{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T19:48:23Z","timestamp":1784404103894,"version":"3.55.0"},"publisher-location":"Singapore","reference-count":31,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819535422","type":"print"},{"value":"9789819535439","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,10,20]],"date-time":"2025-10-20T00:00:00Z","timestamp":1760918400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,10,20]],"date-time":"2025-10-20T00:00:00Z","timestamp":1760918400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-981-95-3543-9_29","type":"book-chapter","created":{"date-parts":[[2025,10,19]],"date-time":"2025-10-19T11:03:21Z","timestamp":1760871801000},"page":"531-549","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Provenance-Based Intrusion Detection via\u00a0Multi-scale Graph Representation Learning"],"prefix":"10.1007","author":[{"given":"Xuebo","family":"Qiu","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mingqi","family":"Lv","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tieming","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tiantian","family":"Zhu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Qijie","family":"Song","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,10,20]]},"reference":[{"key":"29_CR1","unstructured":"Transparent computing engagement 3 data release (2017). https:\/\/github.com\/darpa-i2o\/Transparent-Computing\/blob\/master\/README-E3.md"},{"key":"29_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"240","DOI":"10.1007\/978-3-030-88418-5_12","volume-title":"Computer Security \u2013 ESORICS 2021","author":"ME Ahmed","year":"2021","unstructured":"Ahmed, M.E., Kim, H., Camtepe, S., Nepal, S.: Peeler: profiling Kernel-level events to detect ransomware. In: Bertino, E., Shulman, H., Waidner, M. (eds.) ESORICS 2021. LNCS, vol. 12972, pp. 240\u2013260. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-88418-5_12"},{"key":"29_CR3","unstructured":"Alsaheel, A., et al.: ATLAS: a sequence-based learning approach for attack investigation. In: 30th USENIX Security Symposium (USENIX Security 21), pp. 3005\u20133022 (2021)"},{"key":"29_CR4","doi-asserted-by":"publisher","unstructured":"Altinisik, E., Deniz, F., Sencar, H.T.: ProvG-searcher: a graph representation learning approach for efficient provenance graph search. In: Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security, pp. 2247\u20132261, November 2023. https:\/\/doi.org\/10.1145\/3576915.3623187","DOI":"10.1145\/3576915.3623187"},{"key":"29_CR5","doi-asserted-by":"crossref","unstructured":"Aly, A., Iqbal, S., Youssef, A., Mansour, E.: MEGR-APT: a memory-efficient apt hunting system based on attack representation learning. IEEE Trans. Inf. Forensics Secur. (2024)","DOI":"10.1109\/TIFS.2024.3396390"},{"key":"29_CR6","unstructured":"National Cyber Security Centre: MOVEit vulnerability and data extortion incident (2023). https:\/\/www.ncsc.gov.uk\/information\/moveit-vulnerability"},{"key":"29_CR7","doi-asserted-by":"publisher","unstructured":"Chen, T., et al.: APT-KGL: an intelligent APT detection system based on threat knowledge and heterogeneous provenance graph learning. IEEE Trans. Dependable Secure Comput., 1\u201315 (2022). https:\/\/doi.org\/10.1109\/TDSC.2022.3229472","DOI":"10.1109\/TDSC.2022.3229472"},{"key":"29_CR8","unstructured":"Chen, T., Song, Q., Qiu, X., Zhu, T., Zhu, Z., Lv, M.: Kellect: a Kernel-based efficient and lossless event log collector. arXiv preprint arXiv:2207.11530 (2022)"},{"key":"29_CR9","doi-asserted-by":"crossref","unstructured":"Cheng, Z., et al.: KAIROS: practical intrusion detection and investigation using whole-system provenance. arXiv preprint arXiv:2308.05034 (2023)","DOI":"10.1109\/SP54263.2024.00005"},{"key":"29_CR10","doi-asserted-by":"crossref","unstructured":"Duan, J., et al.: Graph anomaly detection via multi-scale contrastive learning networks with augmented view. In: Proceedings of the AAAI Conference on Artificial Intelligence, vol.