Quote of the day

A person who never made a mistake never tried anything new.

- Albert Einstein

Contact

Privacy-Preserving Collaborative Threat Intelligence with Graph Neural Networks on Attack Graphs

Open Cybersecurity

Privacy-Preserving Collaborative Threat Intelligence with Graph Neural Networks on Attack Graphs

Privacy-Preserving Collaborative Threat Intelligence with Graph Neural Networks on Attack Graphs

Description

Enable multiple organizations to collaboratively learn campaign-level attack patterns from provenance graphs without exposing internal topology or sensitive threat indicators.

Details

Context and Problem Statement

Cross-organizational visibility improves detection of persistent campaigns, but provenance graphs and threat indicators can reveal internal architecture and past incidents. Existing platforms mainly share atomic indicators that rapidly become obsolete.

Research Question

How can organizations collaboratively learn transferable attack-behavior representations over distributed graphs while preserving privacy and improving detection utility beyond conventional indicator sharing?

Proposed Approach

Represent system activity as provenance graphs, learn graph embeddings using GNNs, train federatively with differential privacy, and align learned behaviors with MITRE ATT&CK to improve transfer across heterogeneous organizations.

Expected Contribution

A quantitative privacy-utility analysis and a method for semantically aligning transferable threat representations.

Expected Prototype

A multi-node experimental platform that correlates campaign-level alerts while reporting privacy-budget consumption.

Datasets

DARPA Transparent Computing traces and additional isolated-testbed traces.

Challenges

Large provenance graphs, semantic heterogeneity, utility loss under differential privacy, and legal barriers to cross-border sharing.

Research Question

Does federated co-learning of attack-graph representations provide measurable detection gains over conventional indicator sharing under a controlled privacy budget?

Innovation

The project replaces atomic indicator sharing with privacy-preserving collaborative learning of behavioral representations.

Expected Deliverable

A multi-node federated prototype, a privacy-utility study, and a research paper.

Technologies

Graph Neural Networks Federated Learning Differential Privacy Provenance Graphs MITRE ATT&CK and STIX

Required Skills

  • Graph Machine Learning
  • Applied Cryptography and Differential Privacy
  • Systems Security and Instrumentation
  • Large-Scale Data Processing

Datasets

  • Public academic provenance-graph traces
  • Traces generated in an isolated testbed

Morocco & Africa Relevance

African public institutions and critical-infrastructure operators could benefit from joint detection without exposing internal weaknesses.