{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,6]],"date-time":"2026-03-06T04:41:16Z","timestamp":1772772076143,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":39,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,7,30]],"date-time":"2024-07-30T00:00:00Z","timestamp":1722297600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"National Research Agency","award":["ANR-20-CE39-0008"],"award-info":[{"award-number":["ANR-20-CE39-0008"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,7,30]]},"DOI":"10.1145\/3664476.3670466","type":"proceedings-article","created":{"date-parts":[[2024,7,25]],"date-time":"2024-07-25T12:35:50Z","timestamp":1721910950000},"page":"1-10","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":6,"title":["FedHE-Graph: Federated Learning with Hybrid Encryption on Graph Neural Networks for Advanced Persistent Threat Detection"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0008-9702-1700","authenticated-orcid":false,"given":"Atmane Ayoub","family":"Mansour Bahar","sequence":"first","affiliation":[{"name":"\u00c9cole Nationale Sup\u00e9rieure d'Informatique, Algeria"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-3146-5503","authenticated-orcid":false,"given":"Kamel Soa\u00efd","family":"Ferrahi","sequence":"additional","affiliation":[{"name":"\u00c9cole Nationale Sup\u00e9rieure d'Informatique, Algeria"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0376-0657","authenticated-orcid":false,"given":"Mohamed-Lamine","family":"Messai","sequence":"additional","affiliation":[{"name":"ERIC, University Lyon 2, France"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0670-815X","authenticated-orcid":false,"given":"Hamida","family":"Seba","sequence":"additional","affiliation":[{"name":"LIRIS, University Lyon 1, France"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-2410-2582","authenticated-orcid":false,"given":"Karima","family":"Amrouche","sequence":"additional","affiliation":[{"name":"\u00c9cole Nationale Sup\u00e9rieure d'Informatique, Algeria"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2024,7,30]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Praveen Kumar\u00a0Reddy Maddikunta, and Thippa\u00a0Reddy Gadekallu","author":"Agrawal Shaashwat","year":"2022","unstructured":"Shaashwat Agrawal, Sagnik Sarkar, Ons Aouedi, Gokul Yenduri, Kandaraj Piamrat, Mamoun Alazab, Sweta Bhattacharya, Praveen Kumar\u00a0Reddy Maddikunta, and Thippa\u00a0Reddy Gadekallu. 2022. Federated learning for intrusion detection system: Concepts, challenges and future directions. Computer Communications (2022)."},{"key":"e_1_3_2_1_2_1","volume-title":"Sergio\u00a0L\u00f3pez Bernal, G\u00e9r\u00f4me Bovet, Manuel\u00a0Gil P\u00e9rez, Gregorio\u00a0Mart\u00ednez P\u00e9rez, and Alberto\u00a0Huertas Celdr\u00e1n.","author":"Tom\u00e1s\u00a0Mart\u00ednez Beltr\u00e1n Enrique","year":"2023","unstructured":"Enrique Tom\u00e1s\u00a0Mart\u00ednez Beltr\u00e1n, Mario\u00a0Quiles P\u00e9rez, Pedro Miguel\u00a0S\u00e1nchez S\u00e1nchez, Sergio\u00a0L\u00f3pez Bernal, G\u00e9r\u00f4me Bovet, Manuel\u00a0Gil P\u00e9rez, Gregorio\u00a0Mart\u00ednez P\u00e9rez, and Alberto\u00a0Huertas Celdr\u00e1n. 2023. Decentralized federated learning: Fundamentals, state of the art, frameworks, trends, and challenges. IEEE Communications Surveys & Tutorials (2023)."},{"key":"e_1_3_2_1_3_1","volume-title":"GHunter: A Fast Subgraph Matching Method for Threat Hunting. In 2023 26th International Conference on Computer Supported Cooperative Work in Design (CSCWD). IEEE, 1014\u20131019","author":"Cheng Zijun","year":"2023","unstructured":"Zijun Cheng, Rujie Dai, Leiqi Wang, Ziyang Yu, Qiujian Lv, Yan Wang, and Degang Sun. 2023. GHunter: A Fast Subgraph Matching Method for Threat Hunting. In 2023 26th International Conference on Computer Supported Cooperative Work in Design (CSCWD). IEEE, 1014\u20131019."},{"key":"e_1_3_2_1_4_1","volume-title":"2024 IEEE Symposium on Security and Privacy (SP). IEEE Computer Society, 5\u20135.","author":"Cheng Zijun","year":"2023","unstructured":"Zijun Cheng, Qiujian Lv, Jinyuan Liang, Yan Wang, Degang Sun, Thomas Pasquier, and Xueyuan Han. 2023. KAIROS: Practical Intrusion Detection and Investigation using Whole-system Provenance. In 2024 IEEE Symposium on Security and Privacy (SP). IEEE Computer Society, 5\u20135."},{"key":"e_1_3_2_1_5_1","unstructured":"Matt Curtin. 2005. Brute Force. Springer."