DUPIN: Attack Learning Is Still Needed! Demonstrating Few-Shot after Unsupervised Pretraining Is A Nimble Forensics Learner
Chanwoo Bae, Hailun Ding, Shiqing Ma, Xiangyu Zhang
Abstract
We propose a novel approach to learning-based attack forensics called DUPIN. DUPIN performs unsupervised pre-training on an enormous amount of audit events in the form of provenance graphs. It then proceeds to a few-shot learning stage, leveraging a small number of labeled attack examples to fine-tune its detection capabilities. We pretrain DUPIN on up to 38 - 52 days of audit logs (7.3TB total) and evaluate it against various baselines on 25 APT campaigns across four different data sources, facilitating the scalable evaluation.
Create a lesson
Related papers
Capability-Gated Language Models: Security Composes, Utility Does Not
Patrikas Vanagas, Augustas Mačijauskas, Laurynas Lopata
Don't Trust the Code, Check Its Effects: Runtime Refinement for Regenerated Systems Code Under an Adversarial Generator
Jinhao Hu, Ashvin Goel, Laurent Bindschaedler
NeuroPriv: Adversarial Representation Learning for Privacy in Wearable EEG Systems
Sarmistha Sarna Gomasta, Bhawana Chhaglani, Prashant Shenoy
OreProof: Verifiable Provenance with Limited Disclosure for Critical-Minerals Supply Chains Using Zero-Knowledge Proofs
Oleksandr Hrabar, Hossein Arshadi Soufiani, Henry M. Kim et al.
Workload Identification with Physical Side Channels for AI Governance
Simone Gargiulo, Gabriel Kulp
Delegation Without Trust: An Empirical Gap Analysis of Identity, Authorization, and Runtime Governance in Multi-Agent LLM Systems
Panduranga Sai Varma Dantuluri, Jyotirmoy Sundi