TY - GEN
T1 - LADE
T2 - 22nd EAI International Conference on Security and Privacy in Communication Networks, SecureComm 2026
AU - Gwak, Joon Young
AU - Strier, Aubrey
AU - Xi, Zhaohan
AU - Yan, Guanhua
AU - Shu, Xiaokui
AU - Stoller, Scott D.
AU - Yang, Ping
N1 - Publisher Copyright:
© ICST Institute for Computer Sciences, Social Informatics and Telecommunications Engineering 2027.
PY - 2027
Y1 - 2027
N2 - Advanced Persistent Threat (APT) attacks are sophisticated cyberattacks characterized by stealth, persistence, and long-term engagement with targeted systems. Traditional detection approaches using machine learning and deep learning rely on internal model representations or post hoc explainability techniques, which often lack human-readable context and require significant manual interpretation. This paper investigates the use of large language models (LLMs) for APT detection through code analysis. We evaluate LLMs’ ability to identify APT-related behaviors in code-snippet sequences, localize malicious components, and map them to corresponding MITRE ATT&CK tactics, techniques, and procedures (TTPs). To address context-window limitations, we introduce a segmentation-based approach that divides long code sequences into smaller segments and iteratively processes them while preserving context through summary propagation. Because real-world APT data are scarce due to their stealthy nature, privacy constraints, and long attack lifecycles, we construct an APT dataset derived from Caldera adversary profiles and emulation plans. Experimental results show that LLMs, when guided by rubric-based prompts and supplemented with ATT&CK domain knowledge, achieve robust performance across detection, localization, and TTP mapping tasks.
AB - Advanced Persistent Threat (APT) attacks are sophisticated cyberattacks characterized by stealth, persistence, and long-term engagement with targeted systems. Traditional detection approaches using machine learning and deep learning rely on internal model representations or post hoc explainability techniques, which often lack human-readable context and require significant manual interpretation. This paper investigates the use of large language models (LLMs) for APT detection through code analysis. We evaluate LLMs’ ability to identify APT-related behaviors in code-snippet sequences, localize malicious components, and map them to corresponding MITRE ATT&CK tactics, techniques, and procedures (TTPs). To address context-window limitations, we introduce a segmentation-based approach that divides long code sequences into smaller segments and iteratively processes them while preserving context through summary propagation. Because real-world APT data are scarce due to their stealthy nature, privacy constraints, and long attack lifecycles, we construct an APT dataset derived from Caldera adversary profiles and emulation plans. Experimental results show that LLMs, when guided by rubric-based prompts and supplemented with ATT&CK domain knowledge, achieve robust performance across detection, localization, and TTP mapping tasks.
KW - Advanced Persistent Threat Detection
KW - Large Language Models
KW - MITRE ATT&CK Framework
UR - https://www.scopus.com/pages/publications/105046815950
U2 - 10.1007/978-3-032-32767-3_11
DO - 10.1007/978-3-032-32767-3_11
M3 - Conference contribution
AN - SCOPUS:105046815950
SN - 9783032327666
T3 - Lecture Notes of the Institute for Computer Sciences, Social-Informatics and Telecommunications Engineering, LNICST
SP - 245
EP - 273
BT - Security and Privacy in Communication Networks - 22nd EAI International Conference, SecureComm 2026, Proceedings
A2 - Cao, Yinzhi
A2 - Luo, Bo
A2 - Meng, Weizhi
PB - Springer Science and Business Media Deutschland GmbH
Y2 - 21 July 2026 through 24 July 2026
ER -