9789819203758"],"references-count":37,"URL":"https:\/\/doi.org\/10.1007\/978-981-92-0375-8_30","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"12 May 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"DASFAA","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Database Systems for Advanced Applications","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Jeju","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Korea (Republic of)","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2026","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"27 April 2026","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30 April 2026","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"31","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"dasfaa2026","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/dasfaa2026.github.io\/index.html","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}