{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,4]],"date-time":"2026-03-04T07:53:14Z","timestamp":1772610794306,"version":"3.50.1"},"reference-count":36,"publisher":"MDPI AG","issue":"3","license":[{"start":{"date-parts":[[2026,3,2]],"date-time":"2026-03-02T00:00:00Z","timestamp":1772409600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100016360","name":"Zhongyuan University of Technology","doi-asserted-by":"crossref","award":["GG202417"],"award-info":[{"award-number":["GG202417"]}],"id":[{"id":"10.13039\/501100016360","id-type":"DOI","asserted-by":"crossref"}]},{"name":"Key Research and Development Program of Henan","award":["251111212000"],"award-info":[{"award-number":["251111212000"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Information"],"abstract":"<jats:p>Advanced Persistent Threats (APTs) are characterized by stealth, infrequency, and long cycles, evading traditional security to endanger critical infrastructure. Complex semantic links between system entities can be accurately modeled using representation learning techniques based on heterogeneous provenance graphs, providing a novel method for uncovering hidden APT attack chains. However, in large-scale practical implementations, this approach still faces three major challenges: combinatorial explosion of long-range meta-paths, loss of semantic evolution during graph compression, and high computational overhead for dynamic environments. To address these, we propose APT-LMSPS, a detection system leveraging Long-Range Meta-path Progressive Sampling Search (LMSPS). The LMSPS algorithm uses dynamic pruning and semantic contribution assessment to convert meta-path combination explosion into constant-scale computation, accurately modeling long-range dependencies. Second, the Maintaining Global Semantics (MGS) approach intelligently filters events by tracking node semantic state changes, achieving an 8:1 compression ratio while preserving over 90% of critical pathways\u2019 semantic integrity. Lastly, the meta-path encoding database uses a caching approach to avoid repeated encoding, doubling encoding effectiveness and enabling efficient, accurate, system-wide APT detection in large-scale scenarios. Evaluated on DARPA, StreamSpot, and ATLAS datasets, APT-LMSPS maintains competitive accuracy (F1-score \u2265 0.98) and improves long-range processing efficiency by an order of magnitude over baselines.<\/jats:p>","DOI":"10.3390\/info17030245","type":"journal-article","created":{"date-parts":[[2026,3,2]],"date-time":"2026-03-02T14:06:56Z","timestamp":1772460416000},"page":"245","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["APT-LMSPS: An Efficient APT Detection System via Long-Range Meta-Path Progressive Sampling Search"],"prefix":"10.3390","volume":"17","author":[{"given":"Jizhao","family":"Liu","sequence":"first","affiliation":[{"name":"College of Computer and Artificial Intelligence, Zhongyuan University of Technology, Zhengzhou 451191, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zitao","family":"Zhang","sequence":"additional","affiliation":[{"name":"College of Computer and Artificial Intelligence, Zhongyuan University of Technology, Zhengzhou 451191, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shuqin","family":"Zhang","sequence":"additional","affiliation":[{"name":"College of Computer and Artificial Intelligence, Zhongyuan University of Technology, Zhengzhou 451191, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fangfang","family":"Shan","sequence":"additional","affiliation":[{"name":"College of Computer and Artificial Intelligence, Zhongyuan University of Technology, Zhengzhou 451191, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jun","family":"Li","sequence":"additional","affiliation":[{"name":"College of Computer and Artificial Intelligence, Zhongyuan University of Technology, Zhengzhou 451191, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2026,3,2]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"104194","DOI":"10.1016\/j.cose.2024.104194","article-title":"Hyper attack graph: Constructing a hypergraph for cyber threat intelligence analysis","volume":"149","author":"Jia","year":"2025","journal-title":"Comput. Secur."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"1715","DOI":"10.1109\/TNSM.2024.3358730","article-title":"LogFiT: Log anomaly detection using fine-tuned language models","volume":"21","author":"Almodovar","year":"2024","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"104159","DOI":"10.1016\/j.cose.2024.104159","article-title":"Provenance-based APT campaigns detection via masked graph representation learning","volume":"148","author":"Ren","year":"2025","journal-title":"Comput. Secur."