{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,8]],"date-time":"2026-07-08T12:22:41Z","timestamp":1783513361788,"version":"3.55.0"},"reference-count":37,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100002855","name":"MOST","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100002855","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012166","name":"National Key Research and Development Program of China","doi-asserted-by":"publisher","award":["2023YFB2704900"],"award-info":[{"award-number":["2023YFB2704900"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Computer Networks"],"published-print":{"date-parts":[[2026,8]]},"DOI":"10.1016\/j.comnet.2026.112437","type":"journal-article","created":{"date-parts":[[2026,5,29]],"date-time":"2026-05-29T15:59:57Z","timestamp":1780070397000},"page":"112437","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["ApexSentinel: Detecting and Explaining Advanced Persistent Threats with Large Language Models"],"prefix":"10.1016","volume":"286","author":[{"given":"Jiayi","family":"Zhang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5898-7317","authenticated-orcid":false,"given":"Futai","family":"Zou","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-3340-2914","authenticated-orcid":false,"given":"Canyang","family":"Wu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Heming","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.comnet.2026.112437_b1","doi-asserted-by":"crossref","unstructured":"S.M. Milajerdi, B. Eshete, R. Gjomemo, V. Venkatakrishnan, Poirot: Aligning attack behavior with kernel audit records for cyber threat hunting, in: Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, 2019, pp. 1795\u20131812.","DOI":"10.1145\/3319535.3363217"},{"key":"10.1016\/j.comnet.2026.112437_b2","series-title":"2019 IEEE Symposium on Security and Privacy","first-page":"1137","article-title":"Holmes: real-time apt detection through correlation of suspicious information flows","author":"Milajerdi","year":"2019"},{"key":"10.1016\/j.comnet.2026.112437_b3","series-title":"Unicorn: Runtime provenance-based detector for advanced persistent threats","author":"Han","year":"2020"},{"key":"10.1016\/j.comnet.2026.112437_b4","series-title":"NDSS","article-title":"You are what you do: Hunting stealthy malware via data provenance analysis","author":"Wang","year":"2020"},{"key":"10.1016\/j.comnet.2026.112437_b5","series-title":"2020 IEEE Symposium on Security and Privacy","first-page":"1172","article-title":"Tactical provenance analysis for endpoint detection and response systems","author":"Hassan","year":"2020"},{"key":"10.1016\/j.comnet.2026.112437_b6","series-title":"2020 IEEE Symposium on Security and Privacy","first-page":"1139","article-title":"Combating dependence explosion in forensic analysis using alternative tag propagation semantics","author":"Hossain","year":"2020"},{"key":"10.1016\/j.comnet.2026.112437_b7","doi-asserted-by":"crossref","unstructured":"W.U. Hassan, S. Guo, D. Li, Z. Chen, K. Jee, Z. Li, A. Bates, Nodoze: Combatting threat alert fatigue with automated provenance triage, in: Network and Distributed Systems Security Symposium, 2019.","DOI":"10.14722\/ndss.2019.23349"},{"key":"10.1016\/j.comnet.2026.112437_b8","doi-asserted-by":"crossref","unstructured":"K. Pei, Z. Gu, B. Saltaformaggio, S. Ma, F. Wang, Z. Zhang, L. Si, X. Zhang, D. Xu, Hercule: Attack story reconstruction via community discovery on correlated log graph, in: Proceedings of the 32Nd Annual Conference on Computer Security Applications, 2016, pp. 583\u2013595.","DOI":"10.1145\/2991079.2991122"},{"key":"10.1016\/j.comnet.2026.112437_b9","doi-asserted-by":"crossref","unstructured":"F. Liu, Y. Wen, D. Zhang, X. Jiang, X. Xing, D. Meng, Log2vec: A heterogeneous graph embedding based approach for detecting cyber threats within enterprise, in: Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, 2019, pp. 1777\u20131794.","DOI":"10.1145\/3319535.3363224"},{"key":"10.1016\/j.comnet.2026.112437_b10","unstructured":"A. Alsaheel, Y. Nan, S. Ma, L. Yu, G. Walkup, Z.B. Celik, X. Zhang, D. Xu, ATLAS: A sequence-based learning approach for attack investigation, in: 30th USENIX Security Symposium, USENIX Security 21, 2021, pp. 3005\u20133022."