PGAE: A Perturbed Graph Autoencoder Integrating Explicit and Implicit Features for APT Detection
摘要
As Advanced Persistent Threats (APTs) continue to evolve in terms of stealth and persistence, traditional provenance graph-based intrusion detection systems face two core challenges: 1) provenance graphs often contain numerous redundant edges, which can easily introduce noise interference; 2) traditional Graph Neural Networks (GNNs) is difficult to capture the interaction of low-order semantic features in provenance graphs, which limits the detection performance. To address these challenges, we propose PGAE—a perturbation-based graph autoencoder framework that integrates explicit and implicit feature interactions, achieving unsupervised APT node detection. PGAE innovatively applies a dual-edge-node masking mechanism to perturb the structure of provenance graphs. It then synchronously learns explicit interaction patterns and implicit dependencies of node features through an improved graph autoencoder, leveraging a cross-correlation decoder for dual optimization of feature reconstruction and topology rebuilding. Experiments show that PGAE significantly outperforms mainstream methods in terms of accuracy across multiple APT detection datasets, validating its effectiveness and practical applicability.