{"id":"W4415841383","doi":"10.48550/arxiv.2510.15188","title":"OCR-APT: Reconstructing APT Stories from Audit Logs using Subgraph Anomaly Detection and LLMs","year":2025,"lang":"","type":"preprint","venue":"ArXiv.org","topic":"Software System Performance and Reliability","field":"Computer Science","cited_by":0,"is_retracted":false,"has_abstract":true,"ca_institutions":"Concordia University","funders":"","keywords":"Anomaly detection; Spurious relationship; Robustness (evolution); Audit; Attack patterns; Subgraph isomorphism problem; Iterated function; Audit trail","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.001276467,0.002016194,0.0005565836,0.003585566,0.0004148534,0.001245484,0.001747061,0.001170079,0.001627698],"category_scores_gemma":[0.009691886,0.000374724,0.0009548285,0.001602128,0.0006330837,0.002711031,0.001760186,0.001159455,0.001685555],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0008490616,"about_ca_system_score_gemma":0.001098223,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.01198431,"about_ca_topic_score_gemma":0.0191011,"domain_scores_codex":[0.9985594,0.0003116175,0.0001089049,0.0004510181,0.0004757694,0.00009322724],"domain_scores_gemma":[0.9950609,0.001821734,0.0007151289,0.001496612,0.0007282078,0.0001774085],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"bench_or_experimental","study_design_scores_codex":[0.0008573792,0.0005077441,0.02992387,0.0009537467,0.0003349528,0.001262814,0.001194177,0.1058639,0.01989591,0.004952078,0.08344004,0.7508134],"study_design_scores_gemma":[0.00003195975,0.0001054009,0.003803639,0.0000402083,0.00004334009,0.0003184385,0.0002294324,0.9614779,0.01229214,0.007737299,0.01387218,0.00004805264],"study_design_candidate":"bench_or_experimental","study_design_consensus":null,"genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.1835912,0.002052396,0.4882505,0.001521197,0.00038838,0.000729239,0.02573764,0.290786,0.006943367],"genre_scores_gemma":[0.5345327,0.0006875116,0.3944543,0.0004976258,0.0001363345,0.0003138663,0.06112541,0.003147562,0.005104777],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.01198431,"threshold_uncertainty_score":0.0238291,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.04361607421284627,"score_gpt":0.2695770273053696,"score_spread":0.2259609530925234,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}