},{"key":"10.1016\/j.comnet.2026.112437_b11","doi-asserted-by":"crossref","first-page":"3972","DOI":"10.1109\/TIFS.2022.3208815","article-title":"Threatrace: Detecting and tracing host-based threats in node level through provenance graph learning","volume":"17","author":"Wang","year":"2022","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.comnet.2026.112437_b12","series-title":"2022 IEEE Symposium on Security and Privacy","first-page":"489","article-title":"Shadewatcher: Recommendation-guided cyber threat analysis using system audit records","author":"Zengy","year":"2022"},{"key":"10.1016\/j.comnet.2026.112437_b13","unstructured":"Z. Jia, Y. Xiong, Y. Nan, Y. Zhang, J. Zhao, M. Wen, MAGIC: Detecting advanced persistent threats via masked graph representation learning, in: 33rd USENIX Security Symposium (USENIX Security 24), 2024, pp. 5197\u20135214."},{"key":"10.1016\/j.comnet.2026.112437_b14","unstructured":"DARPA I2O, DARPA Transparent Computing Program Engagement 3 Data Release. [Online]. Available https:\/\/github.com\/darpa-i2o\/."},{"key":"10.1016\/j.comnet.2026.112437_b15","doi-asserted-by":"crossref","unstructured":"K. He, X. Chen, S. Xie, Y. Li, P. Doll\u00e1r, R. Girshick, Masked autoencoders are scalable vision learners, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2022, pp. 16000\u201316009.","DOI":"10.1109\/CVPR52688.2022.01553"},{"issue":"10","key":"10.1016\/j.comnet.2026.112437_b16","doi-asserted-by":"crossref","first-page":"P10008","DOI":"10.1088\/1742-5468\/2008\/10\/P10008","article-title":"Fast unfolding of communities in large networks","volume":"2008","author":"Blondel","year":"2008","journal-title":"J. Stat. Mech. Theory Exp."},{"key":"10.1016\/j.comnet.2026.112437_b17","series-title":"Efficient estimation of word representations in vector space","author":"Mikolov","year":"2013"},{"key":"10.1016\/j.comnet.2026.112437_b18","series-title":"An image is worth 16x16 words: Transformers for image recognition at scale","author":"Dosovitskiy","year":"2020"},{"key":"10.1016\/j.comnet.2026.112437_b19","doi-asserted-by":"crossref","unstructured":"Y. Jiang, J. Liang, F. Ma, Y. Chen, C. Zhou, Y. Shen, Z. Wu, J. Fu, M. Wang, S. Li, et al., When fuzzing meets llms: Challenges and opportunities, in: Companion Proceedings of the 32nd ACM International Conference on the Foundations of Software Engineering, 2024, pp. 492\u2013496.","DOI":"10.1145\/3663529.3663784"},{"key":"10.1016\/j.comnet.2026.112437_b20","series-title":"Hackphyr: A local fine-tuned LLM agent for network security environments","author":"Rigaki","year":"2024"},{"key":"10.1016\/j.comnet.2026.112437_b21","doi-asserted-by":"crossref","unstructured":"T. Wang, X. Xie, L. Zhang, C. Wang, L. Zhang, Y. Cui, Shieldgpt: An llm-based framework for ddos mitigation, in: Proceedings of the 8th Asia-Pacific Workshop on Networking, 2024, pp. 108\u2013114.","DOI":"10.1145\/3663408.3663424"},{"key":"10.1016\/j.comnet.2026.112437_b22","series-title":"Beyond yes and no: Improving zero-shot llm rankers via scoring fine-grained relevance labels","author":"Zhuang","year":"2023"},{"key":"10.1016\/j.comnet.2026.112437_b23","doi-asserted-by":"crossref","unstructured":"S. Freitas, J. Kalajdjieski, A. Gharib, R. McCann, AI-driven guided response for security operation centers with Microsoft Copilot for Security, in: Companion Proceedings of the ACM on Web Conference 2025, 2025, pp. 191\u2013200.","DOI":"10.1145\/3701716.3715209"},{"key":"10.1016\/j.comnet.2026.112437_b24","series-title":"Qwen2.5: A party of foundation models","author":"Qwen Team","year":"2024"},{"key":"10.1016\/j.comnet.2026.112437_b25","article-title":"PyTorch: An imperative style, high-performance deep learning library","volume":"vol. 