{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,9]],"date-time":"2026-06-09T00:00:47Z","timestamp":1780963247463,"version":"3.54.1"},"reference-count":74,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100004731","name":"Natural Science Foundation of Zhejiang Province","doi-asserted-by":"publisher","award":["LZ23F020011"],"award-info":[{"award-number":["LZ23F020011"]}],"id":[{"id":"10.13039\/501100004731","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62372410"],"award-info":[{"award-number":["62372410"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U22B2028"],"award-info":[{"award-number":["U22B2028"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Journal of Information Security and Applications"],"published-print":{"date-parts":[[2026,7]]},"DOI":"10.1016\/j.jisa.2026.104457","type":"journal-article","created":{"date-parts":[[2026,4,16]],"date-time":"2026-04-16T15:51:50Z","timestamp":1776354710000},"page":"104457","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["Provenance-based advanced persistent threat detection via holistic contrastive learning with heuristic augmentation"],"prefix":"10.1016","volume":"100","author":[{"ORCID":"https:\/\/orcid.org\/0009-0003-3140-9917","authenticated-orcid":false,"given":"Xuebo","family":"Qiu","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4810-7491","authenticated-orcid":false,"given":"Mingqi","family":"Lv","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tiantian","family":"Zhu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Qijie","family":"Song","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tieming","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.jisa.2026.104457_bib0001","article-title":"Two statistical traffic features for certain APT group identification","volume":"67","author":"Liu","year":"2022","journal-title":"J Inf Secur Appl"},{"key":"10.1016\/j.jisa.2026.104457_bib0002","unstructured":"Seals T.. Move over, APTs: cybercriminals now target critical infrastructure too. 2024. https:\/\/www.darkreading.com\/ics-ot-security\/common-cybercriminals-begin-critical-infrastructure-targeting."},{"key":"10.1016\/j.jisa.2026.104457_bib0003","doi-asserted-by":"crossref","first-page":"5257","DOI":"10.1109\/TIFS.2024.3396390","article-title":"MEGR-APT: a memory-efficient apt hunting system based on attack representation learning","volume":"19","author":"Aly","year":"2024","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"10.1016\/j.jisa.2026.104457_bib0004","first-page":"1","article-title":"APT-KGL: an intelligent apt detection system based on threat knowledge and heterogeneous provenance graph learning","author":"Chen","year":"2022","journal-title":"IEEE Trans Dependable Secure Comput"},{"key":"10.1016\/j.jisa.2026.104457_bib0005","series-title":"2021 20th IEEE international conference on machine learning and applications (ICMLA)","first-page":"1720","article-title":"Prov-gem: automated provenance analysis framework using graph embeddings","author":"Kapoor","year":"2021"},{"key":"10.1016\/j.jisa.2026.104457_bib0006","series-title":"2024\u202fIEEE symposium on security and privacy (SP)","first-page":"139","article-title":"Flash: a comprehensive approach to intrusion detection via provenance graph representation learning","author":"Rehman","year":"2024"},{"key":"10.1016\/j.jisa.2026.104457_bib0007","doi-asserted-by":"crossref","first-page":"3972","DOI":"10.1109\/TIFS.2022.3208815","article-title":"Threatrace: detecting and tracing host-based threats in node level through provenance graph learning","volume":"17","author":"Wang","year":"2022","journal-title":"IEEE Trans Inf Forensics Secur"},{"issue":"1","key":"10.1016\/j.jisa.2026.104457_bib0008","doi-asserted-by":"crossref","first-page":"551","DOI":"10.1109\/TDSC.2020.2971484","article-title":"Conan: a practical real-time APT detection system with high accuracy and efficiency","volume":"19","author":"Xiong","year":"2022","journal-title":"IEEE Trans Dependable Secure Comput"},{"key":"10.1016\/j.jisa.2026.104457_bib0009","first-page":"1","article-title":"AptShield: a stable, efficient and real-time apt detection system for linux hosts","author":"Zhu","year":"2023","journal-title":"IEEE Trans Dependable Secure Comput"},{"key":"10.1016\/j.jisa.2026.104457_bib0010","doi-asserted-by":"crossref","unstructured":"Cheng Z., Lv Q., Liang J., Wang Y., Sun D., Pasquier T., et al. Kairos:: practical intrusion detection and investigation using whole-system provenance. 