{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,8]],"date-time":"2026-03-08T23:50:51Z","timestamp":1773013851715,"version":"3.50.1"},"reference-count":47,"publisher":"Institution of Engineering and Technology (IET)","issue":"1","license":[{"start":{"date-parts":[[2025,10,31]],"date-time":"2025-10-31T00:00:00Z","timestamp":1761868800000},"content-version":"vor","delay-in-days":303,"URL":"http:\/\/creativecommons.org\/licenses\/by\/4.0\/"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/doi.wiley.com\/10.1002\/tdm_license_1.1"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62372410"],"award-info":[{"award-number":["62372410"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004731","name":"Natural Science Foundation of Zhejiang Province","doi-asserted-by":"publisher","award":["LZ23F020011"],"award-info":[{"award-number":["LZ23F020011"]}],"id":[{"id":"10.13039\/501100004731","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["ietresearch.onlinelibrary.wiley.com"],"crossmark-restriction":true},"short-container-title":["IET Information Security"],"published-print":{"date-parts":[[2025,1]]},"abstract":"<jats:p>HID (host intrusion detection) is a security mechanism for detecting malicious activities performed in a host (e.g., a server, an edge device). Recent research has recast HID as a provenance graph learning problem thanks to the advancement in deep learning techniques, especially the GNNs (graph neural networks). Although the provenance graph learning based HID methods show promise, they are vulnerable to adversarial attacks, where the attackers can bypass the HID models by carefully modifying their attack behaviors. In this paper, we reveal that an adversarial sample generated against one HID model may not be necessarily able to attack another HID model, and we further explore the success rate of adversarial attacks between different HID models by evaluating the mutual transferability. Based on the evaluation, we propose ProvADShield, a framework designed to defend against adversarial attacks on provenance graph learning based HID models. The core idea of ProvADShield is to combine multiple HID models by leveraging the mutual transferability. We evaluate ProvADShield based on a provenance dataset collected and made public by our team. The experiment results show that ProvADShield outperforms state\u2010of\u2010the\u2010art defense systems against adversarial attacks.<\/jats:p>","DOI":"10.1049\/ise2\/8625988","type":"journal-article","created":{"date-parts":[[2025,10,31]],"date-time":"2025-10-31T15:59:09Z","timestamp":1761926349000},"update-policy":"https:\/\/doi.org\/10.1002\/crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["ProvADShield: A Multimodel Ensemble Defender Against Adversarial Attacks on Provenance Graph Host Intrusion Detector"],"prefix":"10.1049","volume":"2025","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4810-7491","authenticated-orcid":false,"given":"Mingqi","family":"Lv","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kehan","family":"Qian","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4664-3311","authenticated-orcid":false,"given":"Tieming","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8657-662X","authenticated-orcid":false,"given":"Tiantian","family":"Zhu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7153-2755","authenticated-orcid":false,"given":"Jinyin","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"265","published-online":{"date-parts":[[2025,10,31]]},"reference":[{"key":"e_1_2_14_1_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2020.101734"},{"key":"e_1_2_14_2_2","doi-asserted-by":"publisher","DOI":"10.1145\/3344382"},{"key":"e_1_2_14_3_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103485"},{"key":"e_1_2_14_4_2","unstructured":"AlsaheelA. NanY. andMaS. et al.ATLAS: A Sequence-based Learning Approach for Attack Investigation 30th USENIX Security Symposium (USENIX Security 21) 2021 USENIX Association 3005\u20133022."