{"id":"W3105780912","doi":"","title":"UNICORN:Runtime Provenance-Based Detector for Advanced Persistent Threats","year":2020,"lang":"en","type":"preprint","venue":"Bristol Research (University of Bristol)","topic":"Network Security and Intrusion Detection","field":"Computer Science","cited_by":75,"is_retracted":false,"has_abstract":true,"ca_institutions":"University of British Columbia","funders":"","keywords":"Unicorn; Computer science; Graph; Anomaly detection; Computation; Detector; Theoretical computer science; Data mining; Algorithm","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.002839536,0.001164179,0.0008356412,0.002366279,0.0006249392,0.001854668,0.001781961,0.0009966912,0.001808964],"category_scores_gemma":[0.01859787,0.0006201131,0.0007165826,0.0009993035,0.001011053,0.003759155,0.003008968,0.001609117,0.001020056],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0009435356,"about_ca_system_score_gemma":0.002006931,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.003666745,"about_ca_topic_score_gemma":0.006529072,"domain_scores_codex":[0.9969624,0.0005347319,0.000251853,0.0006013168,0.001486856,0.0001628523],"domain_scores_gemma":[0.9888404,0.004169771,0.001055364,0.003973654,0.001586474,0.0003743664],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.001116917,0.0004922462,0.07849036,0.001571015,0.0003808721,0.001096783,0.001465158,0.09383988,0.05550226,0.038582,0.07475308,0.6527094],"study_design_scores_gemma":[0.00005078322,0.0001599833,0.003710911,0.00008393203,0.0000690568,0.0006223546,0.0001107392,0.9037355,0.0388747,0.02051937,0.03197041,0.00009227929],"study_design_candidate":"simulation_or_modeling","study_design_consensus":null,"genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.03376953,0.0008401286,0.808782,0.0005409191,0.0002442482,0.0003791532,0.002645943,0.1488728,0.003925467],"genre_scores_gemma":[0.4938905,0.0005902564,0.4873373,0.0004811214,0.0001258063,0.0003352519,0.007368946,0.005293943,0.004576827],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.003666745,"threshold_uncertainty_score":0.01501709,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.09279258365515726,"score_gpt":0.3040890968178061,"score_spread":0.2112965131626489,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}