{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,4]],"date-time":"2026-07-04T08:19:31Z","timestamp":1783153171965,"version":"3.54.6"},"publisher-location":"New York, NY, USA","reference-count":64,"publisher":"ACM","funder":[{"name":"National Natural Science Foundation of China","award":["625B2139, 62572377, 62302362"],"award-info":[{"award-number":["625B2139, 62572377, 62302362"]}]},{"name":"Shaanxi Province Natural Science Basic Research Program","award":["2025SYS-SYSZD-081"],"award-info":[{"award-number":["2025SYS-SYSZD-081"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,4,13]]},"DOI":"10.1145\/3774904.3792269","type":"proceedings-article","created":{"date-parts":[[2026,4,9]],"date-time":"2026-04-09T21:54:34Z","timestamp":1775771674000},"page":"2776-2787","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["ProvGuard: Logic-Aware Multi-View Contrastive Learning for Robust and Efficient Host Threat Detection"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0006-3265-4078","authenticated-orcid":false,"given":"Anyuan","family":"Sang","sequence":"first","affiliation":[{"name":"Xidian University, Xi'an, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2750-7031","authenticated-orcid":false,"given":"Li","family":"Yang","sequence":"additional","affiliation":[{"name":"Xidian University, Xi'an, China and Shaanxi Key Laboratory of Network and System Security, Xian, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5201-5074","authenticated-orcid":false,"given":"Lu","family":"Zhou","sequence":"additional","affiliation":[{"name":"Xidian University, Xi'an, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-5237-7547","authenticated-orcid":false,"given":"Cheng","family":"Zhou","sequence":"additional","affiliation":[{"name":"Xidian University, Xi'an, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-4286-4003","authenticated-orcid":false,"given":"Junbo","family":"Jia","sequence":"additional","affiliation":[{"name":"Xidian University, Xi'an, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-1975-8062","authenticated-orcid":false,"given":"Huipeng","family":"Yang","sequence":"additional","affiliation":[{"name":"Xidian University, Xi'an, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,4,12]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"[n.d.]. Apt notes. https:\/\/github.com\/kbandla\/APTnotes Last accessed on 2025-7-25."},{"key":"e_1_3_2_1_2_1","unstructured":"[n.d.]. Streamspot Dataset. https:\/\/github.com\/sbustreamspot\/sbustreamspotdata Last accessed on 2025-7-29."},{"key":"e_1_3_2_1_3_1","unstructured":"[n.d.]. Transparent Computing Engagement 3 DataRelease. https:\/\/github.com\/darpa-i2o\/TransparentComputing\/blob\/master\/README-E3.md Last accessed on 2025-7-21."},{"key":"e_1_3_2_1_4_1","volume-title":"Adversarial Deep Learning for Robust Detection of Binary Encoded Malware. In 2018 IEEE Symposium on Security and Privacy Workshops (SPW). IEEE, 76-82","author":"Al-Dujaili Abdullah","year":"2018","unstructured":"Abdullah Al-Dujaili, Alex Huang, Erik Hemberg, and Una-May O'Reilly. 2018. Adversarial Deep Learning for Robust Detection of Binary Encoded Malware. In 2018 IEEE Symposium on Security and Privacy Workshops (SPW). IEEE, 76-82."},{"key":"e_1_3_2_1_5_1","volume-title":"USENIX Security Symposium. 3005- 3022","author":"Alsaheel Abdulellah","year":"2021","unstructured":"Abdulellah Alsaheel, Yuhong Nan, Shiqing Ma, Le Yu, GregoryWalkup, Z Berkay Celik, Xiangyu Zhang, and Dongyan Xu. 2021. ATLAS: A Sequence-based Learning Approach for Attack Investigation.. In USENIX Security Symposium. 