1
Return

NIMBLE: A modular self-supervised GraphSAGE framework for deployable provenance anomaly detection

delete2026-08-07
delete0
PRE
AI
G
Gang Xu
B
Bowen Tian
Y
Yachao Chang
X
Xiu‐Bo Chen
P
Pengsen Cheng
W
Weijie Tan
Y
Yuling Chen
G
Guangcan Yang *
DOI:10.1016/j.cose.2026.105081delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Provenance graphs are effective for host-based intrusion detection because they encode interactions among system entities, but practical anomaly detection still requires clear separation between representation learning, anomaly scoring, and deployment-time thresholding. We present NIMBLE, a modular self-supervised GraphSAGE framework fitted on benign provenance graphs and paired with a downstream outlier detector. NIMBLE supports configurable attribute corruption, optional edge reconstruction, pooled graph-level or node-level readout, and frozen-embedding scoring with Isolation Forest. We evaluate two thresholding protocols: a strict benign-quantile threshold selection (BQTS) protocol that uses only held-out benign validation scores before blind testing, and a label-tuned protocol reported only as an upper-bound reference for comparison with prior public benchmarks. The main scope supported by our matched-compute evidence is that a GraphSAGE representation with a decoupled iForest scorer is better suited than a MAGIC-style GCNII masked graph autoencoder for node-level DARPA E3 Trace detection under the same training and detector budget. BQTS performs reliably on homogeneous graph-level (StreamSpot) and node-level (Trace) settings but remains unreliable on the low-volume stealthy supply-chain scenario (Wget) under the default benign-q0.95 rule. Five-seed experiments and ablations show that GraphSAGE is the dominant architectural contributor, denoising and edge reconstruction are dataset-dependent regularizers rather than universally beneficial components, and detector choice remains important. The resulting contribution is a practical, batch-memory-efficient provenance representation pipeline that decouples graph encoding from anomaly scoring while making deployment-time thresholding explicit and auditable.

Journal

C
COMPUTERS & SECURITY
IF:
5.4
Papers:
164
Citations:
0

Organization

B
beijing university of posts and telecommunications
Scholars:
1.8K
Papers: 696
Citations: 0
N
north china university of technology
Scholars:
779
Papers: 340
Citations: 0
G
guizhou university
Scholars:
2.3W
Papers: 1.3W
Citations: 15
S
sichuan university
Scholars:
11.5W
Papers: 7.6W
Citations: 100
Cited Papers

Cited Papers

Citing Papers

Citing Papers