2023. arXiv preprint arXiv: 230805034.","DOI":"10.1109\/SP54263.2024.00005"},{"key":"10.1016\/j.jisa.2026.104457_bib0011","unstructured":"Jia Z., Xiong Y., Nan Y., Zhang Y., Zhao J., Wen M.. Magic: detecting advanced persistent threats via masked graph representation learning2024; 33rd USENIX Security Symposium (USENIX Security 24); 5197\u20135214."},{"key":"10.1016\/j.jisa.2026.104457_bib0012","unstructured":"Chen T., Song Q., Qiu X., Zhu T., Zhu Z., Lv M.. Kellect: a kernel-based efficient and lossless event log collector. 2022. arXiv preprint arXiv: 220711530."},{"key":"10.1016\/j.jisa.2026.104457_bib0013","series-title":"2024\u202fIEEE symposium on security and privacy (SP)","first-page":"87","article-title":"Eaudit: a fast, scalable and deployable audit data collection system","author":"Sekar","year":"2023"},{"key":"10.1016\/j.jisa.2026.104457_bib0014","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103485","article-title":"System-level data management for endpoint advanced persistent threat detection: issues, challenges and trends","volume":"135","author":"Chen","year":"2023","journal-title":"Comput Secur"},{"key":"10.1016\/j.jisa.2026.104457_bib0015","series-title":"2019\u202fIEEE symposium on security and privacy (SP)","first-page":"1137","article-title":"Holmes: real-time apt detection through correlation of suspicious information flows","author":"Milajerdi","year":"2019"},{"key":"10.1016\/j.jisa.2026.104457_bib0016","series-title":"26th USENIX security symposium (USENIX security 17)","first-page":"487","article-title":"{SLEUTH}: Real-time attack scenario reconstruction from {COTS} audit data","author":"Hossain","year":"2017"},{"key":"10.1016\/j.jisa.2026.104457_bib0017","article-title":"Deep graphSAGE enhancements for intrusion detection: analyzing attention mechanisms and GCN integration","volume":"90","author":"Saidane","year":"2025","journal-title":"J Inf Secur Appl"},{"key":"10.1016\/j.jisa.2026.104457_bib0018","article-title":"Host-based intrusion detection with multi-datasource and deep learning","volume":"78","author":"Hwang","year":"2023","journal-title":"J Inf Secur Appl"},{"key":"10.1016\/j.jisa.2026.104457_bib0019","article-title":"Federated reinforcement learning based intrusion detection system using dynamic attention mechanism","volume":"78","author":"Vadigi","year":"2023","journal-title":"J Inf Secur Appl"},{"key":"10.1016\/j.jisa.2026.104457_bib0020","series-title":"30th USENIX security symposium (USENIX security 21)","first-page":"3005","article-title":"{ATLAS}: A sequence-based learning approach for attack investigation","author":"Alsaheel","year":"2021"},{"key":"10.1016\/j.jisa.2026.104457_bib0021","series-title":"2020\u202fIEEE symposium on security and privacy (SP)","first-page":"1172","article-title":"Tactical provenance analysis for endpoint detection and response systems","author":"Hassan","year":"2020"},{"key":"10.1016\/j.jisa.2026.104457_bib0022","series-title":"2022\u202fIEEE symposium on security and privacy (SP)","first-page":"489","article-title":"Shadewatcher: recommendation-guided cyber threat analysis using system audit records","author":"Zengy","year":"2022"},{"key":"10.1016\/j.jisa.2026.104457_bib0023","series-title":"32nd USENIX security symposium (USENIX security 23)","first-page":"4355","article-title":"{PROGRAPHER}: an anomaly detection system based on provenance graph embedding","author":"Yang","year":"2023"},{"key":"10.1016\/j.jisa.2026.104457_bib0024","article-title":"A data-driven network intrusion detection system using feature selection and deep learning","volume":"78","author":"Zhang","year":"2023","journal-title":"J Inf Secur Appl"},{"key":"10.1016\/j.jisa.2026.104457_bib0025","article-title":"An adaptable deep learning-based intrusion detection system to zero-day attacks","volume":"76","author":"Soltani","year":"2023","journal-title":"J Inf Secur Appl"},{"key":"10.1016\/j.jisa.2026.104457_bib0026","series-title":"Proceedings of the AAAI conference on artificial intelligence","first-page":"7459","article-title":"Graph anomaly detection via multi-scale contrastive learning networks with augmented view","volume":"vol. 37","author":"Duan","year":"2023"},{"key":"10.1016\/j.jisa.2026.104457_bib0027","series-title":"Proceedings of the 30th ACM international conference on information & knowledge