From One Attack Domain to Another: Contrastive Transfer Learning with Siamese Networks for APT Detection

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Benabderrahmane, Sidahmed, Rahwan, Talal
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914170901889024
author Benabderrahmane, Sidahmed
Rahwan, Talal
author_facet Benabderrahmane, Sidahmed
Rahwan, Talal
contents Advanced Persistent Threats (APT) pose a major cybersecurity challenge due to their stealth, persistence, and adaptability. Traditional machine learning detectors struggle with class imbalance, high dimensional features, and scarce real world traces. They often lack transferability-performing well in the training domain but degrading in novel attack scenarios. We propose a hybrid transfer framework that integrates Transfer Learning, Explainable AI (XAI), contrastive learning, and Siamese networks to improve cross-domain generalization. An attention-based autoencoder supports knowledge transfer across domains, while Shapley Additive exPlanations (SHAP) select stable, informative features to reduce dimensionality and computational cost. A Siamese encoder trained with a contrastive objective aligns source and target representations, increasing anomaly separability and mitigating feature drift. We evaluate on real-world traces from the DARPA Transparent Computing (TC) program and augment with synthetic attack scenarios to test robustness. Across source to target transfers, the approach delivers improved detection scores with classical and deep baselines, demonstrating a scalable, explainable, and transferable solution for APT detection.
format Preprint
id arxiv_https___arxiv_org_abs_2511_20500
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle From One Attack Domain to Another: Contrastive Transfer Learning with Siamese Networks for APT Detection
Benabderrahmane, Sidahmed
Rahwan, Talal
Machine Learning
Artificial Intelligence
Cryptography and Security
Neural and Evolutionary Computing
Advanced Persistent Threats (APT) pose a major cybersecurity challenge due to their stealth, persistence, and adaptability. Traditional machine learning detectors struggle with class imbalance, high dimensional features, and scarce real world traces. They often lack transferability-performing well in the training domain but degrading in novel attack scenarios. We propose a hybrid transfer framework that integrates Transfer Learning, Explainable AI (XAI), contrastive learning, and Siamese networks to improve cross-domain generalization. An attention-based autoencoder supports knowledge transfer across domains, while Shapley Additive exPlanations (SHAP) select stable, informative features to reduce dimensionality and computational cost. A Siamese encoder trained with a contrastive objective aligns source and target representations, increasing anomaly separability and mitigating feature drift. We evaluate on real-world traces from the DARPA Transparent Computing (TC) program and augment with synthetic attack scenarios to test robustness. Across source to target transfers, the approach delivers improved detection scores with classical and deep baselines, demonstrating a scalable, explainable, and transferable solution for APT detection.
title From One Attack Domain to Another: Contrastive Transfer Learning with Siamese Networks for APT Detection
topic Machine Learning
Artificial Intelligence
Cryptography and Security
Neural and Evolutionary Computing
url https://arxiv.org/abs/2511.20500