\u00a037, pp. 7459\u20137467 (2023)","DOI":"10.1609\/aaai.v37i6.25907"},{"key":"29_CR11","doi-asserted-by":"crossref","unstructured":"Hassan, W.U., Bates, A., Marino, D.: Tactical provenance analysis for endpoint detection and response systems. In: 2020 IEEE Symposium on Security and Privacy (SP), pp. 1172\u20131189. IEEE (2020)","DOI":"10.1109\/SP40000.2020.00096"},{"key":"29_CR12","unstructured":"Hossain, M.N., et al.: SLEUTH: real-time attack scenario reconstruction from COTS audit data. In: 26th USENIX Security Symposium (USENIX Security 17), pp. 487\u2013504 (2017)"},{"key":"29_CR13","doi-asserted-by":"crossref","unstructured":"Hou, Z., et al.: GraphMAE: self-supervised masked graph autoencoders. In: Proceedings of the 28th ACM SIGKDD Conference on Knowledge Discovery and Data Mining, pp. 594\u2013604 (2022)","DOI":"10.1145\/3534678.3539321"},{"key":"29_CR14","doi-asserted-by":"crossref","unstructured":"Inam, M.A., et al.: SoK: history is a vast early warning system: auditing the provenance of system intrusions. In: 2023 IEEE Symposium on Security and Privacy (SP), pp. 2620\u20132638. IEEE (2023)","DOI":"10.1109\/SP46215.2023.10179405"},{"key":"29_CR15","unstructured":"Jia, Z., Xiong, Y., Nan, Y., Zhang, Y., Zhao, J., Wen, M.: Magic: detecting advanced persistent threats via masked graph representation learning (2023)"},{"key":"29_CR16","doi-asserted-by":"crossref","unstructured":"Kapoor, M., Melton, J., Ridenhour, M., Krishnan, S., Moyer, T.: PROV-GEM: automated provenance analysis framework using graph embeddings. In: 2021 20th IEEE International Conference on Machine Learning and Applications (ICMLA), pp. 1720\u20131727. IEEE (2021)","DOI":"10.1109\/ICMLA52953.2021.00273"},{"issue":"6","key":"29_CR17","first-page":"5879","volume":"35","author":"Y Liu","year":"2022","unstructured":"Liu, Y., et al.: Graph self-supervised learning: a survey. IEEE Trans. Knowl. Data Eng. 35(6), 5879\u20135900 (2022)","journal-title":"IEEE Trans. Knowl. Data Eng."},{"issue":"6","key":"29_CR18","doi-asserted-by":"publisher","first-page":"2378","DOI":"10.1109\/TNNLS.2021.3068344","volume":"33","author":"Y Liu","year":"2021","unstructured":"Liu, Y., Li, Z., Pan, S., Gong, C., Zhou, C., Karypis, G.: Anomaly detection on attributed networks via contrastive self-supervised learning. IEEE Trans. Neural Netw. Learn. Syst. 33(6), 2378\u20132392 (2021)","journal-title":"IEEE Trans. Neural Netw. Learn. Syst."},{"key":"29_CR19","doi-asserted-by":"publisher","unstructured":"Milajerdi, S.M., Gjomemo, R., Eshete, B., Sekar, R., Venkatakrishnan, V.: HOLMES: real-time APT detection through correlation of suspicious information flows. In: 2019 IEEE Symposium on Security and Privacy (SP), pp. 1137\u20131152, May 2019. https:\/\/doi.org\/10.1109\/SP.2019.00026","DOI":"10.1109\/SP.2019.00026"},{"key":"29_CR20","unstructured":"Rehman, M.U., Ahmadi, H., Hassan, W.U.: FLASH: a comprehensive approach to intrusion detection via provenance graph representation learning. In: 2024 IEEE Symposium on Security and Privacy (SP), p. 139. IEEE Computer Society (2024)"},{"key":"29_CR21","unstructured":"Veli\u010dkovi\u0107, P., Cucurull, G., Casanova, A., Romero, A., Lio, P., Bengio, Y.: Graph attention networks. arXiv preprint arXiv:1710.10903 (2017)"},{"key":"29_CR22","unstructured":"Velickovic, P., Fedus, W., Hamilton, W.L., Li\u00f2, P., Bengio, Y., Hjelm, R.D.: Deep graph infomax. In: ICLR (Poster), vol. 2, no. 3, p. 4 (2019)"},{"key":"29_CR23","doi-asserted-by":"publisher","first-page":"3972","DOI":"10.1109\/TIFS.2022.3208815","volume":"17","author":"S Wang","year":"2022","unstructured":"Wang, S., et al.: THREATRACE: detecting and tracing host-based threats in node level through provenance graph learning. IEEE Trans. Inf. Forensics Secur. 