management","first-page":"3122","article-title":"Anemone: graph anomaly detection with multi-scale contrastive learning","author":"Jin","year":"2021"},{"issue":"6","key":"10.1016\/j.jisa.2026.104457_bib0028","doi-asserted-by":"crossref","first-page":"2378","DOI":"10.1109\/TNNLS.2021.3068344","article-title":"Anomaly detection on attributed networks via contrastive self-supervised learning","volume":"33","author":"Liu","year":"2021","journal-title":"IEEE Trans Neural Netw Learn Syst"},{"key":"10.1016\/j.jisa.2026.104457_bib0029","doi-asserted-by":"crossref","DOI":"10.1016\/j.knosys.2025.113093","article-title":"Graph anomaly detection via diffusion enhanced multi-view contrastive learning","volume":"311","author":"Kong","year":"2025","journal-title":"Knowl Based Syst"},{"key":"10.1016\/j.jisa.2026.104457_bib0030","unstructured":"Leman. Streamspot dataset. 2016. https:\/\/github.com\/sbustreamspot\/sbustreamspot-data."},{"key":"10.1016\/j.jisa.2026.104457_bib0031","unstructured":"Han X., Seltzer M.. Unicorn dataset. 2020. https:\/\/dataverse.harvard.edu\/dataverse\/unicorn-wget."},{"key":"10.1016\/j.jisa.2026.104457_bib0032","unstructured":"Computing D.T.. Transparent computing engagement 3 data release. 2017. https:\/\/github.com\/darpa-i2o\/Transparent-Computing\/blob\/master\/README-E3.md."},{"key":"10.1016\/j.jisa.2026.104457_bib0033","series-title":"International conference on information and communications security","first-page":"531","article-title":"Provenance-based intrusion detection via multi-scale graph representation learning","author":"Qiu","year":"2025"},{"key":"10.1016\/j.jisa.2026.104457_bib0034","unstructured":"MITRE. Acquire infrastructure: Malvertising. 2025a. https:\/\/attack.mitre.org\/techniques\/T1583\/008\/."},{"key":"10.1016\/j.jisa.2026.104457_bib0035","unstructured":"MITRE. Exploitation for client execution. 2025b. https:\/\/attack.mitre.org\/techniques\/T1203\/."},{"key":"10.1016\/j.jisa.2026.104457_bib0036","unstructured":"Martin L.. Cyber kill chain. 2025. https:\/\/www.lockheedmartin.com\/en-us\/capabilities\/cyber\/cyber-kill-chain.html."},{"key":"10.1016\/j.jisa.2026.104457_bib0037","series-title":"2024\u202fIEEE symposium on security and privacy (SP)","first-page":"3515","article-title":"R-caid: embedding root cause analysis within provenance-based intrusion detection","author":"Goyal","year":"2024"},{"key":"10.1016\/j.jisa.2026.104457_bib0038","series-title":"Security symposium (USENIX sec\u201925). USENIX","article-title":"Orthrus: achieving high quality of attribution in provenance-based intrusion detection systems","author":"Jiang","year":"2025"},{"key":"10.1016\/j.jisa.2026.104457_bib0039","doi-asserted-by":"crossref","unstructured":"Han X., Pasquier T., Bates A., Mickens J., Seltzer M.. Unicorn: runtime provenance-based detector for advanced persistent threats. 2020. arXiv preprint arXiv: 200101525.","DOI":"10.14722\/ndss.2020.24046"},{"key":"10.1016\/j.jisa.2026.104457_bib0040","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2024.104159","article-title":"Provenance-based APT campaigns detection via masked graph representation learning","volume":"148","author":"Ren","year":"2025","journal-title":"Comput Secur"},{"key":"10.1016\/j.jisa.2026.104457_bib0041","unstructured":"Bahar A.A.M., Ferrahi K.S., Messai M.-L., Seba H., Amrouche K.. Continuum: detecting apt attacks through spatial-temporal graph neural networks. 2025. arXiv preprint arXiv: 250102981."},{"key":"10.1016\/j.jisa.2026.104457_bib0042","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2024.125877","article-title":"A dynamic provenance graph-based detector for advanced persistent threats","volume":"265","author":"Wang","year":"2025","journal-title":"Expert Syst Appl"},{"key":"10.1016\/j.jisa.2026.104457_bib0043","unstructured":"Huang Y., Hassan W.U.I., Guo Y., Chen X., Li D.. Provsyn: synthesizing provenance graphs for data augmentation in intrusion detection systems. 2025. arXiv preprint arXiv: 250606226."},{"key":"10.1016\/j.jisa.2026.104457_bib0044","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2025.104359","article-title":"Pdcleaner: a multi-view collaborative data compression method for provenance graph-based apt detection systems","volume":"152","author":"Jin","year":"2025","journal-title":"Comput Secur"},{"key":"10.1016\/j.jisa.2026.104457_bib0045","unstructured":"Corporation M.. Mitre att&ck. 2015. https:\/\/attack.mitre.org."