{"id":"https://openalex.org/W7125944830","doi":"https://doi.org/10.1109/smc58881.2025.11343010","title":"NAHID: Node-Level Host Intrusion Detection Based on Provenance Graph","display_name":"NAHID: Node-Level Host Intrusion Detection Based on Provenance Graph","publication_year":2025,"publication_date":"2025-10-05","ids":{"openalex":"https://openalex.org/W7125944830","doi":"https://doi.org/10.1109/smc58881.2025.11343010"},"language":null,"primary_location":{"id":"doi:10.1109/smc58881.2025.11343010","is_oa":false,"landing_page_url":"https://doi.org/10.1109/smc58881.2025.11343010","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE International Conference on Systems, Man, and Cybernetics (SMC)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5061949166","display_name":"Wentao Li","orcid":"https://orcid.org/0000-0002-4522-2163"},"institutions":[{"id":"https://openalex.org/I19820366","display_name":"Chinese Academy of Sciences","ror":"https://ror.org/034t30j35","country_code":"CN","type":"government","lineage":["https://openalex.org/I19820366"]},{"id":"https://openalex.org/I4210156404","display_name":"Institute of Information Engineering","ror":"https://ror.org/04r53se39","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210156404"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Wentao Li","raw_affiliation_strings":["Institute of Information Engineering,Chinese Academy of Sciences,Beijing,China"],"affiliations":[{"raw_affiliation_string":"Institute of Information Engineering,Chinese Academy of Sciences,Beijing,China","institution_ids":["https://openalex.org/I4210156404","https://openalex.org/I19820366"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101315622","display_name":"Xingyuan Wei","orcid":null},"institutions":[{"id":"https://openalex.org/I19820366","display_name":"Chinese Academy of Sciences","ror":"https://ror.org/034t30j35","country_code":"CN","type":"government","lineage":["https://openalex.org/I19820366"]},{"id":"https://openalex.org/I4210156404","display_name":"Institute of Information Engineering","ror":"https://ror.org/04r53se39","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210156404"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xingyuan Wei","raw_affiliation_strings":["Institute of Information Engineering,Chinese Academy of Sciences,Beijing,China"],"affiliations":[{"raw_affiliation_string":"Institute of Information Engineering,Chinese Academy of Sciences,Beijing,China","institution_ids":["https://openalex.org/I4210156404","https://openalex.org/I19820366"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101898339","display_name":"Qiujian Lv","orcid":"https://orcid.org/0000-0003-1031-185X"},"institutions":[{"id":"https://openalex.org/I19820366","display_name":"Chinese Academy of Sciences","ror":"https://ror.org/034t30j35","country_code":"CN","type":"government","lineage":["https://openalex.org/I19820366"]},{"id":"https://openalex.org/I4210156404","display_name":"Institute of Information Engineering","ror":"https://ror.org/04r53se39","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210156404"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Qiujian Lv","raw_affiliation_strings":["Institute of Information Engineering,Chinese Academy of Sciences,Beijing,China"],"affiliations":[{"raw_affiliation_string":"Institute of Information Engineering,Chinese Academy of Sciences,Beijing,China","institution_ids":["https://openalex.org/I4210156404","https://openalex.org/I19820366"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5124145097","display_name":"Yan Wang","orcid":null},"institutions":[{"id":"https://openalex.org/I19820366","display_name":"Chinese Academy of Sciences","ror":"https://ror.org/034t30j35","country_code":"CN","type":"government","lineage":["https://openalex.org/I19820366"]},{"id":"https://openalex.org/I4210156404","display_name":"Institute of Information Engineering","ror":"https://ror.org/04r53se39","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210156404"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yan Wang","raw_affiliation_strings":["Institute of Information Engineering,Chinese Academy of Sciences,Beijing,China"],"affiliations":[{"raw_affiliation_string":"Institute of Information Engineering,Chinese Academy of Sciences,Beijing,China","institution_ids":["https://openalex.org/I4210156404","https://openalex.org/I19820366"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5124130202","display_name":"Ning Li","orcid":null},"institutions":[{"id":"https://openalex.org/I19820366","display_name":"Chinese Academy of Sciences","ror":"https://ror.org/034t30j35","country_code":"CN","type":"government","lineage":["https://openalex.org/I19820366"]},{"id":"https://openalex.org/I4210156404","display_name":"Institute of Information Engineering","ror":"https://ror.org/04r53se39","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210156404"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Ning Li","raw_affiliation_strings":["Institute of Information