Privacy-Preserving Collaborative Threat Intelligence with Graph Neural Networks on Attack Graphs
Privacy-Preserving Collaborative Threat Intelligence with Graph Neural Networks on Attack Graphs
Description
Details
Context and Problem Statement
Cross-organizational visibility improves detection of persistent campaigns, but provenance graphs and threat indicators can reveal internal architecture and past incidents. Existing platforms mainly share atomic indicators that rapidly become obsolete.
Research Question
How can organizations collaboratively learn transferable attack-behavior representations over distributed graphs while preserving privacy and improving detection utility beyond conventional indicator sharing?
Proposed Approach
Represent system activity as provenance graphs, learn graph embeddings using GNNs, train federatively with differential privacy, and align learned behaviors with MITRE ATT&CK to improve transfer across heterogeneous organizations.
Expected Contribution
A quantitative privacy-utility analysis and a method for semantically aligning transferable threat representations.
Expected Prototype
A multi-node experimental platform that correlates campaign-level alerts while reporting privacy-budget consumption.
Datasets
DARPA Transparent Computing traces and additional isolated-testbed traces.
Challenges
Large provenance graphs, semantic heterogeneity, utility loss under differential privacy, and legal barriers to cross-border sharing.
Research Question
Innovation
Expected Deliverable
Technologies
Required Skills
- Graph Machine Learning
- Applied Cryptography and Differential Privacy
- Systems Security and Instrumentation
- Large-Scale Data Processing
Datasets
- Public academic provenance-graph traces
- Traces generated in an isolated testbed