Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

GRASP -- Graph-Based Anomaly Detection Through Self-Supervised Classification

About

Advanced persistent threat (APT) attacks remain difficult to detect due to their stealth, adaptability, and use of legitimate system components. Provenance-based intrusion detection systems (PIDS) offer a promising defense by capturing detailed relationships between system components and actions. However, current PIDS rely on predefined or subset-determined thresholds, which limit detection stability and the ability to detect any anomalous behavior in general. Furthermore, related work often neglects the role of process executables, which describe system activity by interacting through a process with files, network components, and other processes. We introduce GRASP, a PIDS based on masked self-supervised classification. GRASP masks the executable information of processes and learns to infer it from their two-hop provenance graph neighborhood, marking misclassified processes as anomalies. It captures behavior patterns for the learned executables without thresholding, making it robust against interference and unknown activities. Evaluations on the DARPA TC and OpTC datasets demonstrate that GRASP consistently detects anomalous behavior, including known attack-related activities, outperforming existing systems. Our PIDS identifies all documented attacks on datasets where the behavior of executables is learnable. In addition, compared to existing systems, GRASP uncovers potentially malicious anomalous behavior not labeled as an attack in the documentation.

Robin Buchta, Carsten Kleiner, Felix Heine, Gabi Dreo Rodosek• 2026

Related benchmarks

TaskDatasetResultRank
Intrusion DetectionOpTC 051
ADP (Mean)100
16
Intrusion DetectionCADETS E3
ADP (Mean)100
10
Intrusion DetectionClearscope E3
ADP (Mean)0.00e+0
10
Intrusion DetectionTHEIA E3
ADP (Mean)100
9
Intrusion DetectionCadets E5
ADP (Mean)100
8
Intrusion DetectionOpTC 201
ADP (Mean)100
8
Intrusion DetectionOpTC 501
µAr100
3
Detection PerformanceCadets E5
μAr1
1
Detection PerformanceTheia-E5
μAr0.00e+0
1
Detection PerformanceClearscope-E5
μAr1
1
Showing 10 of 10 rows

Other info

Follow for update