},{"key":"e_1_2_14_5_2","unstructured":"JiaZ. XiongY. NanY. ZhangY. ZhaoJ. andWenM. MAGIC: Detecting Advanced Persistent Threats via Masked Graph Representation Learning 33rd USENIX Security Symposium (USENIX Security 24) 2024 Philadelphia USA USENIX Association."},{"key":"e_1_2_14_6_2","doi-asserted-by":"crossref","unstructured":"ChengZ. et al.KAIROS: Practical Intrusion Detection and Investigation Using Whole-System Provenance 45th IEEE Symposium on Security and Privacy (SP 2024) 2024 California USA IEEE.","DOI":"10.1109\/SP54263.2024.00005"},{"key":"e_1_2_14_7_2","first-page":"7693","article-title":"Adversarial Attack and Defence on Graph Data: A Survey","volume":"35","author":"Sun L.","year":"2022","journal-title":"IEEE Transactions on Knowledge and Data Engineering"},{"key":"e_1_2_14_8_2","doi-asserted-by":"crossref","unstructured":"Z\u00fcgnerD. AkbarnejadA. andG\u00fcnnemannS. Adversarial Attacks on Neural Networks for Graph Data Proceedings of the 24th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining (KDD 2018) 2018 London UK IEEE.","DOI":"10.1145\/3219819.3220078"},{"key":"e_1_2_14_9_2","doi-asserted-by":"crossref","unstructured":"GoyalA. HanX. WangG. andBatesA. Sometimes You Aren\u2019t What You Do: Mimicry Attacks against Provenance Graph Host Intrusion Detection Systems 30th Annual Network and Distributed System Security Symposium (NDSS 2023) 2023 California USA.","DOI":"10.14722\/ndss.2023.24207"},{"key":"e_1_2_14_10_2","unstructured":"MukherjeeK. WiedemeierJ. andWangT. et al.Evading Provenance-Based ML Detectors With Adversarial System Actions 32nd USENIX Security Symposium (USENIX Security 2023) 2023 California USA USENIX Association."},{"key":"e_1_2_14_11_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3208815"},{"key":"e_1_2_14_12_2","doi-asserted-by":"crossref","unstructured":"PierazziF. PendleburyF. CortellazziJ. andCavallaroL. Intriguing Properties of Adversarial ML Attacks in the Problem Space 2020 IEEE Symposium on Security and Privacy (SP 2020) 2020 California USA IEEE.","DOI":"10.1109\/SP40000.2020.00073"},{"key":"e_1_2_14_13_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.2971484"},{"key":"e_1_2_14_14_2","unstructured":"ChenT. DongC. andLvM. et al.APT-KGL: An Intelligent APT Detection System Based on Threat Knowledge and Heterogeneous Provenance Graph Learning IEEE Transactions on Dependable and Secure Computing 2022 IEEE."},{"key":"e_1_2_14_15_2","unstructured":"KipfT.andWellingM. Semi-Supervised Classification With Graph Convolutional Networks 5th International Conference on Learning Representations (ICLR 2017) 2017 Toulon France."},{"key":"e_1_2_14_16_2","unstructured":"HamiltonW. YingZ. andLeskovecJ. Inductive Representation Learning on Large Graphs 30th Annual Conference on Neural Information Processing Systems (NIPS 2017) 2017 California USA Curran Associates Inc.."},{"key":"e_1_2_14_17_2","unstructured":"LiuZ.andZhouJ. Graph Attention Networks 6th International Conference on Learning Representations (ICLR 2018) 2018 British Columbia Canada University of Cambridge."},{"key":"e_1_2_14_18_2","unstructured":"XuK. HuW. LeskovecJ. andJegelkaS. How Powerful are Graph Neural Networks? 7th International Conference on Learning Representations (ICLR 2019) 2019 Los Angeles USA Cornell University."},{"key":"e_1_2_14_19_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i18.18017"},{"key":"e_1_2_14_20_2","doi-asserted-by":"crossref","unstructured":"ZouX. ZhengQ. andDongY. et al.TDGIA: Effective Injection Attacks on Graph Neural Networks The 27th ACM SIGKDD Conference on Knowledge Discovery and Data Mining (KDD 2021) Virtual Event 2021 Singapore ACM.","DOI":"10.1145\/3447548.3467314"},{"key":"e_1_2_14_21_2","doi-asserted-by":"crossref","unstructured":"WuH. WangC. TyshetskiyY. DochertyA. LuK. andZhuL. Adversarial Examples for Graph Data: Deep Insights into Attack and Defence Proceedings of the Twenty-Eighth International Joint Conference on Artificial Intelligence (IJCAI 2019) 2019 Macao China Cornell University.","DOI":"10.24963\/ijcai.2019\/669"},{"key":"e_1_2_14_22_2","unstructured":"LiuY. ChenX. LiuC. andSongD. Delving into Transferable Adversarial Examples and Black-box Attacks 5th International Conference on Learning Representations (ICLR 2017) 2017 Toulon France ICLR."