},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Han, X., Pasquier, T., Bates, A., Mickens, J., and Seltzer, M. (2020). Unicorn: Runtime provenance-based detector for advanced persistent threats. arXiv.","DOI":"10.14722\/ndss.2020.24046"},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Wei, R., Cai, L., Zhao, L., Yu, A., and Meng, D. (2021). Deephunter: A graph neural network based approach for robust cyber threat hunting. Proceedings of the International Conference on Security and Privacy in Communication Systems, Springer.","DOI":"10.1007\/978-3-030-90019-9_1"},{"key":"ref_6","unstructured":"Kapoor, M., Melton, J., Ridenhour, M., Sriram, M., Moyer, T., and Krishnan, S. (2022). Flurry: A Fast Framework for Reproducible Multi-layered Provenance Graph Representation Learning. arXiv."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"51","DOI":"10.1186\/s42400-024-00240-w","article-title":"ProcSAGE: An efficient host threat detection method based on graph representation learning","volume":"7","author":"Xu","year":"2024","journal-title":"Cybersecurity"},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"3957","DOI":"10.1109\/TDSC.2022.3221789","article-title":"Advanced persistent threat detection using data provenance and metric learning","volume":"20","author":"Akbar","year":"2022","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Huang, Z., Gu, Y., and Zhao, Q. (2022, January 4\u20136). One-class directed heterogeneous graph neural network for intrusion detection. Proceedings of the 2022 6th International Conference on Innovation in Artificial Intelligence, Guangzhou, China.","DOI":"10.1145\/3529466.3529480"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"103862","DOI":"10.1016\/j.cose.2024.103862","article-title":"Bon-APT: Detection, attribution, and explainability of APT malware using temporal segmentation of API calls","volume":"142","author":"Shenderovitz","year":"2024","journal-title":"Comput. Secur."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Cheng, Z., Lv, Q., Liang, J., Wang, Y., Sun, D., Pasquier, T., and Han, X. (2024). Kairos: Practical intrusion detection and investigation using whole-system provenance. Proceedings of the 2024 IEEE Symposium on Security and Privacy (SP), IEEE.","DOI":"10.1109\/SP54263.2024.00005"},{"key":"ref_12","unstructured":"Ferrini, F., Longa, A., Passerini, A., and Jaeger, M. (2024). Meta-path learning for multi-relational graph neural networks. Proceedings of the Learning on Graphs Conference, PMLR."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"104359","DOI":"10.1016\/j.cose.2025.104359","article-title":"PDCleaner: A multi-view collaborative data compression method for provenance graph-based APT detection systems","volume":"152","author":"Jin","year":"2025","journal-title":"Comput. Secur."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Li, L., and Chen, W. (2024). ConGraph: Advanced persistent threat detection method based on provenance graph combined with process context in cyber-physical system environment. Electronics, 13.","DOI":"10.3390\/electronics13050945"},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"125877","DOI":"10.1016\/j.eswa.2024.125877","article-title":"A dynamic provenance graph-based detector for advanced persistent threats","volume":"265","author":"Wang","year":"2025","journal-title":"Expert Syst. Appl."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Rehman, M.U., Ahmadi, H., and Hassan, W.U. (2024). Flash: A comprehensive approach to intrusion detection via provenance graph representation learning. Proceedings of the 2024 IEEE Symposium on Security and Privacy (SP), IEEE.","DOI":"10.1109\/SP54263.2024.00139"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Anjum, M.M., Iqbal, S., and Hamelin, B. (2022, January 25\u201329). ANUBIS: A provenance graph-based framework for advanced persistent threat detection. Proceedings of the 37th ACM\/SIGAPP Symposium on Applied Computing, Virtual.","DOI":"10.1145\/3477314.3507097"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3559768","article-title":"APTHunter: Detecting advanced persistent threats in early stages","volume":"4","author":"Mahmoud","year":"2023","journal-title":"Digit. Threat. Res. Pract."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Qiao, W., Feng, Y., Li, T., Ma, Z., Shen, Y., Ma, J., and Liu, Y. (2024). Slot: Provenance-Driven APT Detection through Graph Reinforcement Learning. arXiv.","DOI":"10.1145\/3719027.3744788"},{"key":"ref_20","unstructured":"Jia, Z., Xiong, Y., Nan, Y., Zhang, Y., Zhao, J., and Wen, M. (2024, January 14\u201316). {MAGIC}: Detecting advanced persistent threats via masked graph representation learning. Proceedings of the 33rd USENIX Security Symposium (USENIX Security 24), Philadelphia, PA, USA."},{"key":"ref_21","unstructured":"Jiang, W., Chai, T., Liu, H., Wang, K., and Zhang, H. (2025). TFLAG: Towards Practical APT Detection via Deviation-Aware Learning on Temporal Provenance Graph. arXiv."