},{"issue":"6","key":"10.1016\/j.jisa.2026.104457_bib0046","first-page":"5879","article-title":"Graph self-supervised learning: a survey","volume":"35","author":"Liu","year":"2022","journal-title":"IEEE Trans Knowl Data Eng"},{"key":"10.1016\/j.jisa.2026.104457_bib0047","unstructured":"Veli\u010dkovi\u0107 P., Cucurull G., Casanova A., Romero A., Lio P., Bengio Y.. Graph attention networks. 2017. arXiv preprint arXiv: 171010903."},{"key":"10.1016\/j.jisa.2026.104457_bib0048","series-title":"Computer security\u2013ESORICS 2021: 26th european symposium on research in computer security, darmstadt, germany, october 4\u20138, 2021, proceedings, part I 26","first-page":"240","article-title":"Peeler: profiling kernel-level events to detect ransomware","author":"Ahmed","year":"2021"},{"issue":"3","key":"10.1016\/j.jisa.2026.104457_bib0049","first-page":"4","article-title":"Deep graph infomax","volume":"2","author":"Velickovic","year":"2019","journal-title":"ICLR (poster)"},{"key":"10.1016\/j.jisa.2026.104457_bib0050","series-title":"Companion proceedings of the web conference 2022","first-page":"1063","article-title":"Graph augmentation learning","author":"Yu","year":"2022"},{"key":"10.1016\/j.jisa.2026.104457_bib0051","first-page":"5812","article-title":"Graph contrastive learning with augmentations","volume":"33","author":"You","year":"2020","journal-title":"Adv Neural Inf Process Syst"},{"key":"10.1016\/j.jisa.2026.104457_bib0052","series-title":"Proceedings of the web conference 2021","first-page":"2069","article-title":"Graph contrastive learning with adaptive augmentation","author":"Zhu","year":"2021"},{"key":"10.1016\/j.jisa.2026.104457_bib0053","series-title":"Proceedings of the AAAI conference on artificial intelligence","first-page":"11015","article-title":"Data augmentation for graph neural networks","volume":"vol. 35","author":"Zhao","year":"2021"},{"key":"10.1016\/j.jisa.2026.104457_bib0054","series-title":"2023\u202fIEEE 39th international conference on data engineering (ICDE)","first-page":"696","article-title":"CLDG: contrastive learning on dynamic graphs","author":"Xu","year":"2023"},{"key":"10.1016\/j.jisa.2026.104457_bib0055","series-title":"Proceedings of the 30th ACM SIGKDD conference on knowledge discovery and data mining","first-page":"4700","article-title":"Topology-monitorable contrastive learning on dynamic graphs","author":"Zhu","year":"2024"},{"key":"10.1016\/j.jisa.2026.104457_bib0056","series-title":"2022 5th international conference on data science and information technology (DSIT)","first-page":"1","article-title":"Auglog: system log anomaly detection based on contrastive learning and data augmentation","author":"Zhou","year":"2022"},{"key":"10.1016\/j.jisa.2026.104457_bib0057","series-title":"International conference on advanced information systems engineering","first-page":"381","article-title":"Model-agnostic event log augmentation for predictive process monitoring","author":"K\u00e4ppel","year":"2023"},{"key":"10.1016\/j.jisa.2026.104457_bib0058","article-title":"Rapid distance-based outlier detection via sampling","volume":"26","author":"Sugiyama","year":"2013","journal-title":"Adv Neural Inf Process Syst"},{"key":"10.1016\/j.jisa.2026.104457_bib0059","article-title":"Systemtap: instrumenting the linux kernel for analyzing performance and functional problems","volume":"116","author":"Jacob","year":"2008","journal-title":"IBM Redb"},{"key":"10.1016\/j.jisa.2026.104457_bib0060","series-title":"Proceedings of the 22nd ACM SIGKDD international conference on knowledge discovery and data mining","first-page":"1035","article-title":"Fast memory-efficient anomaly detection in streaming heterogeneous graphs","author":"Manzoor","year":"2016"},{"key":"10.1016\/j.jisa.2026.104457_bib0061","series-title":"Proceedings of the 2023\u202fACM SIGSAC conference on computer and communications security","first-page":"2247","article-title":"Provg-searcher: a graph representation learning approach for efficient provenance graph search","author":"Altinisik","year":"2023"},{"key":"10.1016\/j.jisa.2026.104457_bib0062","unstructured":"Xu K., Hu W., Leskovec J., Jegelka S.. How powerful are graph neural networks?2018. arXiv preprint arXiv: 181000826."},{"key":"10.1016\/j.jisa.2026.104457_bib0063","series-title":"Inductive representation learning on large graphs","isbn-type":"print","author":"Hamilton","year":"2017","ISBN":"https:\/\/id.crossref.org\/isbn\/9781510860964"},{"key":"10.1016\/j.jisa.2026.104457_bib0064","unstructured":"Sun F.