3005- 3022."},{"key":"e_1_3_2_1_6_1","volume-title":"Proceedings of the 35th International Conference on Machine Learning. PMLR, 274-283","author":"Athalye Anish","year":"2018","unstructured":"Anish Athalye, Nicholas Carlini, and David Wagner. 2018. Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial Examples. In Proceedings of the 35th International Conference on Machine Learning. PMLR, 274-283."},{"key":"e_1_3_2_1_7_1","first-page":"319","volume-title":"24th USENIX Security Symposium (USENIX Security 15)","author":"Bates Adam","year":"2015","unstructured":"Adam Bates, Dave Jing Tian, Kevin RB Butler, and Thomas Moyer. 2015. Trustworthy {Whole-System} provenance for the linux kernel. In 24th USENIX Security Symposium (USENIX Security 15). 319-334."},{"key":"e_1_3_2_1_8_1","first-page":"7193","volume-title":"34th USENIX Security Symposium (USENIX Security 25)","author":"Bilot Tristan","year":"2025","unstructured":"Tristan Bilot, Baoxiang Jiang, Zefeng Li, Nour El Madhoun, Khaldoun Al Agha, Anis Zouaoui, and Thomas Pasquier. 2025. Sometimes Simpler is Better: A Comprehensive Analysis of {State-of-the-Art} {Provenance-Based} Intrusion Detection Systems. In 34th USENIX Security Symposium (USENIX Security 25). 7193-7212."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/342009.335388"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00005"},{"key":"e_1_3_2_1_11_1","volume-title":"Proceedings of the 37th International Conference on Machine Learning (ICML). PMLR, 2206-2216","author":"Croce Francesco","year":"2020","unstructured":"Francesco Croce and Matthias Hein. 2020. Reliable Evaluation of Adversarial Robustness with an Ensemble of Diverse Parameter-Free Attacks. In Proceedings of the 37th International Conference on Machine Learning (ICML). PMLR, 2206-2216."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3616580"},{"key":"e_1_3_2_1_13_1","first-page":"6575","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Dong Feng","year":"2023","unstructured":"Feng Dong, Liu Wang, Xu Nie, Fei Shao, Haoyu Wang, Ding Li, Xiapu Luo, and Xusheng Xiao. 2023. {DISTDET}: A {Cost-Effective} Distributed Cyber Threat Detection System. In 32nd USENIX Security Symposium (USENIX Security 23). 6575-6592."},{"key":"e_1_3_2_1_14_1","first-page":"2461","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Fang Pengcheng","year":"2022","unstructured":"Pengcheng Fang, Peng Gao, Changlin Liu, Erman Ayday, Kangkook Jee, Ting Wang, Yanfang Fanny Ye, Zhuotao Liu, and Xusheng Xiao. 2022. {Back-Propagating} System Dependency Impact for Attack Investigation. In 31st USENIX Security Symposium (USENIX Security 22). 2461-2478."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2023.24207"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-39964-3_62"},{"key":"e_1_3_2_1_17_1","volume-title":"Inductive representation learning on large graphs. Advances in neural information processing systems 30","author":"Hamilton Will","year":"2017","unstructured":"Will Hamilton, Zhitao Ying, and Jure Leskovec. 2017. Inductive representation learning on large graphs. Advances in neural information processing systems 30 (2017)."},{"key":"e_1_3_2_1_18_1","volume-title":"Unicorn: Runtime provenance-based detector for advanced persistent threats.. In NDSS.","author":"Han Xueyuan","year":"2020","unstructured":"Xueyuan Han, Thomas Pasquier, Adam Bates, James Mickens, and Margo Seltzer. 2020. Unicorn: Runtime provenance-based detector for advanced persistent threats.. In NDSS."},{"key":"e_1_3_2_1_19_1","volume-title":"30th USENIX Security Symposium (USENIX Security . 