[2602.02929] RPG-AE: Neuro-Symbolic Graph Autoencoders with Rare Pattern Mining for Provenance-Based Anomaly Detection

[2602.02929] RPG-AE: Neuro-Symbolic Graph Autoencoders with Rare Pattern Mining for Provenance-Based Anomaly Detection

arXiv - AI 4 min read Article

Summary

This paper presents RPG-AE, a neuro-symbolic framework combining Graph Autoencoders and rare pattern mining for detecting Advanced Persistent Threats in system-level provenance data.

Why It Matters

As cyber threats become increasingly sophisticated, effective detection methods are crucial for cybersecurity. This research introduces a novel approach that enhances anomaly detection by integrating advanced machine learning techniques, potentially improving security measures across various systems.

Key Takeaways

  • RPG-AE combines Graph Autoencoders with rare pattern mining for anomaly detection.
  • The method improves detection of Advanced Persistent Threats (APTs) in system behavior.
  • Evaluation on DARPA datasets shows substantial gains in anomaly ranking quality.
  • The approach outperforms existing unsupervised methods and is competitive with ensemble techniques.
  • Coupling graph-based learning with classical pattern mining enhances interpretability and effectiveness.

Computer Science > Machine Learning arXiv:2602.02929 (cs) [Submitted on 3 Feb 2026 (v1), last revised 15 Feb 2026 (this version, v2)] Title:RPG-AE: Neuro-Symbolic Graph Autoencoders with Rare Pattern Mining for Provenance-Based Anomaly Detection Authors:Asif Tauhid, Sidahmed Benabderrahmane, Mohamad Altrabulsi, Ahamed Foisal, Talal Rahwan View a PDF of the paper titled RPG-AE: Neuro-Symbolic Graph Autoencoders with Rare Pattern Mining for Provenance-Based Anomaly Detection, by Asif Tauhid and 4 other authors View PDF HTML (experimental) Abstract:Advanced Persistent Threats (APTs) are sophisticated, long-term cyberattacks that are difficult to detect because they operate stealthily and often blend into normal system behavior. This paper presents a neuro-symbolic anomaly detection framework that combines a Graph Autoencoder (GAE) with rare pattern mining to identify APT-like activities in system-level provenance data. Our approach first constructs a process behavioral graph using k-Nearest Neighbors based on feature similarity, then learns normal relational structure using a Graph Autoencoder. Anomaly candidates are identified through deviations between observed and reconstructed graph structure. To further improve detection, we integrate an rare pattern mining module that discovers infrequent behavioral co-occurrences and uses them to boost anomaly scores for processes exhibiting rare signatures. We evaluate the proposed method on the DARPA Transparent Computing datasets an...

Related Articles

Machine Learning

We have an AI agent fragmentation problem

Every AI agent works fine on its own — but the moment you try to use more than one, everything falls apart. Different runtimes. Different...

Reddit - Artificial Intelligence · 1 min ·
Machine Learning

Using AI properly

AI is a tool. Period. I spent decades asking forums for help in writing HTML code for my website. I wanted my posts to self-scroll to a p...

Reddit - Artificial Intelligence · 1 min ·
Anthropic Teams Up With Its Rivals to Keep AI From Hacking Everything | WIRED
Llms

Anthropic Teams Up With Its Rivals to Keep AI From Hacking Everything | WIRED

The AI lab's Project Glasswing will bring together Apple, Google, and more than 45 other organizations. They'll use the new Claude Mythos...

Wired - AI · 7 min ·
Machine Learning

[for hire] Open for contracts – Veteran Data Scientist (AI / ML / OR) focused on delivering real‑world solutions.

Hi Reddit, I've spent 20 years working with data, and I've learned how to crack problems that AI systems struggle with. I've got a knack ...

Reddit - ML Jobs · 1 min ·
More in Machine Learning: This Week Guide Trending

No comments

No comments yet. Be the first to comment!

Stay updated with AI News

Get the latest news, tools, and insights delivered to your inbox.

Daily or weekly digest • Unsubscribe anytime