KMITL
Permanent URI for this communityhttps://dspace.kmitl.ac.th/handle/123456789/1
Browse
2 results
Search Results
- Some of the metrics are blocked by yourconsent settings
Item type:Publication, Adaptive Detection of Advanced Persistent Threats (APT) With Graph Neural Networks and Rehearsal-Based Continual Learning on Wazuh EDR Telemetry(2025-01-01)Pomsathit, AuttaponIn the rapidly evolving cybersecurity landscape, Advanced Persistent Threats (APTs) pose major challenges due to their stealthy and adaptive behavior. Traditional detection methods based on signatures or heuristics are limited in identifying novel and evolving attacks, while static deep learning models suffer from concept drift and catastrophic forgetting, leading to degraded performance over time. This paper proposes an adaptive APT detection framework that integrates Graph Neural Networks (GNNs) with rehearsal-based continual learning using telemetry data from Wazuh, an open-source Security Information and Event Management (SIEM) and Endpoint Detection and Response (EDR) platform. Endpoint telemetry is represented as graphs where nodes denote system components and edges describe behavioral interactions among them. Experimental evaluations on real-world Wazuh telemetry augmented with sandbox-executed APT scenarios demonstrate that the proposed approach consistently achieves F1-scores above 0.98, outperforming static and fine-tuned baselines in both adaptability and knowledge retention. These results confirm that combining graph-based representations with continual learning offers a scalable, interpretable, and resilient solution for modern SOC and EDR environments facing advanced and evolving cyber threats. - Some of the metrics are blocked by yourconsent settings
Item type:Publication, Energy-Efficient Continual Learning for Autonomous Driving(2023-01-01) ;Ng, Qi Ding ;Loo, Chu Kiong ;Pasupa, Kitsuchart ;Dilokthanakul, NatZhang, JieOur work highlighted the primary challenges of Autonomous Driving (AD), namely the Catastrophic Forgetting (CF) of previous knowledge by the AD system upon new scenario encounters. Considering the infeasible model retraining with past data given computational, power, and storage constraints on the embedded device, we proposed an experiment featuring Avalanche Continual Learning (CL) training strategies to investigate which strategies excel in this task and combine the promising ones in the hope for a more balanced and efficient trade-off between performance and energy consumption. Our experiment unprecedentedly validated the candidates against a new benchmark introducing natural distribution change and time correlation between input images. We found that although a synergy of CL strategies yields higher resistance towards CF, the slight accuracy gain is not worth the additional computation when we account for energy consumption, rendering a simple Replay strategy the best solution for the Continual Learning benchmark for Autonomous Driving: Online Continual Classification (CLAD-C). Our proposal delivers a 65.80% improvement over the baseline at our proposed accuracy-power ratio metric.
