dorsal/arxiv
View SchemaAPT-MCL: An Adaptive APT Detection System Based on Multi-View Collaborative Provenance Graph Learning
| Authors | Mingqi Lv, Shanshan Zhang, Haiwen Liu, Tieming Chen, Tiantian Zhu |
|---|---|
| Categories | |
| ArXiv ID | 2601.08328vv1 |
| URL | https://arxiv.org/abs/2601.08328 |
| License | http://arxiv.org/licenses/nonexclusive-distrib/1.0/ |
Abstract
Advanced persistent threats (APTs) are stealthy and multi-stage, making single-point defenses (e.g., malware- or traffic-based detectors) ill-suited to capture long-range and cross-entity attack semantics. Provenance-graph analysis has become a prominent approach for APT detection. However, its practical deployment is hampered by (i) the scarcity of APT samples, (ii) the cost and difficulty of fine-grained APT sample labeling, and (iii) the diversity of attack tactics and techniques. Aiming at these problems, this paper proposes APT-MCL, an intelligent APT detection system based on Multi-view Collaborative provenance graph Learning. It adopts an unsupervised learning strategy to discover APT attacks at the node level via anomaly detection. After that, it creates multiple anomaly detection sub-models based on multi-view features and integrates them within a collaborative learning framework to adapt to diverse attack scenarios. Extensive experiments on three real-world APT datasets validate the approach: (i) multi-view features improve cross-scenario generalization, and (ii) co-training substantially boosts node-level detection under label scarcity, enabling practical deployment on diverse attack scenarios.
{
"annotation_id": "0039469a-5f0a-48a6-9ddb-98413879ceed",
"date_created": "2026-02-17T05:53:15.166000Z",
"date_modified": "2026-02-17T05:53:15.166000Z",
"file_hash": "8c2c60faf21e0448d70f9a60827b8961f30a0349e3346cd45d79b1d6195f0e89",
"private": false,
"record": {
"abstract": "Advanced persistent threats (APTs) are stealthy and multi-stage, making single-point defenses (e.g., malware- or traffic-based detectors) ill-suited to capture long-range and cross-entity attack semantics. Provenance-graph analysis has become a prominent approach for APT detection. However, its practical deployment is hampered by (i) the scarcity of APT samples, (ii) the cost and difficulty of fine-grained APT sample labeling, and (iii) the diversity of attack tactics and techniques. Aiming at these problems, this paper proposes APT-MCL, an intelligent APT detection system based on Multi-view Collaborative provenance graph Learning. It adopts an unsupervised learning strategy to discover APT attacks at the node level via anomaly detection. After that, it creates multiple anomaly detection sub-models based on multi-view features and integrates them within a collaborative learning framework to adapt to diverse attack scenarios. Extensive experiments on three real-world APT datasets validate the approach: (i) multi-view features improve cross-scenario generalization, and (ii) co-training substantially boosts node-level detection under label scarcity, enabling practical deployment on diverse attack scenarios.",
"arxiv_id": "2601.08328",
"authors": [
"Mingqi Lv",
"Shanshan Zhang",
"Haiwen Liu",
"Tieming Chen",
"Tiantian Zhu"
],
"categories": [
"cs.CR"
],
"license": "http://arxiv.org/licenses/nonexclusive-distrib/1.0/",
"title": "APT-MCL: An Adaptive APT Detection System Based on Multi-View Collaborative Provenance Graph Learning",
"url": "https://arxiv.org/abs/2601.08328",
"version": "v1"
},
"schema_id": "dorsal/arxiv",
"source": {
"execution_id": "d70544ff-6df1-4a98-869c-3c7e41898d43",
"id": "arXiv Dataset",
"type": "Model",
"variant": "snapshot-2026-01-17",
"version": "0.1.0"
},
"user_id": 1000002
}