2345-2362","author":"Han Xueyuan","year":"2021","unstructured":"Xueyuan Han, Xiao Yu, Thomas Pasquier, Ding Li, Junghwan Rhee, James Mickens, Margo Seltzer, and Haifeng Chen. 2021. SIGL: Securing software installations through deep graph learning. In 30th USENIX Security Symposium (USENIX Security . 2345-2362."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00096"},{"key":"e_1_3_2_1_21_1","volume-title":"Nodoze: Combatting threat alert fatigue with automated provenance triage. In network and distributed systems security symposium.","author":"Hassan Wajih Ul","year":"2019","unstructured":"Wajih Ul Hassan, Shengjian Guo, Ding Li, Zhengzhang Chen, Kangkook Jee, Zhichun Li, and Adam Bates. 2019. Nodoze: Combatting threat alert fatigue with automated provenance triage. In network and distributed systems security symposium."},{"key":"e_1_3_2_1_22_1","volume-title":"Pubali Datta, and Adam Bates.","author":"Hassan Wajih Ul","year":"2020","unstructured":"Wajih Ul Hassan, Mohammad Ali Noureddine, Pubali Datta, and Adam Bates. 2020. OmegaLog: High-fidelity attack investigation via transparent multi-layer log analysis. In Network and distributed system security symposium."},{"key":"e_1_3_2_1_23_1","volume-title":"International conference on machine learning. PMLR, 4116-4126","author":"Hassani Kaveh","year":"2020","unstructured":"Kaveh Hassani and Amir Hosein Khasahmadi. 2020. Contrastive multi-view representation learning on graphs. In International conference on machine learning. PMLR, 4116-4126."},{"key":"e_1_3_2_1_24_1","volume-title":"USENIX Security Symposium. 487-504","author":"Hossain Md Nahid","year":"2017","unstructured":"Md Nahid Hossain, Sadegh M Milajerdi, Junao Wang, Birhanu Eshete, Rigel Gjomemo, R Sekar, Scott D Stoller, and VN Venkatakrishnan. 2017. SLEUTH: Real-time Attack Scenario Reconstruction from COTS Audit Data.. In USENIX Security Symposium. 487-504."},{"key":"e_1_3_2_1_25_1","volume-title":"2023 IEEE Symposium on Security and Privacy (SP). IEEE Computer Society, 307-325","author":"Inam Muhammad Adil","year":"2022","unstructured":"Muhammad Adil Inam, Yinfang Chen, Akul Goyal, Jason Liu, Jaron Mink, Noor Michael, Sneha Gaur, Adam Bates, and Wajih Ul Hassan. 2022. SoK: History is a Vast Early Warning System: Auditing the Provenance of System Intrusions. In 2023 IEEE Symposium on Security and Privacy (SP). IEEE Computer Society, 307-325."},{"key":"e_1_3_2_1_26_1","first-page":"5197","volume-title":"33rd USENIX Security Symposium (USENIX Security 24)","author":"Jia Zian","year":"2024","unstructured":"Zian Jia, Yun Xiong, Yuhong Nan, Yao Zhang, Jinjing Zhao, and Mi Wen. 2024. MAGIC: Detecting Advanced Persistent Threats via Masked Graph Representation Learning. In 33rd USENIX Security Symposium (USENIX Security 24). 5197-5214."},{"key":"e_1_3_2_1_27_1","volume-title":"ORTHRUS: Achieving High Quality of Attribution in Provenance-based Intrusion Detection Systems. In Security Symposium (USENIX Sec'25)","author":"Jiang Baoxiang","year":"2025","unstructured":"Baoxiang Jiang, Tristan Bilot, Nour El Madhoun, Khaldoun AlAgha, Anis Zouaoui, Shahrear Iqbal, Xueyuan Han, and Thomas Pasquier. 2025. ORTHRUS: Achieving High Quality of Attribution in Provenance-based Intrusion Detection Systems. In Security Symposium (USENIX Sec'25). USENIX."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/945445.945467"},{"key":"e_1_3_2_1_29_1","volume-title":"Dominic G Lucchetti, and Peter M Chen.","author":"King Samuel T","year":"2005","unstructured":"Samuel T King, Zhuoqing Morley Mao, Dominic G Lucchetti, and Peter M Chen. 2005. Enriching Intrusion Alerts Through Multi-Host Causality.. In Ndss. Citeseer."