-Y., Hoffmann J., Verma V., Tang J.. Infograph: unsupervised and semi-supervised graph-level representation learning via mutual information maximization. 2019. arXiv preprint arXiv: 190801000."},{"key":"10.1016\/j.jisa.2026.104457_bib0065","series-title":"Proceedings of the ACM web conference 2022","first-page":"1070","article-title":"Simgrace: a simple framework for graph contrastive learning without data augmentation","author":"Xia","year":"2022"},{"key":"10.1016\/j.jisa.2026.104457_bib0066","series-title":"30th network and distributed system security symposium","article-title":"Sometimes, you aren\u2019t what you do: mimicry attacks against provenance graph host intrusion detection systems","author":"Goyal","year":"2023"},{"key":"10.1016\/j.jisa.2026.104457_bib0067","doi-asserted-by":"crossref","DOI":"10.14722\/ndss.2019.23349","article-title":"Nodoze: combatting threat alert fatigue with automated provenance triage","author":"Hassan","year":"2019","journal-title":"Netw Distrib Syst Secur Symp"},{"key":"10.1016\/j.jisa.2026.104457_bib0068","series-title":"31st USENIX security symposium (USENIX security 22)","first-page":"2461","article-title":"{Back-Propagating} system dependency impact for attack investigation","author":"Fang","year":"2022"},{"issue":"12","key":"10.1016\/j.jisa.2026.104457_bib0069","first-page":"2346","article-title":"Learning under concept drift: a review","volume":"31","author":"Lu","year":"2018","journal-title":"IEEE Trans Knowl Data Eng"},{"issue":"4","key":"10.1016\/j.jisa.2026.104457_bib0070","doi-asserted-by":"crossref","first-page":"694","DOI":"10.14778\/3636218.3636233","article-title":"Meter: a dynamic concept adaptation framework for online anomaly detection","volume":"17","author":"Zhu","year":"2023","journal-title":"Proc VLDB Endow"},{"issue":"8","key":"10.1016\/j.jisa.2026.104457_bib0071","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3551636","article-title":"A comprehensive survey on poisoning attacks and countermeasures in machine learning","volume":"55","author":"Tian","year":"2022","journal-title":"ACM Comput Surv"},{"issue":"2","key":"10.1016\/j.jisa.2026.104457_bib0072","doi-asserted-by":"crossref","first-page":"1563","DOI":"10.1109\/TPAMI.2022.3162397","article-title":"Dataset security for machine learning: data poisoning, backdoor attacks, and defenses","volume":"45","author":"Goldblum","year":"2022","journal-title":"IEEE Trans Pattern Anal Mach Intell"},{"key":"10.1016\/j.jisa.2026.104457_bib0073","doi-asserted-by":"crossref","first-page":"6693","DOI":"10.1109\/TIFS.2024.3420126","article-title":"A robust privacy-preserving federated learning model against model poisoning attacks","volume":"19","author":"Yazdinejad","year":"2024","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"10.1016\/j.jisa.2026.104457_bib0074","doi-asserted-by":"crossref","unstructured":"Hadi M.U., Qureshi R., Shah A., Irfan M., Zafar A., Shaikh M.B., et al. A survey on large language models: applications, challenges, limitations, and practical usage. Authorea Preprints2023.","DOI":"10.36227\/techrxiv.23589741.v1"}],"container-title":["Journal of Information Security and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S2214212626000876?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S2214212626000876?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,6,8]],"date-time":"2026-06-08T23:28:05Z","timestamp":1780961285000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S2214212626000876"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7]]},"references-count":74,"alternative-id":["S2214212626000876"],"URL":"https:\/\/doi.org\/10.1016\/j.jisa.2026.104457","relation":{},"ISSN":["2214-2126"],"issn-type":[{"value":"2214-2126","type":"print"}],"subject":[],"published":{"date-parts":[[2026,7]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Provenance-based advanced persistent threat detection via holistic contrastive learning with heuristic augmentation","name":"articletitle","label":"Article Title"},{"value":"Journal of Information Security and Applications","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.jisa.2026.104457","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Published by Elsevier Ltd.","name":"copyright","label":"Copyright"}],"article-number":"104457"}}