{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,3]],"date-time":"2026-07-03T06:18:14Z","timestamp":1783059494548,"version":"3.54.6"},"reference-count":67,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100004826","name":"Natural Science Foundation of Beijing Municipality","doi-asserted-by":"publisher","award":["L251066"],"award-info":[{"award-number":["L251066"]}],"id":[{"id":"10.13039\/501100004826","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Journal of Computer and System Sciences"],"published-print":{"date-parts":[[2026,9]]},"DOI":"10.1016\/j.jcss.2026.103813","type":"journal-article","created":{"date-parts":[[2026,5,4]],"date-time":"2026-05-04T21:21:44Z","timestamp":1777929704000},"page":"103813","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["An APT detection scheme based on a hierarchical co-attention transformer"],"prefix":"10.1016","volume":"160","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-5731-2818","authenticated-orcid":false,"given":"Mahmoud","family":"Basi","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tao","family":"Shang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Cheng","family":"Yuhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"issue":"2","key":"10.1016\/j.jcss.2026.103813_br0010","doi-asserted-by":"crossref","first-page":"1851","DOI":"10.1109\/COMST.2019.2891891","article-title":"A survey on advanced persistent threats: techniques, solutions, challenges, and research opportunities","volume":"21","author":"Alshamrani","year":"2019","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"10.1016\/j.jcss.2026.103813_br0020","series-title":"Apt1: exposing one of China's cyber espionage units","year":"2013"},{"key":"10.1016\/j.jcss.2026.103813_br0030","series-title":"Communications and Multimedia Security (CMS 2014)","first-page":"63","article-title":"A study on advanced persistent threats","volume":"vol. 8735","author":"Chen","year":"2014"},{"key":"10.1016\/j.jcss.2026.103813_br0040","series-title":"6th International Conference on Information Warfare and Security (ICIW)","first-page":"113","article-title":"Intelligence-driven computer network defense informed by analysis of adversary campaigns and intrusion kill chains","author":"Hutchins","year":"2011"},{"key":"10.1016\/j.jcss.2026.103813_br0050","series-title":"Detecting Encrypted Command & Control Channels With Network Fingerprints","author":"Larinkoski","year":"2016"},{"key":"10.1016\/j.jcss.2026.103813_br0060","series-title":"What is Polymorphic Malware? Examples & Challenges","author":"SentinelOne","year":"2025"},{"key":"10.1016\/j.jcss.2026.103813_br0070","unstructured":"W. contributors, Intrusion detection system evasion techniques, Wikipedia, last updated 2025."},{"key":"10.1016\/j.jcss.2026.103813_br0080","unstructured":"R. Ajax, Comparison of traditional vs. ai-based intrusion detection and prevention systems, uploaded March 2025 via ResearchGate, 2025."},{"issue":"17","key":"10.1016\/j.jcss.2026.103813_br0090","doi-asserted-by":"crossref","first-page":"8482","DOI":"10.3390\/app12178482","article-title":"Malware detection issues, challenges, and future directions: a survey","volume":"12","author":"Aboaoja","year":"2022","journal-title":"Appl. Sci."},{"key":"10.1016\/j.jcss.2026.103813_br0100","doi-asserted-by":"crossref","DOI":"10.3390\/computers14070245","article-title":"Exploring the role of artificial intelligence in detecting advanced persistent threats","author":"Brandao","year":"2025","journal-title":"Computers"},{"issue":"7","key":"10.1016\/j.jcss.2026.103813_br0110","doi-asserted-by":"crossref","first-page":"1121","DOI":"10.1016\/j.jcss.2005.12.004","article-title":"An analytical model for loss estimation in network traffic analysis systems","volume":"72","author":"Ferro","year":"2006","journal-title":"J. Comput. Syst. Sci."},{"issue":"6","key":"10.1016\/j.jcss.2026.103813_br0120","doi-asserted-by":"crossref","first-page":"1703","DOI":"10.1016\/j.jcss.2011.10.018","article-title":"Improvement of assurance including security for wireless sensor networks using dispersed data transmission","volume":"78","author":"Kohno","year":"2012","journal-title":"J. Comput. Syst. Sci."},{"issue":"3","key":"10.1016\/j.jcss.2026.103813_br0130","doi-asserted-by":"crossref","first-page":"644","DOI":"10.1016\/j.jcss.2013.06.016","article-title":"Detection and mitigation of sinkhole attacks in wireless sensor networks","volume":"80","author":"Shafiei","year":"2014","journal-title":"J. Comput. Syst. Sci."},{"key":"10.1016\/j.jcss.2026.103813_br0140","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.jcss.2016.09.008","article-title":"Trace malicious source to guarantee cyber security for mass monitor critical infrastructure","volume":"98","author":"Liu","year":"2018","journal-title":"J. Comput. Syst. Sci."