},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Wu, Q., and Xiang, Y. (2024). Improving the Accuracy of Anomaly Detection from System Audit Logs via Heterogeneous Provenance Graphs. Proceedings of the 2024 International Conference on Networking and Network Applications (NaNA), IEEE.","DOI":"10.1109\/NaNA63151.2024.00093"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Yan, N., Wen, Y., Chen, L., Wu, Y., Zhang, B., Wang, Z., and Meng, D. (2022). Deepro: Provenance-based APT campaigns detection via GNN. Proceedings of the 2022 IEEE International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), IEEE.","DOI":"10.1109\/TrustCom56396.2022.00106"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"5257","DOI":"10.1109\/TIFS.2024.3396390","article-title":"Megr-apt: A memory-efficient apt hunting system based on attack representation learning","volume":"19","author":"Aly","year":"2024","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Bhattarai, B., and Huang, H.H. (2023). Prov2vec: Learning Provenance Graph Representation for Unsupervised APT Detection. arXiv.","DOI":"10.1145\/3664476.3664494"},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Chen, T., Dong, C., Lv, M., Song, Q., Liu, H., Zhu, T., Xu, K., Chen, L., Ji, S., and Fan, Y. (2022). Apt-kgl: An intelligent apt detection system based on threat knowledge and heterogeneous provenance graph learning. IEEE Trans. Dependable Secur. Comput., 1\u201315.","DOI":"10.1109\/TDSC.2022.3229472"},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Lv, M., Gao, H., Qiu, X., Chen, T., Zhu, T., Chen, J., and Ji, S. (2024, January 14\u201318). TREC: APT tactic\/technique recognition via few-shot provenance subgraph learning. Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security, Salt Lake City, UT, USA.","DOI":"10.1145\/3658644.3690221"},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Chang, H., Rong, Y., Xu, T., Huang, W., Zhang, H., Cui, P., Zhu, W., and Huang, J. (2020, January 9\u201311). A restricted black-box adversarial framework towards attacking graph embedding models. Proceedings of the AAAI Conference on Artificial Intelligence, New York, NY, USA.","DOI":"10.1609\/aaai.v34i04.5741"},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Khoury, J., Klisura, \u0110., Zanddizari, H., Parra, G.D.L.T., Najafirad, P., and Bou-Harb, E. (2024). Jbeil: Temporal graph-based inductive learning to infer lateral movement in evolving enterprise networks. Proceedings of the 2024 IEEE Symposium on Security and Privacy (SP), IEEE.","DOI":"10.1109\/SP54263.2024.00009"},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"104016","DOI":"10.1016\/j.cose.2024.104016","article-title":"A survey of large language models for cyber threat detection","volume":"145","author":"Chen","year":"2024","journal-title":"Comput. Secur."},{"key":"ref_31","first-page":"44240","article-title":"Long-range meta-path search on large-scale heterogeneous graphs","volume":"37","author":"Li","year":"2024","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Manzoor, E., Milajerdi, S.M., and Akoglu, L. (2016, January 13\u201317). Fast memory-efficient anomaly detection in streaming heterogeneous graphs. Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, San Francisco, CA, USA.","DOI":"10.1145\/2939672.2939783"},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3539605","article-title":"Provenance-based intrusion detection systems: A survey","volume":"55","author":"Zipperle","year":"2022","journal-title":"ACM Comput. Surv."},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Huang, Z., and Wang, P. (2025). RAS-GNN: Reconstructing APT Attack Scenario Using Graph Neural Network. Proceedings of the ICASSP 2025\u20132025 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP), IEEE.","DOI":"10.1109\/ICASSP49660.2025.10890506"},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"104263","DOI":"10.1016\/j.cose.2024.104263","article-title":"AJSAGE: A intrusion detection scheme based on Jump-Knowledge Connection To GraphSAGE","volume":"150","author":"Xu","year":"2025","journal-title":"Comput. Secur."},{"key":"ref_36","unstructured":"Alsaheel, A., Nan, Y., Ma, S., Yu, L., Walkup, G., Celik, Z.B., Zhang, X., and Xu, D. (2021, January 11\u201313). {ATLAS}: A sequence-based learning approach for attack investigation. Proceedings of the 30th USENIX Security Symposium (USENIX Security 21), Virtual. Available online: https:\/\/www.usenix.org\/conference\/usenixsecurity21\/presentation\/alsaheel."}],"container-title":["Information"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2078-2489\/17\/3\/245\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,4]],"date-time":"2026-03-04T05:12:45Z","timestamp":1772601165000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2078-2489\/17\/3\/245"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,3,2]]},"references-count":36,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2026,3]]}},"alternative-id":["info17030245"],"URL":"https:\/\/doi.org\/10.3390\/info17030245","relation":{},"ISSN":["2078-2489"],"issn-type":[{"value":"2078-2489","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,3,2]]}}}