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/2872362.2872395"},{"key":"e_1_3_2_1_31_1","first-page":"4","article-title":"MCI: Modeling-based Causality Inference in Audit Logging for Attack Investigation","volume":"2","author":"Kwon Yonghwi","year":"2018","unstructured":"Yonghwi Kwon, Fei Wang, Weihang Wang, Kyu Hyung Lee, Wen-Chuan Lee, Shiqing Ma, Xiangyu Zhang, Dongyan Xu, Somesh Jha, Gabriela F Ciocarlie, et al. 2018. MCI: Modeling-based Causality Inference in Audit Logging for Attack Investigation.. In NDSS, Vol. 2. 4.","journal-title":"NDSS"},{"key":"e_1_3_2_1_32_1","volume-title":"NDSS","volume":"16","author":"Lee Kyu Hyung","year":"2013","unstructured":"Kyu Hyung Lee, Xiangyu Zhang, and Dongyan Xu. 2013. High Accuracy Attack Provenance via Binary-based Execution Partition.. In NDSS, Vol. 16."},{"key":"e_1_3_2_1_33_1","first-page":"413","article-title":"Isolation forest. In 2008 eighth ieee international conference on data mining","author":"Liu Fei Tony","year":"2008","unstructured":"Fei Tony Liu, Kai Ming Ting, and Zhi-Hua Zhou. 2008. Isolation forest. In 2008 eighth ieee international conference on data mining. IEEE, 413-422.","journal-title":"IEEE"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"crossref","unstructured":"Yushan Liu Mu Zhang Ding Li Kangkook Jee Zhichun Li Zhenyu Wu Junghwan Rhee and Prateek Mittal. 2018. Towards a Timely Causality Analysis for Enterprise Security.. In NDSS.","DOI":"10.14722\/ndss.2018.23254"},{"key":"e_1_3_2_1_35_1","volume-title":"USENIX Security Symposium. 1111-1128","author":"Ma Shiqing","year":"2017","unstructured":"Shiqing Ma, Juan Zhai, FeiWang, Kyu Hyung Lee, Xiangyu Zhang, and Dongyan Xu. 2017. MPI: Multiple Perspective Attack Investigation with Semantic Aware Execution Partitioning.. In USENIX Security Symposium. 1111-1128."},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/2939672.2939783"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363217"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00026"},{"key":"e_1_3_2_1_39_1","first-page":"1199","volume-title":"Evading Provenance-Based ML Detectors with Adversarial System Actions. In 32nd USENIX Security Symposium (USENIX Security 23)","author":"Mukherjee Kunal","year":"2023","unstructured":"Kunal Mukherjee, Joshua Wiedemeier, Tianhao Wang, James Wei, Feng Chen, Muhyun Kim, Murat Kantarcioglu, and Kangkook Jee. 2023. Evading Provenance-Based ML Detectors with Adversarial System Actions. In 32nd USENIX Security Symposium (USENIX Security 23). USENIX Association, Anaheim, CA, 1199-1216. https:\/\/www.usenix.org\/conference\/usenixsecurity23\/presentation\/mukherjee"},{"key":"e_1_3_2_1_40_1","volume-title":"Adam Bates, Christopher Fletcher, Andrew Miller, and Dave Tian.","author":"Paccagnella Riccardo","year":"2020","unstructured":"Riccardo Paccagnella, Pubali Datta, Wajih Ul Hassan, Adam Bates, Christopher Fletcher, Andrew Miller, and Dave Tian. 2020. Custos: Practical tamper-evident auditing of operating systems using trusted execution. In Network and distributed system security symposium."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/3127479.3129249"},{"key":"e_1_3_2_1_42_1","volume-title":"Pytorch: An imperative style, high-performance deep learning library. Advances in neural information processing systems 32","author":"Paszke Adam","year":"2019","unstructured":"Adam Paszke, Sam Gross, Francisco Massa, Adam Lerer, James Bradbury, Gregory Chanan, Trevor Killeen, Zeming Lin, Natalia Gimelshein, Luca Antiga, et al. 2019. Pytorch: An imperative style, high-performance deep learning library. Advances in neural information processing systems 32 (2019)."