32","author":"Paszke","year":"2019"},{"key":"10.1016\/j.comnet.2026.112437_b26","series-title":"Exploring Network Structure, Dynamics, and Function Using Networkx","author":"Hagberg","year":"2008"},{"key":"10.1016\/j.comnet.2026.112437_b27","series-title":"Qwen3 technical report","author":"Yang","year":"2025"},{"key":"10.1016\/j.comnet.2026.112437_b28","series-title":"Gpt-4o system card","author":"Hurst","year":"2024"},{"issue":"6","key":"10.1016\/j.comnet.2026.112437_b29","doi-asserted-by":"crossref","DOI":"10.1007\/s11704-024-40231-1","article-title":"A survey on large language model based autonomous agents","volume":"18","author":"Wang","year":"2024","journal-title":"Front. Comput. Sci."},{"key":"10.1016\/j.comnet.2026.112437_b30","article-title":"Large model based agents: State-of-the-art, cooperation paradigms, security and privacy, and future trends","author":"Wang","year":"2025","journal-title":"IEEE Commun. Surv. Tutorials"},{"key":"10.1016\/j.comnet.2026.112437_b31","series-title":"2021 International Joint Conference on Neural Networks","first-page":"1","article-title":"LogBERT: Log anomaly detection via BERT","author":"Guo","year":"2021"},{"key":"10.1016\/j.comnet.2026.112437_b32","series-title":"32nd USENIX Security Symposium","first-page":"373","article-title":"AIRTAG: Towards automated attack investigation by unsupervised learning with log texts","author":"Ding","year":"2023"},{"issue":"24","key":"10.1016\/j.comnet.2026.112437_b33","doi-asserted-by":"crossref","DOI":"10.3390\/s23249881","article-title":"ConLBS: An attack investigation approach using contrastive learning with behavior sequence","volume":"23","author":"Li","year":"2023","journal-title":"Sensors"},{"key":"10.1016\/j.comnet.2026.112437_b34","unstructured":"B. Zhang, Y. Gao, C. Yu, B. Kuang, Z. Zhang, H. Kim, A. Fu, TAPAS: An Efficient Online APT Detection with Task-guided Process Provenance Graph Segmentation and Analysis, in: 34th USENIX Security Symposium, USENIX Security 25, 2025, pp. 607\u2013624."},{"key":"10.1016\/j.comnet.2026.112437_b35","doi-asserted-by":"crossref","unstructured":"H. Nazari, A. Yazdinejad, A. Dehghantanha, F. Zarrinkalam, G. Srivastava, P3GNN: A privacy-preserving provenance graph-based model for autonomous APT detection in software defined networking, in: Proceedings of the Workshop on Autonomous Cybersecurity, 2023, pp. 34\u201344.","DOI":"10.1145\/3689933.3690836"},{"key":"10.1016\/j.comnet.2026.112437_b36","series-title":"2024 IEEE Symposium on Security and Privacy","first-page":"3533","article-title":"Kairos: Practical intrusion detection and investigation using whole-system provenance","author":"Cheng","year":"2024"},{"issue":"6","key":"10.1016\/j.comnet.2026.112437_b37","doi-asserted-by":"crossref","first-page":"324","DOI":"10.1109\/MNET.2024.3389734","article-title":"Combating advanced persistent threats: Challenges and solutions","volume":"38","author":"Wang","year":"2024","journal-title":"IEEE Netw."}],"container-title":["Computer Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1389128626004494?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1389128626004494?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,7,8]],"date-time":"2026-07-08T11:56:03Z","timestamp":1783511763000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S1389128626004494"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,8]]},"references-count":37,"alternative-id":["S1389128626004494"],"URL":"https:\/\/doi.org\/10.1016\/j.comnet.2026.112437","relation":{},"ISSN":["1389-1286"],"issn-type":[{"value":"1389-1286","type":"print"}],"subject":[],"published":{"date-parts":[[2026,8]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"ApexSentinel: Detecting and Explaining Advanced Persistent Threats with Large Language Models","name":"articletitle","label":"Article Title"},{"value":"Computer Networks","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.comnet.2026.112437","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier B.V. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"112437"}}