Engineering,Chinese Academy of Sciences,Beijing,China"],"affiliations":[{"raw_affiliation_string":"Institute of Information Engineering,Chinese Academy of Sciences,Beijing,China","institution_ids":["https://openalex.org/I4210156404","https://openalex.org/I19820366"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5066842835","display_name":"Ziyang Yu","orcid":"https://orcid.org/0000-0002-6656-3741"},"institutions":[{"id":"https://openalex.org/I19820366","display_name":"Chinese Academy of Sciences","ror":"https://ror.org/034t30j35","country_code":"CN","type":"government","lineage":["https://openalex.org/I19820366"]},{"id":"https://openalex.org/I4210156404","display_name":"Institute of Information Engineering","ror":"https://ror.org/04r53se39","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210156404"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Ziyang Yu","raw_affiliation_strings":["Institute of Information Engineering,Chinese Academy of Sciences,Beijing,China"],"affiliations":[{"raw_affiliation_string":"Institute of Information Engineering,Chinese Academy of Sciences,Beijing,China","institution_ids":["https://openalex.org/I4210156404","https://openalex.org/I19820366"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5061949166"],"corresponding_institution_ids":["https://openalex.org/I19820366","https://openalex.org/I4210156404"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.74632875,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"2372","last_page":"2379"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.26600000262260437,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.26600000262260437,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12127","display_name":"Software System Performance and Reliability","score":0.17829999327659607,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11986","display_name":"Scientific Computing and Data Management","score":0.08820000290870667,"subfield":{"id":"https://openalex.org/subfields/1802","display_name":"Information Systems and Management"},"field":{"id":"https://openalex.org/fields/18","display_name":"Decision Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/intrusion-detection-system","display_name":"Intrusion detection system","score":0.6915000081062317},{"id":"https://openalex.org/keywords/false-positive-paradox","display_name":"False positive paradox","score":0.6276000142097473},{"id":"https://openalex.org/keywords/host","display_name":"Host (biology)","score":0.6047000288963318},{"id":"https://openalex.org/keywords/granularity","display_name":"Granularity","score":0.5160999894142151},{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.45590001344680786},{"id":"https://openalex.org/keywords/graph","display_name":"Graph","score":0.43540000915527344},{"id":"https://openalex.org/keywords/construct","display_name":"Construct (python library)","score":0.42570000886917114}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7893999814987183},{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.6915000081062317},{"id":"https://openalex.org/C64869954","wikidata":"https://www.wikidata.org/wiki/Q1859747","display_name":"False positive paradox","level":2,"score":0.6276000142097473},{"id":"https://openalex.org/C126831891","wikidata":"https://www.wikidata.org/wiki/Q221673","display_name":"Host (biology)","level":2,"score":0.6047000288963318},{"id":"https://openalex.org/C177774035","wikidata":"https://www.wikidata.org/wiki/Q1246948","display_name":"Granularity","level":2,"score":0.5160999894142151},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.4918999969959259},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.45590001344680786},{"id":"https://openalex.org/C132525143","wikidata":"https://www.wikidata.org/wiki/Q141488","display_name":"Graph","level":2,"score":0.43540000915527344},{"id":"https://openalex.org/C2780801425","wikidata":"https://www.wikidata.org/wiki/Q5164392","display_name":"Construct (python library)","level":2,"score":0.42570000886917114},{"id":"https://openalex.org/C137524506","wikidata":"https://www.wikidata.org/wiki/Q2247688","display_name":"Anomaly-based intrusion detection system","level":3,"score":0.3903000056743622},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.3878999948501587},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.374099999666214},{"id":"https://openalex.org/C132964779","wikidata":"https://www.wikidata.org/wiki/Q2110223","display_name":"Raw data","level":2,"score":0.357699990272522},{"id":"https://openalex.org/C2777212361","wikidata":"https://www.wikidata.org/wiki/Q5127848","display_name":"Class (philosophy)","level":2,"score":0.3075999915599823},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.30140000581741333},{"id":"https://openalex.org/C14036430","wikidata":"https://www.wikidata.org/wiki/Q3736076","display_name":"Function (biology)","level":2,"score":0.29499998688697815},{"id":"https://openalex.org/C2776359362","wikidata":"https://www.wikidata.org/wiki/Q2145286","display_name":"Representation (politics)","level":3,"score":0.2874999940395355},{"id":"https://openalex.org/C2778579508","wikidata":"https://www.wikidata.org/wiki/Q722192","display_name":"System call","level":2,"score":0.28029999136924744},{"id":"https://openalex.org/C2780451532","wikidata":"https://www.wikidata.org/wiki/Q759676","display_name":"Task (project management)","level":2,"score":0.263700008392334},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.25290000438690186}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/smc58881.2025.11343010","is_oa":false,"landing_page_url":"https://doi.org/10.1109/smc58881.2025.11343010","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE International Conference on Systems, Man, and Cybernetics (SMC)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16","score":0.6418055891990662}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":27,"referenced_works":["https://openalex.org/W2284900416","https://openalex.org/W2790557990","https://openalex.org/W2962703433","https://openalex.org/W2963691377","https://openalex.org/W2965683718","https://openalex.org/W2978956219","https://openalex.org/W2986944522","https://openalex.org/W2990225485","https://openalex.org/W2998010923","https://openalex.org/W2998038410","https://openalex.org/W3006711782","https://openalex.org/W3010522687","https://openalex.org/W3015650867","https://openalex.org/W3126165507","https://openalex.org/W3187966659","https://openalex.org/W3208773001","https://openalex.org/W3212868562","https://openalex.org/W4205704613","https://openalex.org/W4214699222","https://openalex.org/W4220692398","https://openalex.org/W4288057803","https://openalex.org/W4324007191","https://openalex.org/W4324134989","https://openalex.org/W4376480418","https://openalex.org/W4399451239","https://openalex.org/W4402265033","https://openalex.org/W4402288718"],"related_works":[],"abstract_inverted_index":{"Attacks,":[0],"including":[1],"program":[2],"exploits,":[3],"malware":[4],"implantation,":[5],"and":[6,127,132,169,219,238],"targeted":[7],"intrusions":[8],"such":[9],"as":[10,179],"advanced":[11],"persistent":[12],"threats":[13],"(APTs),":[14],"are":[15],"increasingly":[16],"used":[17],"by":[18,120],"modern":[19],"adversaries.":[20],"Recently,":[21],"provenance-based":[22],"host":[23,104,137,193,226],"intrusion":[24,82,105,227],"detection":[25,106,174,228],"systems":[26],"(HIDSs)":[27],"have":[28],"gained":[29],"significant":[30],"attention":[31],"due":[32],"to":[33,139,207],"their":[34,46,128],"superior":[35],"performance":[36],"in":[37,60,88,192],"detecting":[38],"complex":[39,166],"attacks":[40],"at":[41],"the":[42,56,65,147,187,204],"system":[43,70],"level.":[44],"Despite":[45],"potential,":[47],"many":[48],"existing":[49],"approaches":[50,76],"either":[51],"do":[52],"not":[53,111],"fully":[54],"utilize":[55],"rich":[57],"information":[58],"available":[59],"raw":[61,136],"data":[62,138],"or":[63,92],"overlook":[64],"evolving":[66],"topological":[67],"structure":[68],"of":[69,115,150],"behavior":[71,149,171],"over":[72,152],"time.":[73],"Furthermore,":[74],"some":[75],"lack":[77],"fine":[78],"granularity":[79],"required":[80],"for":[81,160],"detection.":[83],"These":[84],"deficiencies":[85],"may":[86],"result":[87],"high":[89],"false":[90,93],"positives":[91],"negatives.":[94],"To":[95,144,185],"address":[96,186],"these":[97],"limitations,":[98],"we":[99,196,232],"designed":[100],"an":[101],"anomaly-based":[102],"node-level":[103,181],"system,":[107],"NAHID,":[108],"which":[109],"does":[110],"require":[112],"prior":[113],"knowledge":[114],"attack":[116],"patterns.":[117],"It":[118],"begins":[119],"extracting":[121],"important":[122],"entities":[123],"(e.g.,":[124,130],"processes,":[125],"files)":[126],"interactions":[129],"read":[131],"write":[133],"operations)":[134],"from":[135],"construct":[140],"a":[141,180,198],"provenance":[142,194],"graph.":[143],"effectively":[145],"model":[146,214],"dynamic":[148],"nodes":[151],"time,":[153],"NAHID":[154],"leverages":[155],"temporal":[156,170],"graph":[157,161],"neural":[158],"networks":[159],"representation":[162],"learning,":[163],"capturing":[164],"both":[165],"interaction":[167],"patterns":[168],"evolution.":[172],"The":[173],"task":[175],"is":[176],"then":[177],"formulated":[178],"multi-class":[182],"classification":[183],"problem.":[184],"inherent":[188],"class":[189],"imbalance":[190],"present":[191],"data,":[195],"incorporate":[197],"class-weighted":[199],"loss":[200],"function":[201],"that":[202,221],"enhances":[203],"model\u2019s":[205,236],"ability":[206],"recognize":[208],"minority-class":[209],"anomalies.":[210],"We":[211],"evaluated":[212,234],"our":[213,224,235],"on":[215],"three":[216],"public":[217],"datasets":[218],"demonstrated":[220],"it":[222],"outperforms":[223],"baseline":[225],"system.":[229],"In":[230],"addition,":[231],"also":[233],"runtime":[237],"conducted":[239],"ablation":[240],"experiments.":[241]},"counts_by_year":[],"updated_date":"2026-01-29T23:17:01.242718","created_date":"2026-01-29T00:00:00"}