},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00139"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/3696410.3714925"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2025.3599661"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/3678890.3678916"},{"key":"e_1_3_2_1_47_1","volume-title":"Support vector method for novelty detection. Advances in neural information processing systems 12","author":"Sch\u00f6lkopf Bernhard","year":"1999","unstructured":"Bernhard Sch\u00f6lkopf, Robert C Williamson, Alex Smola, John Shawe-Taylor, and John Platt. 1999. Support vector method for novelty detection. Advances in neural information processing systems 12 (1999)."},{"key":"e_1_3_2_1_48_1","volume-title":"Attack2vec: Leveraging temporal word embeddings to understand the evolution of cyberattacks. 28 st USENIX Security Symposium (USENIX Security 2019)","author":"Shen Yun","year":"2019","unstructured":"Yun Shen and Gianluca Stringhini. 2019. Attack2vec: Leveraging temporal word embeddings to understand the evolution of cyberattacks. 28 st USENIX Security Symposium (USENIX Security 2019) (2019)."},{"key":"e_1_3_2_1_49_1","volume-title":"Mgae: Masked autoencoders for self-supervised learning on graphs. arXiv preprint arXiv:2201.02534","author":"Tan Qiaoyu","year":"2022","unstructured":"Qiaoyu Tan, Ninghao Liu, Xiao Huang, Rui Chen, Soo-Hyun Choi, and Xia Hu. 2022. Mgae: Masked autoencoders for self-supervised learning on graphs. arXiv preprint arXiv:2201.02534 (2022)."},{"key":"e_1_3_2_1_50_1","first-page":"4","article-title":"Deep graph infomax","volume":"2","author":"Velickovic Petar","year":"2019","unstructured":"Petar Velickovic, William Fedus, William L Hamilton, Pietro Li\u00f2, Yoshua Bengio, and R Devon Hjelm. 2019. Deep graph infomax. ICLR (Poster) 2, 3 (2019), 4.","journal-title":"ICLR (Poster)"},{"key":"e_1_3_2_1_51_1","volume-title":"Incorporating gradients to rules: Towards lightweight, adaptive provenance-based intrusion detection. arXiv preprint arXiv:2404.14720","author":"Wang Lingzhi","year":"2024","unstructured":"Lingzhi Wang, Xiangmin Shen, Weijian Li, Zhenyuan Li, R Sekar, Han Liu, and Yan Chen. 2024. Incorporating gradients to rules: Towards lightweight, adaptive provenance-based intrusion detection. arXiv preprint arXiv:2404.14720 (2024)."},{"key":"e_1_3_2_1_52_1","unstructured":"Minjie Wang Da Zheng Zihao Ye Quan Gan Mufei Li Xiang Song Jinjing Zhou Chao Ma Lingfan Yu Yu Gai et al. 2019. Deep graph library: A graphcentric highly-performant package for graph neural networks. arXiv preprint arXiv:1909.01315 (2019)."},{"key":"e_1_3_2_1_53_1","volume-title":"Proceedings of the 23rd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining. ACM, 1145-1153","author":"Guo Wenbo","year":"2017","unstructured":"QinglongWang,Wenbo Guo, Kaixuan Zhang, Alexander G. Ororbia, Xinyu Xing, C. Lee Giles, and Xue Liu. 2017. Adversary Resistant Deep Neural Networks with an Application to Malware Detection. In Proceedings of the 23rd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining. ACM, 1145-1153."},{"key":"e_1_3_2_1_54_1","volume-title":"Ding Li, Kangkook Jee, Xiao Yu, Kexuan Zou, Junghwan Rhee, Zhengzhang Chen, Wei Cheng, Carl A Gunter, et al.","author":"Wang Qi","year":"2020","unstructured":"Qi Wang, Wajih Ul Hassan, Ding Li, Kangkook Jee, Xiao Yu, Kexuan Zou, Junghwan Rhee, Zhengzhang Chen, Wei Cheng, Carl A Gunter, et al. 2020. You Are What You Do: Hunting Stealthy Malware via Data Provenance Analysis. In NDSS."