{"id":"https://openalex.org/W4411551250","doi":"https://doi.org/10.1109/cscwd64889.2025.11033279","title":"DAB-LLM: Detection of Anomalies in API Call Behavior Based on Large Language Model","display_name":"DAB-LLM: Detection of Anomalies in API Call Behavior Based on Large Language Model","publication_year":2025,"publication_date":"2025-05-05","ids":{"openalex":"https://openalex.org/W4411551250","doi":"https://doi.org/10.1109/cscwd64889.2025.11033279"},"language":"en","primary_location":{"id":"doi:10.1109/cscwd64889.2025.11033279","is_oa":false,"landing_page_url":"https://doi.org/10.1109/cscwd64889.2025.11033279","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 28th International Conference on Computer Supported Cooperative Work in Design (CSCWD)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5101441626","display_name":"Yue Zhang","orcid":"https://orcid.org/0000-0003-2303-5313"},"institutions":[{"id":"https://openalex.org/I19820366","display_name":"Chinese Academy of Sciences","ror":"https://ror.org/034t30j35","country_code":"CN","type":"funder","lineage":["https://openalex.org/I19820366"]},{"id":"https://openalex.org/I4210156404","display_name":"Institute of Information Engineering","ror":"https://ror.org/04r53se39","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210156404"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Yue Zhang","raw_affiliation_strings":["Institute of Information Engineering, Chinese Academy of Sciences,Beijing,China"],"affiliations":[{"raw_affiliation_string":"Institute of Information Engineering, Chinese Academy of Sciences,Beijing,China","institution_ids":["https://openalex.org/I4210156404","https://openalex.org/I19820366"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5018457522","display_name":"Fangjiao Zhang","orcid":"https://orcid.org/0009-0005-5720-8253"},"institutions":[{"id":"https://openalex.org/I4210156404","display_name":"Institute of Information Engineering","ror":"https://ror.org/04r53se39","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210156404"]},{"id":"https://openalex.org/I19820366","display_name":"Chinese Academy of Sciences","ror":"https://ror.org/034t30j35","country_code":"CN","type":"funder","lineage":["https://openalex.org/I19820366"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Fangjiao Zhang","raw_affiliation_strings":["Institute of Information Engineering, Chinese Academy of Sciences,Beijing,China"],"affiliations":[{"raw_affiliation_string":"Institute of Information Engineering, Chinese Academy of Sciences,Beijing,China","institution_ids":["https://openalex.org/I4210156404","https://openalex.org/I19820366"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5036884975","display_name":"Bai-Sheng Liu","orcid":"https://orcid.org/0000-0002-5853-9290"},"institutions":[{"id":"https://openalex.org/I4210156404","display_name":"Institute of Information Engineering","ror":"https://ror.org/04r53se39","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210156404"]},{"id":"https://openalex.org/I19820366","display_name":"Chinese Academy of Sciences","ror":"https://ror.org/034t30j35","country_code":"CN","type":"funder","lineage":["https://openalex.org/I19820366"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Baihang Liu","raw_affiliation_strings":["Institute of Information Engineering, Chinese Academy of Sciences,Beijing,China"],"affiliations":[{"raw_affiliation_string":"Institute of Information Engineering, Chinese Academy of Sciences,Beijing,China","institution_ids":["https://openalex.org/I4210156404","https://openalex.org/I19820366"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5031113046","display_name":"Baoxu Liu","orcid":"https://orcid.org/0009-0006-9851-5548"},"institutions":[{"id":"https://openalex.org/I19820366","display_name":"Chinese Academy of Sciences","ror":"https://ror.org/034t30j35","country_code":"CN","type":"funder","lineage":["https://openalex.org/I19820366"]},{"id":"https://openalex.org/I4210156404","display_name":"Institute of Information Engineering","ror":"https://ror.org/04r53se39","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210156404"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Baoxu Liu","raw_affiliation_strings":["Institute of Information Engineering, Chinese Academy of Sciences,Beijing,China"],"affiliations":[{"raw_affiliation_string":"Institute of Information Engineering, Chinese Academy of Sciences,Beijing,China","institution_ids":["https://openalex.org/I4210156404","https://openalex.org/I19820366"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5037034567","display_name":"Quanhua Liu","orcid":"https://orcid.org/0000-0002-3616-351X"},"institutions":[{"id":"https://openalex.org/I4210156404","display_name":"Institute of Information Engineering","ror":"https://ror.org/04r53se39","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210156404"]},{"id":"https://openalex.org/I19820366","display_name":"Chinese Academy of Sciences","ror":"https://ror.org/034t30j35","country_code":"CN","type":"funder","lineage":["https://openalex.org/I19820366"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yuling Liu","raw_affiliation_strings":["Institute of Information Engineering, Chinese Academy of Sciences,Beijing,China"],"affiliations":[{"raw_affiliation_string":"Institute of Information Engineering, Chinese Academy of Sciences,Beijing,China","institution_ids":["https://openalex.org/I4210156404","https://openalex.org/I19820366"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5004834139","display_name":"Qixu Liu","orcid":"https://orcid.org/0000-0003-0895-9585"},"institutions":[{"id":"https://openalex.org/I19820366","display_name":"Chinese Academy of Sciences","ror":"https://ror.org/034t30j35","country_code":"CN","type":"funder","lineage":["https://openalex.org/I19820366"]},{"id":"https://openalex.org/I4210156404","display_name":"Institute