{"id":"W4411204262","doi":"10.1109/isdfs65363.2025.11011912","title":"APT-LLM: Embedding-Based Anomaly Detection of Cyber Advanced Persistent Threats Using Large Language Models","year":2025,"lang":"en","type":"article","venue":"","topic":"Information and Cyber Security","field":"Computer Science","cited_by":19,"is_retracted":false,"has_abstract":true,"ca_institutions":"Université de Montréal; Université du Québec à Montréal","funders":"","keywords":"Computer science; Anomaly detection; Embedding; Anomaly (physics); Natural language processing; Artificial intelligence; Physics","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.001147696,0.001392822,0.0006755035,0.001264578,0.000331477,0.0008075694,0.001094114,0.000812978,0.0008397136],"category_scores_gemma":[0.005140943,0.0003860399,0.0009750243,0.0006266509,0.000508079,0.002172389,0.001580853,0.002103645,0.0007760367],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.000626871,"about_ca_system_score_gemma":0.001052869,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.005495424,"about_ca_topic_score_gemma":0.007417846,"domain_scores_codex":[0.9990683,0.0002608006,0.00005577945,0.0002961872,0.0002234449,0.00009550865],"domain_scores_gemma":[0.9981316,0.0009680944,0.0002578848,0.0002716034,0.0002783049,0.00009259916],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"bench_or_experimental","study_design_scores_codex":[0.0004583264,0.0006037692,0.02266559,0.0002289349,0.0003398405,0.0004441097,0.0004626788,0.3314889,0.02220742,0.006897316,0.01007698,0.6041262],"study_design_scores_gemma":[0.000006329453,0.0000481051,0.0008164924,0.000006865389,0.00001063797,0.00005320739,0.0000246428,0.9933003,0.002338314,0.002642866,0.0007405769,0.00001161695],"study_design_candidate":"bench_or_experimental","study_design_consensus":null,"genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.1021324,0.0007512286,0.8856345,0.0005683437,0.0001400818,0.000122743,0.0009061439,0.008647471,0.001097041],"genre_scores_gemma":[0.7173753,0.0004894983,0.2725808,0.0003455665,0.0001158377,0.0002259978,0.003997879,0.0005085397,0.004360517],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.005495424,"threshold_uncertainty_score":0.0109269,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.01478359222374085,"score_gpt":0.2756461668821293,"score_spread":0.2608625746583884,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}