},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3208815"},{"key":"e_1_3_2_1_56_1","first-page":"2172","volume-title":"Proceedings of the ACM on Web Conference","author":"Qiao Wei","year":"2025","unstructured":"WeihengWu,Wei Qiao,Wenhao Yan, Bo Jiang, Yuling Liu, Baoxu Liu, Zhigang Lu, and Junrong Liu. 2025. Brewing Vodka: Distilling Pure Knowledge for Lightweight Threat Detection in Audit Logs. In Proceedings of the ACM on Web Conference 2025. 2172-2182."},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978378"},{"key":"e_1_3_2_1_58_1","first-page":"4355","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Yang Fan","year":"2023","unstructured":"Fan Yang, Jiacen Xu, Chunlin Xiong, Zhou Li, and Kehuan Zhang. 2023. PROGRAPHER: An Anomaly Detection System based on Provenance Graph Embedding. In 32nd USENIX Security Symposium (USENIX Security 23). 4355-4372."},{"key":"e_1_3_2_1_59_1","volume-title":"Graph contrastive learning with augmentations. Advances in neural information processing systems 33","author":"You Yuning","year":"2020","unstructured":"Yuning You, Tianlong Chen, Yongduo Sui, Ting Chen, Zhangyang Wang, and Yang Shen. 2020. Graph contrastive learning with augmentations. Advances in neural information processing systems 33 (2020), 5812-5823."},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833669"},{"key":"e_1_3_2_1_61_1","volume-title":"Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security. 3135-3149","author":"Zeng Jun","year":"2022","unstructured":"Jun Zeng, Chuqi Zhang, and Zhenkai Liang. 2022. PalanT\u00edr: Optimizing Attack Provenance with Hardware-enhanced System Observability. In Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security. 3135-3149."},{"key":"e_1_3_2_1_62_1","first-page":"607","volume-title":"34th USENIX Security Symposium (USENIX Security 25)","author":"Zhang Bo","year":"2025","unstructured":"Bo Zhang, Yansong Gao, Changlong Yu, Boyu Kuang, Zhi Zhang, Hyoungshick Kim, and Anmin Fu. 2025. {TAPAS}: An Efficient Online {APT} Detection with Task-guided Process Provenance Graph Segmentation and Analysis. In 34th USENIX Security Symposium (USENIX Security 25). 607-624."},{"key":"e_1_3_2_1_63_1","volume-title":"APTSHIELD: A Stable, Efficient and Real-time APT Detection System for Linux Hosts","author":"Zhu Tiantian","year":"2023","unstructured":"Tiantian Zhu, Jinkai Yu, Chunlin Xiong, Wenrui Cheng, Qixuan Yuan, Jie Ying, Tieming Chen, Jiabo Zhang, Mingqi Lv, Yan Chen, et al. 2023. APTSHIELD: A Stable, Efficient and Real-time APT Detection System for Linux Hosts. IEEE Transactions on Dependable and Secure Computing (2023)."},{"key":"e_1_3_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1145\/3539605"}],"event":{"name":"WWW '26: The ACM Web Conference 2026","location":"Dubai United Arab Emirates","sponsor":["SIGWEB ACM Special Interest Group on Hypertext, Hypermedia, and Web"]},"container-title":["Proceedings of the ACM Web Conference 2026"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3774904.3792269","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,4]],"date-time":"2026-07-04T07:57:35Z","timestamp":1783151855000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3774904.3792269"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,12]]},"references-count":64,"alternative-id":["10.1145\/3774904.3792269","10.1145\/3774904"],"URL":"https:\/\/doi.org\/10.1145\/3774904.3792269","relation":{},"subject":[],"published":{"date-parts":[[2026,4,12]]},"assertion":[{"value":"2026-04-12","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}