Attributing Stealth Cyberattacks via Temporal Probabilistic Graph Neural Networks

Wei Liu, Peng Gao, Haotian Zhang, Ke Li, Weiyong Yang, Xingshen Wei, Jiwu Shu · Journal of Computer Information Systems · 2025

Stealth cyberattacks pose a significant threat to critical infrastructures, exposing critical limitations in conventional detection techniques. Existing methods struggle to handle the scarcity of real-world attack data, fail to model the complexity and dynamic evolution of attack patterns effectively, and often lack transparency, reducing their reliability in production environments. To address these limitations, this paper introduces SilentCatchR, a new attack attribution framework that advances the state of the art in three key ways. First, it employs a perturbation mechanism to enrich rare attack instances, improving the diversity and robustness of training data. Second, it integrates these enriched instances into network flow graphs and applies a transformer-based encoder-decoder model to capture the intricate, evolving stealth attack patterns. Finally, SilentCatchR incorporates a probabilistic graphical model to identify the most influential activities contributing to the attack, significantly enhancing interpretability. The broader implications of this work include improved resilience of critical infrastructure systems and increased confidence in AI-based security solutions. Experimental results show that the proposed method improves detection accuracy by up to 9.6% and 8.0% and enhances interpretability by up to 28.0% and 42.7% on the CERT and ATLAS datasets, respectively, compared to existing state-of-the-art approaches, paving the way for more secure and transparent cyber defense systems.

Read the paper · More papers on PaperTik