},{"key":"10.1016\/j.jcss.2026.103813_br0150","first-page":"70804","article-title":"Advanced persistent threat detection and countermeasures: a survey","volume":"9","author":"Zhao","year":"2021","journal-title":"IEEE Access"},{"key":"10.1016\/j.jcss.2026.103813_br0160","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2020.107247","article-title":"Building an efficient intrusion detection system based on feature selection and ensemble classifier","volume":"174","author":"Zhou","year":"2020","journal-title":"Comput. Netw."},{"key":"10.1016\/j.jcss.2026.103813_br0170","author":"Zhang"},{"key":"10.1016\/j.jcss.2026.103813_br0180","series-title":"Machine Learning in Cyber Security: Predicting and Preventing Advanced Persistent Threats (apts)","author":"Ali","year":"2024"},{"key":"10.1016\/j.jcss.2026.103813_br0190","article-title":"Ai-powered intrusion detection systems: challenges and opportunities","author":"Cate","year":"2025","journal-title":"ResearchGate"},{"key":"10.1016\/j.jcss.2026.103813_br0200","article-title":"Adversarial challenges in network intrusion detection systems","year":"2022","journal-title":"Inf. Sci."},{"key":"10.1016\/j.jcss.2026.103813_br0210","series-title":"2018 IEEE Security and Privacy Workshops (SPW)","first-page":"70","article-title":"Bringing a gan to a knife-fight: adapting malware communication to avoid detection","author":"Rigaki","year":"2018"},{"issue":"8","key":"10.1016\/j.jcss.2026.103813_br0220","doi-asserted-by":"crossref","first-page":"1735","DOI":"10.1162\/neco.1997.9.8.1735","article-title":"Long short-term memory","volume":"9","author":"Hochreiter","year":"1997","journal-title":"Neural Comput."},{"key":"10.1016\/j.jcss.2026.103813_br0230","series-title":"Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition","first-page":"2818","article-title":"Rethinking the inception architecture for computer vision","author":"Szegedy","year":"2016"},{"key":"10.1016\/j.jcss.2026.103813_br0240","first-page":"5998","article-title":"Attention is all you need","volume":"30","author":"Vaswani","year":"2017","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.jcss.2026.103813_br0250","series-title":"Proceedings of the 36th International Conference on Machine Learning, vol. 97","first-page":"1544","article-title":"Generating long sequences with sparse transformers","author":"Child","year":"2019"},{"key":"10.1016\/j.jcss.2026.103813_br0260","first-page":"2199","article-title":"Sequential neural models with stochastic layers","volume":"29","author":"Fraccaro","year":"2016","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.jcss.2026.103813_br0270","series-title":"Proceedings of the 27th International Conference on Neural Information Processing Systems (NeurIPS)","first-page":"3835","article-title":"An empirical evaluation of generic convolutional and recurrent networks for sequence modeling","author":"Bai","year":"2018"},{"key":"10.1016\/j.jcss.2026.103813_br0280","series-title":"Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition","article-title":"Mobilenets: efficient convolutional neural networks for mobile vision applications","author":"Howard","year":"2017"},{"key":"10.1016\/j.jcss.2026.103813_br0290","series-title":"Proceedings of the 2021 Conference of the North American Chapter of the Association for Computational Linguistics","first-page":"1","article-title":"Roformer: transformer with rotary position embedding","author":"Su","year":"2021"},{"key":"10.1016\/j.jcss.2026.103813_br0300","author":"Beltagy"},{"key":"10.1016\/j.jcss.2026.103813_br0310","series-title":"International Conference on Learning Representations (ICLR)","article-title":"Rethinking attention with performers","author":"Choromanski","year":"2021"},{"key":"10.1016\/j.jcss.2026.103813_br0320","series-title":"Proceedings of the 2023 International Conference on Big Data Security","first-page":"210","article-title":"Identity-based dynamic data auditing for big data storage","author":"Shang","year":"2023"},{"key":"10.1016\/j.jcss.2026.103813_br0330","series-title":"2024 IEEE Conference on Communications and Network Security","first-page":"101","article-title":"A novel approach for apt attack detection based on feature intelligent extraction and representation learning","author":"Cho","year":"2024"},{"issue":"2","key":"10.1016\/j.jcss.2026.103813_br0340","first-page":"45","article-title":"An improved predictive model for early detection of advanced persistent threat attacks on high value networks","volume":"12","author":"Feng Dorsky","year":"2024","journal-title":"J. Cybersecur. Res."