Skip to main navigation Skip to search Skip to main content

LADE: LLM-Assisted Advanced Persistent Threat Detection and Explanation

  • Joon Young Gwak
  • , Aubrey Strier
  • , Zhaohan Xi
  • , Guanhua Yan
  • , Xiaokui Shu
  • , Scott D. Stoller
  • , Ping Yang
  • State University of New York Binghamton University
  • IBM

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Advanced Persistent Threat (APT) attacks are sophisticated cyberattacks characterized by stealth, persistence, and long-term engagement with targeted systems. Traditional detection approaches using machine learning and deep learning rely on internal model representations or post hoc explainability techniques, which often lack human-readable context and require significant manual interpretation. This paper investigates the use of large language models (LLMs) for APT detection through code analysis. We evaluate LLMs’ ability to identify APT-related behaviors in code-snippet sequences, localize malicious components, and map them to corresponding MITRE ATT&CK tactics, techniques, and procedures (TTPs). To address context-window limitations, we introduce a segmentation-based approach that divides long code sequences into smaller segments and iteratively processes them while preserving context through summary propagation. Because real-world APT data are scarce due to their stealthy nature, privacy constraints, and long attack lifecycles, we construct an APT dataset derived from Caldera adversary profiles and emulation plans. Experimental results show that LLMs, when guided by rubric-based prompts and supplemented with ATT&CK domain knowledge, achieve robust performance across detection, localization, and TTP mapping tasks.

Original languageEnglish
Title of host publicationSecurity and Privacy in Communication Networks - 22nd EAI International Conference, SecureComm 2026, Proceedings
EditorsYinzhi Cao, Bo Luo, Weizhi Meng
PublisherSpringer Science and Business Media Deutschland GmbH
Pages245-273
Number of pages29
ISBN (Print)9783032327666
DOIs
StatePublished - 2027
Event22nd EAI International Conference on Security and Privacy in Communication Networks, SecureComm 2026 - Lancaster, United Kingdom
Duration: Jul 21 2026Jul 24 2026

Publication series

NameLecture Notes of the Institute for Computer Sciences, Social-Informatics and Telecommunications Engineering, LNICST
Volume705 LNICST
ISSN (Print)1867-8211
ISSN (Electronic)1867-822X

Conference

Conference22nd EAI International Conference on Security and Privacy in Communication Networks, SecureComm 2026
Country/TerritoryUnited Kingdom
CityLancaster
Period07/21/2607/24/26

Keywords

  • Advanced Persistent Threat Detection
  • Large Language Models
  • MITRE ATT&CK Framework

Fingerprint

Dive into the research topics of 'LADE: LLM-Assisted Advanced Persistent Threat Detection and Explanation'. Together they form a unique fingerprint.

Cite this