| [1]Inam M A, Chen Y, Goyal A, et al. Sok: History is a vast early warning system: Auditing the provenance of system intrusions[C] Proc of the 2023 IEEE Symp on Security and Privacy (SP). Piscataway, NJ: IEEE, 2023: 26202638[2]陈良臣, 傅德印, 刘宝旭, 等. 基于机器学习的网络未知攻击检测方法研究综述[J]. 信息安全研究, 2025, 11(9): 807813[3]张博, 崔佳巍, 屈肃, 等. 高级持续性威胁及其重构研究进展与挑战[J]. 信息安全研究, 2021, 7(6): 512519[4]Zipperle M, Gottwalt F, Chang E, et al. Provenancebased intrusion detection systems: A survey[J]. ACM Computer Surveys, 2022, 55(7): 136[5]Hossain M N, Milajerdi S M, Wang Junao, et al. SLEUTH: Realtime attack scenario reconstruction from COTS audit data[C] Proc of the 26th USENIX Security Symposium. Berkeley, CA: USENIX Association, 2017: 487504[6]Zengy Jun, Wang Xiang, Liu Jiahao, et al. Shadewatcher: Recommendationguided cyber threat analysis using system audit records[C] Proc of the 2022 IEEE Symp on Security and Privacy (SP). Piscataway, NJ: IEEE, 2022: 489506[7]Liu Fucheng, Wen Yu, Zhang Dongxue, et al. Log2Vec: A heterogeneous graph embedding based approach for detecting cyber threats within enterprise[C] Proc of the 2019 ACM SIGSAC Conf on Computer and Communications Security (CCS). New York: ACM, 2019: 17771794[8]Wang Su, Wang Zhiliang, Zhou Tao, et al. ThreaTrace: Detecting and tracing hostbased threats in node level through provenance graph learning[J]. IEEE Trans on Information Forensics and Security, 2022, 17(12): 39723987[9]Rehman M U, Ahmadi H, Hassan W U. FLASH: A comprehensive approach to intrusion detection via provenance graph representation learning[C] Proc of the 2024 IEEE Symp on Security and Privacy (SP). Piscataway, NJ: IEEE, 2024: 139156[10]Jia Zian, Xiong Yun, Nan Yuhong, et al. MAGIC: Detecting advanced persistent threats via masked graph representation learning[C] Proc of the 33rd USENIX Security Symposium (USENIX Security 24). Berkeley, CA: USENIX Association, 2024: 51975214[11]Liu Yixin, Jin Ming, Pan Shirui, et al. Graph selfsupervised learning: A survey[J]. IEEE Trans on Knowledge and Data Engineering, 2022, 35(6): 58795900[12]Han Yuehui, Hui Le, Jiang Haobo, et al. Generative subgraph contrast for selfsupervised graph representation learning[C] Proc of the European Conf on Computer Vision (ECCV). Berlin: Springer, 2022: 91107[13]Tang Huimin, Shi Yong, Dong Peiwu. Public blockchain evaluation using entropy and TOPSIS[J]. Expert Systems with Applications, 2019, 117(3): 204210[14]Velickovic P, Cucurull G, Casanova A, et al. Graph attention networks[J]. arXiv preprint, arXiv:1710.10903, 2017[15]Peyré G, Cuturi M. Computational optimal transport: With applications to data science[J]. Foundations and Trends in Machine Learning, 2019, 11(56): 355607[16]Peyré G, Cuturi M, Solomon J, et al. Gromovwasserstein averaging of kernel and distance matrices[C] Proc of the Int Conf on Machine Learning. New York: PMLR, 2016: 26642672[17]Chen Tianqi, Guestrin C. XGBoost: A scalable tree boosting system[C] Proc of the 22nd ACM SIGKDD Int Conf on Knowledge Discovery and Data Mining (KDD’16). New York: ACM, 2016: 785794[18]Defense Advanced Research Projects Agency(DARPA). Transparent computing engagement 3 data release[EBOL]. [20251126]. https:github.com darpai2oTransparentComputingtreemaster |