},{"key":"10.1016\/j.jcss.2026.103813_br0350","series-title":"Proceedings of the 2025 USENIX Security Symposium","first-page":"411","article-title":"Autumn: an unsupervised apt detection via detailed process level analysis","author":"Wang","year":"2025"},{"issue":"1","key":"10.1016\/j.jcss.2026.103813_br0360","first-page":"125","article-title":"Shield: Apt detection and intelligent explanation using large language models","volume":"20","author":"Gandhi","year":"2025","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"issue":"3","key":"10.1016\/j.jcss.2026.103813_br0370","first-page":"2000","article-title":"Llm-driven apt detection for 6g wireless networks: a systematic review and taxonomy","volume":"27","author":"Golec","year":"2025","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"10.1016\/j.jcss.2026.103813_br0380","series-title":"IEEE INFOCOM 2025-IEEE Conference on Computer Communications","first-page":"1","article-title":"A principled approach for detecting apts in massive networks via multi-stage causal analytics","author":"Gui","year":"2025"},{"key":"10.1016\/j.jcss.2026.103813_br0390","author":"Han"},{"key":"10.1016\/j.jcss.2026.103813_br0400","author":"Yan"},{"key":"10.1016\/j.jcss.2026.103813_br0410","series-title":"2023 International Joint Conference on Neural Networks","first-page":"990","article-title":"Detecting apt using machine learning: comparative performance analysis with proposed model","author":"Ren","year":"2023"},{"key":"10.1016\/j.jcss.2026.103813_br0420","series-title":"Proceedings of the 2025 IEEE International Conference on Data Mining","first-page":"350","article-title":"Research on apt group classification method based on graph attention networks","author":"Li","year":"2025"},{"key":"10.1016\/j.jcss.2026.103813_br0430","series-title":"2024 IEEE International Conference on Advanced Computing (IACC)","first-page":"58","article-title":"A novel approach for apt attack detection based on an advanced computing framework","author":"Cho","year":"2024"},{"issue":"2","key":"10.1016\/j.jcss.2026.103813_br0440","first-page":"7:1","article-title":"Pdcleaner: a multi-view collaborative data compression method for provenance graph-based apt detection systems","volume":"28","author":"Jin","year":"2025","journal-title":"ACM Trans. Priv. Secur."},{"key":"10.1016\/j.jcss.2026.103813_br0450","series-title":"Proceedings of the 2025 IEEE Symposium on Cybersecurity","first-page":"150","article-title":"Modeling of apt actors targeting healthcare sector","author":"Zhang","year":"2025"},{"key":"10.1016\/j.jcss.2026.103813_br0460","series-title":"2025 IEEE\/IFIP International Conference on Dependable Systems and Networks","first-page":"411","article-title":"Atdetector: a thorough pipeline to detect diverse apt behaviors","author":"Chen","year":"2025"},{"key":"10.1016\/j.jcss.2026.103813_br0470","series-title":"Proceedings of the 2025 ACM Conference on Computer and Communications Security","first-page":"870","article-title":"Tflag: towards practical apt detection via deviation-aware learning on temporal provenance graphs","author":"Jiang","year":"2025"},{"key":"10.1016\/j.jcss.2026.103813_br0480","series-title":"2025 IEEE International Conference on Big Data","first-page":"230","article-title":"Provenance-based apt campaigns detection via masked graph learning","author":"Ren","year":"2025"},{"key":"10.1016\/j.jcss.2026.103813_br0490","series-title":"2024 IEEE 14th International Conference on Electronics Information and Emergency Communication (ICEIEC)","first-page":"61","article-title":"Apt detection based on rsdn framework","author":"Basi","year":"2024"},{"issue":"4","key":"10.1016\/j.jcss.2026.103813_br0500","first-page":"200","article-title":"Slf-adm: securing Linux frontiers\u2014advanced persistent threat detection using machine learning","volume":"15","author":"Karim","year":"2025","journal-title":"IEEE Trans. Netw. Secur."},{"issue":"1","key":"10.1016\/j.jcss.2026.103813_br0510","first-page":"33","article-title":"A lightweight ids for early apt detection using a novel feature selection method","volume":"25","author":"Shaker","year":"2024","journal-title":"Int. J. Netw. Secur."},{"key":"10.1016\/j.jcss.2026.103813_br0520","series-title":"2025 IEEE Symposium on Deep Learning Applications","first-page":"310","article-title":"Advanced persistent threat detection using optimized and hybrid deep learning","author":"Almazmomi","year":"2025"},{"key":"10.1016\/j.jcss.2026.103813_br0530","series-title":"2024 IEEE 23rd International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom)","first-page":"2342","article-title":"Cnn-koa-bigru: a high-accuracy apt detection model based on deep learning networks","author":"Zhang","year":"2024"},{"issue":"3","key":"10.1016\/j.jcss.2026.103813_br0540","first-page":"382","article-title":"Transformers in cybersecurity: advancing threat detection and response through machine learning architectures","volume":"3","author":"Santoso","year":"2024","journal-title":"J. Technol. Inf. Eng."