{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,16]],"date-time":"2026-04-16T15:53:23Z","timestamp":1776354803118,"version":"3.51.2"},"publisher-location":"New York, NY, USA","reference-count":30,"publisher":"ACM","funder":[{"name":"German Federal Ministry for Economic Affairs and Climate Action (BMWK)","award":["03EI6089A"],"award-info":[{"award-number":["03EI6089A"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,4,27]]},"DOI":"10.1145\/3803525.3804991","type":"proceedings-article","created":{"date-parts":[[2026,4,16]],"date-time":"2026-04-16T14:54:47Z","timestamp":1776351287000},"page":"10-16","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["From Anomaly to Attack Path: LLM-Based Network Traffic Investigation for APT Detection"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0005-5088-5681","authenticated-orcid":false,"given":"Benedikt","family":"Pletzer","sequence":"first","affiliation":[{"name":"Laboratory for Safe and Secure Systems, OTH Regensburg, Regensburg, Bayern, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7727-2448","authenticated-orcid":false,"given":"J\u00fcrgen","family":"Mottok","sequence":"additional","affiliation":[{"name":"Laboratory for Safe and Secure Systems, OTH Regensburg, Regensburg, Bayern, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2026,4,26]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","unstructured":"Mohammad F. Al-Hammouri Yazan Otoum Rasha Atwa and Amiya Nayak. 2025. Hybrid LLM-Enhanced Intrusion Detection for Zero-Day Threats in IoT Networks. arXiv:2507.07413 [cs] doi:10.48550\/arXiv.2507.07413","DOI":"10.48550\/arXiv.2507.07413"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/WF-IoT64238.2025.11270748"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/3719027.3765219"},{"key":"e_1_3_2_1_4_1","volume-title":"The Eleventh International Conference on Learning Representations.","author":"Carlini Nicholas","year":"2023","unstructured":"Nicholas Carlini, Daphne Ippolito, Matthew Jagielski, Katherine Lee, Florian Tramer, and Chiyuan Zhang. 2023. Quantifying Memorization across Neural Language Models. In The Eleventh International Conference on Learning Representations."},{"key":"e_1_3_2_1_5_1","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Carlini Nicholas","year":"2021","unstructured":"Nicholas Carlini, Florian Tramer, Eric Wallace, Matthew Jagielski, Ariel Herbert-Voss, Katherine Lee, Adam Roberts, Tom Brown, Dawn Song, Ulfar Erlingsson, et al. 2021. Extracting Training Data from Large Language Models. In 30th USENIX Security Symposium (USENIX Security 21). 2633\u20132650."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.3390\/sym17091373"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.17770\/etr2025vol2.8618"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP60621.2024.00042"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.2407.11278"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3605764.3623985"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2025.naacl-long.469"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/BDCAT63179.2024.00021"},{"key":"e_1_3_2_1_13_1","volume-title":"33rd USENIX Security Symposium (USENIX Security 24)","author":"Jia Zian","year":"2024","unstructured":"Zian Jia, Yun Xiong, Yuhong Nan, Yao Zhang, Jinjing Zhao, and Mi Wen. 2024. MAGIC: Detecting Advanced Persistent Threats via Masked Graph Representation Learning. In 33rd USENIX Security Symposium (USENIX Security 24). USENIX Association, Philadelphia, PA, 5197\u20135214."},{"key":"e_1_3_2_1_14_1","volume-title":"Deduplicating Training Data Mitigates Privacy Risks in Language Models. In International Conference on Machine Learning. PMLR, 10697\u201310707","author":"Kandpal Nikhil","year":"2022","unstructured":"Nikhil Kandpal, Eric Wallace, and Colin Raffel. 2022. Deduplicating Training Data Mitigates Privacy Risks in Language Models. In International Conference on Machine Learning. PMLR, 10697\u201310707."