17, 3972\u20133987 (2022). https:\/\/doi.org\/10.1109\/TIFS.2022.3208815","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"issue":"1","key":"29_CR24","doi-asserted-by":"publisher","first-page":"551","DOI":"10.1109\/TDSC.2020.2971484","volume":"19","author":"C Xiong","year":"2022","unstructured":"Xiong, C., et al.: CONAN: a practical real-time apt detection system with high accuracy and efficiency. IEEE Trans. Dependable Secure Comput. 19(1), 551\u2013565 (2022). https:\/\/doi.org\/10.1109\/TDSC.2020.2971484","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"29_CR25","unstructured":"Yang, F., Xu, J., Xiong, C., Li, Z., Zhang, K.: PROGRAPHER: an anomaly detection system based on provenance graph embedding. In: 32nd USENIX Security Symposium (USENIX Security 23), pp. 4355\u20134372 (2023)"},{"key":"29_CR26","unstructured":"You, Y., Chen, T., Sui, Y., Chen, T., Wang, Z., Shen, Y.: Graph contrastive learning with augmentations. In: Advances in Neural Information Processing Systems, vol. 33, pp. 5812\u20135823 (2020)"},{"key":"29_CR27","doi-asserted-by":"crossref","unstructured":"Yu, S., Huang, H., Dao, M.N., Xia, F.: Graph augmentation learning. In: Companion Proceedings of the Web Conference 2022, pp. 1063\u20131072 (2022)","DOI":"10.1145\/3487553.3524718"},{"key":"29_CR28","doi-asserted-by":"crossref","unstructured":"Zengy, J., et al.: SHADEWATCHER: recommendation-guided cyber threat analysis using system audit records. In: 2022 IEEE Symposium on Security and Privacy (SP), pp. 489\u2013506. IEEE (2022)","DOI":"10.1109\/SP46214.2022.9833669"},{"key":"29_CR29","doi-asserted-by":"crossref","unstructured":"Zhao, T., Liu, Y., Neves, L., Woodford, O., Jiang, M., Shah, N.: Data augmentation for graph neural networks. In: Proceedings of the AAAI Conference on Artificial Intelligence, vol.\u00a035, pp. 11015\u201311023 (2021)","DOI":"10.1609\/aaai.v35i12.17315"},{"key":"29_CR30","doi-asserted-by":"publisher","unstructured":"Zhu, T., et al.: APTSHIELD: a stable, efficient and real-time apt detection system for Linux hosts. IEEE Trans. Dependable Secure Comput., 1\u201318 (2023). https:\/\/doi.org\/10.1109\/TDSC.2023.3243667","DOI":"10.1109\/TDSC.2023.3243667"},{"key":"29_CR31","doi-asserted-by":"crossref","unstructured":"Zhu, Y., Xu, Y., Yu, F., Liu, Q., Wu, S., Wang, L.: Graph contrastive learning with adaptive augmentation. In: Proceedings of the Web Conference 2021, pp. 2069\u20132080 (2021)","DOI":"10.1145\/3442381.3449802"}],"container-title":["Lecture Notes in Computer Science","Information and Communications Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-95-3543-9_29","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,20]],"date-time":"2025-10-20T22:03:44Z","timestamp":1760997824000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-95-3543-9_29"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,20]]},"ISBN":["9789819535422","9789819535439"],"references-count":31,"URL":"https:\/\/doi.org\/10.1007\/978-981-95-3543-9_29","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,10,20]]},"assertion":[{"value":"20 October 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ICICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Information and Communications Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Nanjing","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"China","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 October 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"31 October 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"27","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"icics2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.icics2025.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}