},{"key":"10.1016\/j.jcss.2026.103813_br0550","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR)","first-page":"6281","article-title":"Deep modular co-attention networks for visual question answering","author":"Yu","year":"2019"},{"key":"10.1016\/j.jcss.2026.103813_br0560","series-title":"2024 ACM Conference on Data and Application Security","first-page":"120","article-title":"Rt-apt: a real-time apt anomaly detection method for large-scale provenance graphs","author":"Weng","year":"2024"},{"key":"10.1016\/j.jcss.2026.103813_br0570","series-title":"2025 IEEE Power & Energy Society General Meeting","first-page":"180","article-title":"Apt attack detection in digital substations leveraging the att&ck model","author":"Lee","year":"2025"},{"key":"10.1016\/j.jcss.2026.103813_br0580","article-title":"Hybrid multi-modal detection framework for advanced persistent threats in corporate environments","volume":"112","author":"Shakil","year":"2025","journal-title":"Comput. Secur."},{"key":"10.1016\/j.jcss.2026.103813_br0590","article-title":"Aptsniffer: detecting apt attack traffic using retrieval-augmented large language models","volume":"170","author":"Xu","year":"2025","journal-title":"J. Netw. Comput. Appl."},{"key":"10.1016\/j.jcss.2026.103813_br0600","series-title":"Deployable Machine Learning for Security Defense \u2013 1st Int. Workshop, MLHat 2020, Proceedings","first-page":"138","article-title":"DAPT 2020: constructing a benchmark dataset for advanced persistent threats","volume":"vol. 138","author":"Myneni","year":"2020"},{"issue":"1\u20133","key":"10.1016\/j.jcss.2026.103813_br0610","first-page":"18","article-title":"The evaluation of network anomaly detection systems: statistical analysis of the unsw-nb15 data set and the comparison with the kdd99 data set","volume":"25","author":"Moustafa","year":"2016","journal-title":"Inf. Secur. J."},{"key":"10.1016\/j.jcss.2026.103813_br0620","series-title":"Proceedings of the 4th International Conference on Information Systems Security and Privacy (ICISSP)","first-page":"108","article-title":"Toward generating a new intrusion detection dataset and intrusion traffic characterization","author":"Sharafaldin","year":"2018"},{"key":"10.1016\/j.jcss.2026.103813_br0630","series-title":"Proceedings of the 2024 IEEE Symposium on Security and Privacy","first-page":"123","article-title":"xlstm: extended long short-term memory for apt detection","author":"Jang","year":"2024"},{"key":"10.1016\/j.jcss.2026.103813_br0640","series-title":"2024 International Conference on Neural Information Processing","first-page":"445","article-title":"Cnn-koa-bigru: a high accuracy apt detection model based on deep learning networks","author":"Zhang","year":"2024"},{"issue":"4","key":"10.1016\/j.jcss.2026.103813_br0650","doi-asserted-by":"crossref","first-page":"947","DOI":"10.1007\/s10207-023-00676-0","article-title":"From zero-shot machine learning to zero-day attack detection","volume":"22","author":"Sarhan","year":"2023","journal-title":"Int. J. Inf. Secur."},{"issue":"8","key":"10.1016\/j.jcss.2026.103813_br0660","doi-asserted-by":"crossref","first-page":"1735","DOI":"10.1162\/neco.1997.9.8.1735","article-title":"Long short-term memory","volume":"9","author":"Hochreiter","year":"1997","journal-title":"Neural Comput."},{"key":"10.1016\/j.jcss.2026.103813_br0670","author":"Beck"}],"container-title":["Journal of Computer and System Sciences"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0022000026000590?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0022000026000590?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,7,3]],"date-time":"2026-07-03T05:30:05Z","timestamp":1783056605000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0022000026000590"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,9]]},"references-count":67,"alternative-id":["S0022000026000590"],"URL":"https:\/\/doi.org\/10.1016\/j.jcss.2026.103813","relation":{},"ISSN":["0022-0000"],"issn-type":[{"value":"0022-0000","type":"print"}],"subject":[],"published":{"date-parts":[[2026,9]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"An APT detection scheme based on a hierarchical co-attention transformer","name":"articletitle","label":"Article Title"},{"value":"Journal of Computer and System Sciences","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.jcss.2026.103813","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier Inc. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"103813"}}