},{"key":"e_1_3_2_1_6_1","volume-title":"Apache kafka","author":"Garg Nishant","unstructured":"Nishant Garg. 2013. Apache kafka. Packt Publishing Birmingham, UK."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-023-00727-6"},{"key":"e_1_3_2_1_8_1","volume-title":"Inductive representation learning on large graphs. Advances in neural information processing systems 30","author":"Hamilton Will","year":"2017","unstructured":"Will Hamilton, Zhitao Ying, and Jure Leskovec. 2017. Inductive representation learning on large graphs. Advances in neural information processing systems 30 (2017)."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","unstructured":"Xueyuan Han. 2018. Hour-Long Wget Benign Dataset (Base Graph). https:\/\/doi.org\/10.7910\/DVN\/5H4TDI","DOI":"10.7910\/DVN\/5H4TDI"},{"key":"e_1_3_2_1_10_1","volume-title":"UNICORN: Runtime Provenance-Based Detector for Advanced Persistent Threats. In Network and Distributed System Security Symposium.","author":"Han Xueyuan","year":"2020","unstructured":"Xueyuan Han, Thomas Pasquier, Adam Bates, James Mickens, and Margo Seltzer. 2020. UNICORN: Runtime Provenance-Based Detector for Advanced Persistent Threats. In Network and Distributed System Security Symposium."},{"key":"e_1_3_2_1_11_1","volume-title":"Fedgraphnn: A federated learning system and benchmark for graph neural networks. arXiv preprint arXiv:2104.07145","author":"He Chaoyang","year":"2021","unstructured":"Chaoyang He, Keshav Balasubramanian, Emir Ceyani, Carl Yang, Han Xie, Lichao Sun, Lifang He, Liangwei Yang, Philip\u00a0S Yu, Yu Rong, 2021. Fedgraphnn: A federated learning system and benchmark for graph neural networks. arXiv preprint arXiv:2104.07145 (2021)."},{"key":"e_1_3_2_1_12_1","volume-title":"Fedml: A research library and benchmark for federated machine learning. arXiv preprint arXiv:2007.13518","author":"He Chaoyang","year":"2020","unstructured":"Chaoyang He, Songze Li, Jinhyun So, Xiao Zeng, Mi Zhang, Hongyi Wang, Xiaoyang Wang, Praneeth Vepakomma, Abhishek Singh, Hang Qiu, 2020. Fedml: A research library and benchmark for federated machine learning. arXiv preprint arXiv:2007.13518 (2020)."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.procs.2015.04.191"},{"key":"e_1_3_2_1_14_1","volume-title":"MAGIC: Detecting Advanced Persistent Threats via Masked Graph Representation Learning. arXiv preprint arXiv:2310.09831","author":"Jia Zian","year":"2023","unstructured":"Zian Jia, Yun Xiong, Yuhong Nan, Yao Zhang, Jinjing Zhao, and Mi Wen. 2023. MAGIC: Detecting Advanced Persistent Threats via Masked Graph Representation Learning. arXiv preprint arXiv:2310.09831 (2023)."},{"key":"e_1_3_2_1_15_1","volume-title":"FedML-HE: An Efficient Homomorphic-Encryption-Based Privacy-Preserving Federated Learning System. arXiv preprint arXiv:2303.10837","author":"Jin Weizhao","year":"2023","unstructured":"Weizhao Jin, Yuhang Yao, Shanshan Han, Carlee Joe-Wong, Srivatsan Ravi, Salman Avestimehr, and Chaoyang He. 2023. FedML-HE: An Efficient Homomorphic-Encryption-Based Privacy-Preserving Federated Learning System. arXiv preprint arXiv:2303.10837 (2023)."},{"key":"e_1_3_2_1_16_1","unstructured":"Angelos\u00a0D. Keromytis. 2018. Transparent-Computing\/README-E3.md at master \u00b7 darpa-i2o\/Transparent-Computing \u2014 github.com. https:\/\/github.com\/darpa-i2o\/Transparent-Computing\/blob\/master\/README-E3.md."},{"key":"e_1_3_2_1_17_1","volume-title":"Semi-Supervised Classification with Graph Convolutional Networks. In International Conference on Learning Representations.","author":"Kipf N","year":"2016","unstructured":"Thomas\u00a0N Kipf and Max Welling. 2016. Semi-Supervised Classification with Graph Convolutional Networks. In International Conference on Learning Representations."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-72037-9_8"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102282"},{"key":"e_1_3_2_1_20_1","volume-title":"Proceedings DARPA Information Survivability Conference and Exposition. DISCEX\u201900","author":"Lippmann P","year":"2000","unstructured":"Richard\u00a0P Lippmann, David\u00a0J Fried, Isaac Graf, Joshua\u00a0W Haines, Kristopher\u00a0R Kendall, David McClung, Dan Weber, Seth\u00a0E Webster, Dan Wyschogrod, Robert\u00a0K Cunningham, 2000. Evaluating intrusion detection systems: The 1998 DARPA off-line intrusion detection evaluation. In Proceedings DARPA Information Survivability Conference and Exposition. DISCEX\u201900, Vol.\u00a02. IEEE, 12\u201326."