},{"key":"e_1_2_14_23_2","unstructured":"MujkanovicF. GeislerS. G\u00fcnnemannS. andBojchevskiA. Are Defences for Graph Neural Networks Robust? 35th Annual Conference on Neural Information Processing Systems (NeurIPS 2022) 2022 Los Angeles USA Curran Associates Inc.."},{"key":"e_1_2_14_24_2","doi-asserted-by":"crossref","unstructured":"EntezariN. Al-SayouriS. A. DarvishzadehA. andPapalexakisE. E. All You Need Is Low (Rank): Defending Against Adversarial Attacks on Graphs Proceedings of the 13th International Conference on Web Search and Data Mining (WSDM 2020) 2020 Texas USA ACM.","DOI":"10.1145\/3336191.3371789"},{"key":"e_1_2_14_25_2","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2019.2957786"},{"key":"e_1_2_14_26_2","doi-asserted-by":"crossref","unstructured":"JinW. MaY. LiuX. TangX. WangS. andTangJ. Graph Structure Learning for Robust Graph Neural Networks Proceedings of the 26th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining (KDD 2020) Virtual Event 2020 California USA ACM.","DOI":"10.1145\/3394486.3403049"},{"key":"e_1_2_14_27_2","doi-asserted-by":"crossref","unstructured":"MilajerdiS. M. EsheteB. GjomemoR. andVenkatakrishnanV. N. POIROT: Aligning Attack Behavior With Kernel Audit Records for Cyber Threat Hunting Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security (CCS 2019) 2019 London UK ACM.","DOI":"10.1145\/3319535.3363217"},{"key":"e_1_2_14_28_2","doi-asserted-by":"crossref","unstructured":"MilajerdiS. M. GjomemoR. EsheteB. SekarR. andVenkatakrishnanV. N. HOLMES: Real-Time APT Detection Through Correlation of Suspicious Information Flows 2019 IEEE Symposium on Security and Privacy (SP 2019) 2019 California USA IEEE.","DOI":"10.1109\/SP.2019.00026"},{"key":"e_1_2_14_29_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2023.3243667"},{"key":"e_1_2_14_30_2","doi-asserted-by":"crossref","unstructured":"ManzoorE. MilajerdiS. M. andAkogluL. Fast Memory-efficient Anomaly Detection in Streaming Heterogeneous Graphs Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (KDD 2016) 2016 California USA Association for Computing Machinery.","DOI":"10.1145\/2939672.2939783"},{"key":"e_1_2_14_31_2","unstructured":"GoodfellowI. J. ShlensJ. andSzegedyC. Explaining and Harnessing Adversarial Examples 3rd International Conference on Learning Representations (ICLR 2015) 2015 California USA ICLR."},{"key":"e_1_2_14_32_2","unstructured":"TianJ. ShenC. andWangB. et al.EVADE: Targeted Adversarial False Data Injection Attacks for State Estimation in Smart Grid IEEE Transactions on Sustainable Computing 2024 IEEE 1\u201313."},{"key":"e_1_2_14_33_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2024.3353302"},{"key":"e_1_2_14_34_2","unstructured":"DaiH. LiH. andTianT. et al.Adversarial Attack on Graph Structured Data Proceedings of the 35th International Conference on Machine Learning (ICML 2018) 2018 Stockholm Sweden PMLR."},{"key":"e_1_2_14_35_2","doi-asserted-by":"crossref","unstructured":"MaY. WangS. DerrT. WuL. andTangJ. Graph Adversarial Attack via Rewiring Proceedings of the 27th ACM SIGKDD Conference on Knowledge Discovery & Data Mining (KDD 2021) Virtual Event 2021 Singapore ACM.","DOI":"10.1145\/3447548.3467416"},{"key":"e_1_2_14_36_2","doi-asserted-by":"crossref","unstructured":"XuK. ChenH. andLiuS. et al.Topology Attack and Defence for Graph Neural Networks: An Optimization Perspective Proceedings of the 28th International Joint Conference on Artificial Intelligence (IJCAI 2019) 2019 Macao China AAAI Press.","DOI":"10.24963\/ijcai.2019\/550"},{"key":"e_1_2_14_37_2","doi-asserted-by":"crossref","unstructured":"DaiQ. ShenX. ZhangL. LiQ. andWangD. Adversarial Training Methods for Network Embedding The World Wide Web Conference (WWW 2019) 2019 California USA Association for Computing Machinery.","DOI":"10.1145\/3308558.3313445"},{"key":"e_1_2_14_38_2","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2018.2858821"},{"key":"e_1_2_14_39_2","unstructured":"IoannidisV. N. BerberidisD. andGiannakisG. B. GraphSAC: Detecting Anomalies in Large-Scale Graphs 2019 arXiv."