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/PAIS62114.2024.10541168"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2025.emnlp-main.1789"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICMT58149.2023.10171308"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484576"},{"key":"e_1_3_2_1_19_1","unstructured":"Yige Li Hanxun Huang Yunhan Zhao Xingjun Ma and Jun Sun. 2025. Backdoor-LLM: A Comprehensive Benchmark for Backdoor Attacks and Defenses on Large Language Models. In The Thirty-Ninth Annual Conference on Neural Information Processing Systems Datasets and Benchmarks Track."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","unstructured":"Yanzhou Li Tianlin Li Kangjie Chen Jian Zhang Shangqing Liu Wenhan Wang Tianwei Zhang and Yang Liu. 2024. BadEdit: Backdooring Large Language Models by Model Editing. arXiv:2403.13355 [cs] doi:10.48550\/arXiv.2403.13355","DOI":"10.48550\/arXiv.2403.13355"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2022.3159580"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","unstructured":"Dishita Naik Ishita Naik and Nitin Naik. 2025. When Generative AI Prompts Bite Back: Investigating Different Types of Prompt Injection Attacks on Large Language Models (LLMs) and Their Prevention Methods. doi:10.36227\/techrxiv.176551675.52333626\/v1","DOI":"10.36227\/techrxiv.176551675.52333626\/v1"},{"key":"e_1_3_2_1_23_1","volume-title":"Production Language Models. In The Thirteenth International Conference on Learning Representations.","author":"Nasr Milad","year":"2025","unstructured":"Milad Nasr, Javier Rando, Nicholas Carlini, Jonathan Hayase, Matthew Jagielski, A. Feder Cooper, Daphne Ippolito, Christopher A. Choquette-Choo, Florian Tram\u00e8r, and Katherine Lee. 2025. Scalable Extraction of Training Data from Aligned, Production Language Models. In The Thirteenth International Conference on Learning Representations."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","unstructured":"F\u00e1bio Perez and Ian Ribeiro. 2022. Ignore Previous Prompt: Attack Techniques For Language Models. arXiv:2211.09527 [cs] doi:10.48550\/arXiv.2211.09527","DOI":"10.48550\/arXiv.2211.09527"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","unstructured":"Javier Rando and Florian Tram\u00e8r. 2024. Universal Jailbreak Backdoors from Poisoned Human Feedback. arXiv:2311.14455 [cs] doi:10.48550\/arXiv.2311.14455","DOI":"10.48550\/arXiv.2311.14455"},{"key":"e_1_3_2_1_26_1","volume-title":"International Conference on Information Systems Security and Privacy.","author":"Sharafaldin Iman","unstructured":"Iman Sharafaldin, Arash Habibi Lashkari, and Ali A. Ghorbani. 2018. Toward Generating a New Intrusion Detection Dataset and Intrusion Traffic Characterization. In International Conference on Information Systems Security and Privacy."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2510.07192"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.wasec.2025.100187"},{"key":"e_1_3_2_1_29_1","volume-title":"Industroyer vs. Industroyer2: Evolution of the IEC 104 Component. Industroyer2: Evolution of the IEC 104 Component","author":"Tsaraias Giannis","year":"2022","unstructured":"Giannis Tsaraias and Ivan Speziale. 2022. Industroyer vs. Industroyer2: Evolution of the IEC 104 Component. Industroyer2: Evolution of the IEC 104 Component (2022)."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.104220"}],"event":{"name":"EuroSys '26: 21st European Conference on Computer Systems","location":"Edinburgh Scotland Uk","acronym":"EuroSec '26","sponsor":["SIGOPS ACM Special Interest Group on Operating Systems"]},"container-title":["Proceedings of the 19th European Workshop on Systems Security"],"original-title":[],"deposited":{"date-parts":[[2026,4,16]],"date-time":"2026-04-16T14:55:30Z","timestamp":1776351330000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3803525.3804991"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,26]]},"references-count":30,"alternative-id":["10.1145\/3803525.3804991","10.1145\/3803525"],"URL":"https:\/\/doi.org\/10.1145\/3803525.3804991","relation":{},"subject":[],"published":{"date-parts":[[2026,4,26]]},"assertion":[{"value":"2026-04-26","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}