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363224"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/2939672.2939783"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.4249\/scholarpedia.1883"},{"key":"e_1_3_2_1_24_1","unstructured":"Mathew\u00a0J. Schwartz. 2023. Researcher claims to crack RSA-2048 with Quantum Computer. https:\/\/www.databreachtoday.com\/blogs\/researcher-claims-to-crack-rsa-2048-quantum-computer-p-3536"},{"key":"e_1_3_2_1_25_1","volume-title":"International Conference on Information Security Practice and Experience","author":"Duc\u00a0Hoang Son Ngo","unstructured":"Ngo Duc\u00a0Hoang Son, Huynh\u00a0Thai Thi, Phan\u00a0The Duy, and Van-Hau Pham. 2023. XFedGraph-Hunter: An Interpretable Federated Learning Framework for Hunting Advanced Persistent Threat in Provenance Graph. In International Conference on Information Security Practice and Experience. Springer, 546\u2013561."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.5220\/0011322700003283"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i8.26187"},{"key":"e_1_3_2_1_28_1","volume-title":"Phan\u00a0The Duy, Nghi\u00a0Hoang Khoa, Khoa Ngo-Khanh, and Van-Hau Pham.","author":"Thi Huynh\u00a0Thai","year":"2023","unstructured":"Huynh\u00a0Thai Thi, Ngo Duc\u00a0Hoang Son, Phan\u00a0The Duy, Nghi\u00a0Hoang Khoa, Khoa Ngo-Khanh, and Van-Hau Pham. 2023. XFedHunter: An Explainable Federated Learning Framework for Advanced Persistent Threat Detection in SDN. arXiv preprint arXiv:2309.08485 (2023)."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISCIT55906.2022.9931222"},{"key":"e_1_3_2_1_30_1","first-page":"58","article-title":"The problem of concept drift: definitions and related work","volume":"106","author":"Tsymbal Alexey","year":"2004","unstructured":"Alexey Tsymbal. 2004. The problem of concept drift: definitions and related work. Computer Science Department, Trinity College Dublin 106, 2 (2004), 58.","journal-title":"Computer Science Department, Trinity College Dublin"},{"key":"e_1_3_2_1_31_1","volume-title":"Graph attention networks. stat 1050, 20","author":"Velickovic Petar","year":"2017","unstructured":"Petar Velickovic, Guillem Cucurull, Arantxa Casanova, Adriana Romero, Pietro Lio, Yoshua Bengio, 2017. Graph attention networks. stat 1050, 20 (2017), 10\u201348550."},{"key":"e_1_3_2_1_32_1","unstructured":"viensea1106. [n. d.]. VIENSEA1106\/Federated-learning-meets-homomorphic-encryption: Homomorphic encryption and Federated Learning Based Privacy-Preserving. https:\/\/github.com\/viensea1106\/Federated-Learning-meets-Homomorphic-Encryption\/tree\/main"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3208815"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00041"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3160879"},{"key":"e_1_3_2_1_36_1","unstructured":"Kinza Yasar and Linda Rosencrance. 2023. What is an advanced persistent threat (APT)?: Definition from TechTarget. https:\/\/www.techtarget.com\/searchsecurity\/definition\/advanced-persistent-threat-APT"},{"key":"e_1_3_2_1_37_1","volume-title":"Gnnexplainer: Generating explanations for graph neural networks. Advances in neural information processing systems 32","author":"Ying Zhitao","year":"2019","unstructured":"Zhitao Ying, Dylan Bourgeois, Jiaxuan You, Marinka Zitnik, and Jure Leskovec. 2019. Gnnexplainer: Generating explanations for graph neural networks. Advances in neural information processing systems 32 (2019)."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.3390\/e25111550"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/CDS52072.2021.00111"}],"event":{"name":"ARES 2024: The 19th International Conference on Availability, Reliability and Security","location":"Vienna Austria","acronym":"ARES 2024"},"container-title":["Proceedings of the 19th International Conference on Availability, Reliability and Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3664476.3670466","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3664476.3670466","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T16:51:24Z","timestamp":1755881484000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3664476.3670466"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,7,30]]},"references-count":39,"alternative-id":["10.1145\/3664476.3670466","10.1145\/3664476"],"URL":"https:\/\/doi.org\/10.1145\/3664476.3670466","relation":{},"subject":[],"published":{"date-parts":[[2024,7,30]]},"assertion":[{"value":"2024-07-30","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}