},{"key":"e_1_2_14_40_2","doi-asserted-by":"crossref","unstructured":"ZhuD. ZhangZ. CuiP. andZhuW. Robust Graph Convolutional Networks Against Adversarial Attacks Proceedings of the 25th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining (KDD 2019) 2019 Alaska USA ACM.","DOI":"10.1145\/3292500.3330851"},{"key":"e_1_2_14_41_2","doi-asserted-by":"crossref","unstructured":"Z\u00fcgnerD.andG\u00fcnnemannS. Certifiable Robustness and Robust Training for Graph Convolutional Networks Proceedings of the 25th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining (KDD 2019) 2019 Alaska USA Association for Computing Machinery.","DOI":"10.1145\/3292500.3330905"},{"key":"e_1_2_14_42_2","unstructured":"BojchevskiA. KlicperaJ. andG\u00fcnnemannS. Efficient Robustness Certificates for Discrete Data: Sparsity-Aware Randomized Smoothing for Graphs Images and More 37th International Conference on Machine Learning (ICML 2020) Virtual Event 2020."},{"key":"e_1_2_14_43_2","doi-asserted-by":"crossref","unstructured":"WangY. FuH. ZouW. andJiaJ. MMCert: Provable Defence Against Adversarial Attacks to Multi-Modal Models 2024 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR) 2024 Seattle WA USA IEEE 24655\u201324664.","DOI":"10.1109\/CVPR52733.2024.02328"},{"key":"e_1_2_14_44_2","doi-asserted-by":"crossref","unstructured":"ZhaoK. ChenX. andHuangW. et al.Ensemble Adversarial Defence via Integration of Multiple Dispersed Low Curvature Models The International Joint Conference on Neural Networks (IJCNN 2024) 2024 Yokohama Japan IEEE.","DOI":"10.1109\/IJCNN60899.2024.10651354"},{"key":"e_1_2_14_45_2","first-page":"1","article-title":"Omni: Automated Ensemble With Unexpected Models Against Adversarial Evasion Attack","volume":"27","author":"Shu R.","year":"2020","journal-title":"Empirical Software Engineering"},{"key":"e_1_2_14_46_2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2024.3400056"},{"key":"e_1_2_14_47_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11390-022-2129-2"}],"container-title":["IET Information Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/ietresearch.onlinelibrary.wiley.com\/doi\/pdf\/10.1049\/ise2\/8625988","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/ietresearch.onlinelibrary.wiley.com\/doi\/full-xml\/10.1049\/ise2\/8625988","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/ietresearch.onlinelibrary.wiley.com\/doi\/pdf\/10.1049\/ise2\/8625988","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,8]],"date-time":"2026-03-08T22:36:20Z","timestamp":1773009380000},"score":1,"resource":{"primary":{"URL":"https:\/\/ietresearch.onlinelibrary.wiley.com\/doi\/10.1049\/ise2\/8625988"}},"subtitle":[],"editor":[{"given":"Jiwei","family":"Tian","sequence":"additional","affiliation":[],"role":[{"role":"editor","vocabulary":"crossref"}]}],"short-title":[],"issued":{"date-parts":[[2025,1]]},"references-count":47,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2025,1]]}},"alternative-id":["10.1049\/ise2\/8625988"],"URL":"https:\/\/doi.org\/10.1049\/ise2\/8625988","archive":["Portico"],"relation":{},"ISSN":["1751-8709","1751-8717"],"issn-type":[{"value":"1751-8709","type":"print"},{"value":"1751-8717","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,1]]},"assertion":[{"value":"2025-03-17","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-09-02","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-10-31","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"8625988"}}