of Information Engineering","ror":"https://ror.org/04r53se39","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210156404"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Qixu Liu","raw_affiliation_strings":["Institute of Information Engineering, Chinese Academy of Sciences,Beijing,China"],"affiliations":[{"raw_affiliation_string":"Institute of Information Engineering, Chinese Academy of Sciences,Beijing,China","institution_ids":["https://openalex.org/I4210156404","https://openalex.org/I19820366"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5101441626"],"corresponding_institution_ids":["https://openalex.org/I19820366","https://openalex.org/I4210156404"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.23672205,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"1925","last_page":"1930"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T12016","display_name":"Web Data Mining and Analysis","score":0.9661999940872192,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12016","display_name":"Web Data Mining and Analysis","score":0.9661999940872192,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9200999736785889,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7192444205284119},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.4966509938240051},{"id":"https://openalex.org/keywords/natural-language-processing","display_name":"Natural language processing","score":0.3508967161178589}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7192444205284119},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.4966509938240051},{"id":"https://openalex.org/C204321447","wikidata":"https://www.wikidata.org/wiki/Q30642","display_name":"Natural language processing","level":1,"score":0.3508967161178589}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/cscwd64889.2025.11033279","is_oa":false,"landing_page_url":"https://doi.org/10.1109/cscwd64889.2025.11033279","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 28th International Conference on Computer Supported Cooperative Work in Design (CSCWD)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":13,"referenced_works":["https://openalex.org/W2753669113","https://openalex.org/W2943383044","https://openalex.org/W2995082278","https://openalex.org/W3007234217","https://openalex.org/W3014441188","https://openalex.org/W3153103063","https://openalex.org/W3173859375","https://openalex.org/W4384834982","https://openalex.org/W4389520756","https://openalex.org/W6775681617","https://openalex.org/W6783780438","https://openalex.org/W6796581206","https://openalex.org/W6856800273"],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W2899084033","https://openalex.org/W2748952813","https://openalex.org/W2390279801","https://openalex.org/W4391913857","https://openalex.org/W2358668433","https://openalex.org/W4396701345","https://openalex.org/W2376932109","https://openalex.org/W2001405890","https://openalex.org/W4396696052"],"abstract_inverted_index":{"APIs":[0,43],"are":[1,65,71,90],"now":[2],"central":[3],"to":[4,21,33,40,49,74,80,119,164,168],"digital":[5],"transformation,":[6],"carrying":[7],"the":[8,68,166,213],"core":[9],"business":[10,57],"logic":[11,58],"and":[12,25,67,110,146,153,160,175,189,207],"sensitive":[13,26],"data":[14,27],"of":[15,62,114,171,197,212],"enterprises.":[16],"Attackers":[17],"can":[18,105],"gain":[19],"access":[20],"important":[22],"information":[23],"systems":[24],"by":[28],"attacking":[29],"APIs,":[30],"allowing":[31],"them":[32,78],"steal":[34],"high-value":[35],"data.":[36],"Besides":[37],"being":[38],"vulnerable":[39],"traditional":[41,86],"attacks,":[42],"also":[44],"face":[45],"unique":[46],"threats":[47],"tailored":[48],"their":[50],"characteristics,":[51],"such":[52,93],"as":[53],"attacks":[54,64],"targeting":[55],"API":[56,63,107,116,134,150,154,172,192,225],"threats.":[59],"This":[60],"type":[61],"complex,":[66],"attack":[69,187],"requests":[70],"very":[72],"similar":[73],"legitimate":[75],"traffic,":[76],"making":[77],"difficult":[79],"distinguish":[81],"from":[82],"benign":[83],"requests.":[84],"Therefore,":[85],"single-request":[87],"detection":[88,177],"methods":[89,148],"ineffective":[91],"against":[92],"complex":[94],"attacks.":[95],"By":[96],"employing":[97],"intelligent":[98],"context-aware":[99],"natural":[100],"language":[101],"processing":[102],"techniques,":[103],"we":[104,125],"understand":[106,170],"call":[108,117,135,151,155,173,226],"behavior":[109,118,174,227],"establish":[111],"a":[112,128],"baseline":[113],"normal":[115],"identify":[120],"anomalies.":[121],"In":[122],"this":[123],"paper,":[124],"propose":[126],"DAB-LLM,":[127],"model":[129,167,214,219],"for":[130,149],"Detecting":[131],"Anomalies":[132],"in":[133,185,191,203,224],"Behavior":[136],"based":[137],"on":[138],"Large":[139],"Language":[140],"Model.":[141],"Our":[142],"approach":[143],"utilizes":[144],"extraction":[145],"representation":[147],"chains":[152],"graphs,":[156],"prompt":[157],"optimization":[158],"algorithm,":[159],"LoRA":[161],"fine-tuning":[162],"technique":[163],"enable":[165],"deeply":[169],"enhance":[176],"capabilities.":[178],"Experimental":[179],"results":[180],"indicate":[181],"that":[182,216],"DAB-LLM":[183],"excels":[184],"detecting":[186],"behaviors":[188],"anomalies":[190],"calls,":[193],"achieving":[194],"an":[195],"f1-score":[196],"97.35%":[198],"along":[199],"with":[200],"significant":[201],"improvements":[202],"recall":[204],"rate,":[205],"accuracy":[206],"precision.":[208],"The":[209],"overall":[210],"performance":[211],"shows":[215],"our":[217],"proposed":[218],"significantly":[220],"outperforms":[221],"other":[222],"models":[223],"anomaly":[228],"detection.":[229]},"counts_by_year":[],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
