Where the Numbers Come From: Auditing Evaluation in Provenance-Based Intrusion Detection
cs.CR
Submitted: 2026-09-27
Updated: 2026-09-27
Code: https://github.com/FiveDirections/OpTC-data
Terminology
Sources
- OCR-APT: Reconstructing APT Stories from Audit Logs using Subgraph Anomaly Detection and LLMs
- PIDSMaker: Building and Evaluating Provenance-based Intrusion Detection Systems
- How Benchmarks and Evaluation Protocols Shape Conclusions in Provenance-Based Intrusion Detection
- ATLASv2: ATLAS Attack Engagements, Version 2
- Temporal Graph Networks for Deep Learning on Dynamic Graphs
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs