Pith. sign in

Paper Citation Record · LEDGER

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection

As of 15 August 2026, this Paper Citation Record lists 97 of 97 outbound references and 0 inbound Pith citation observations for arXiv:2507.10873.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2507.10873 v1

Coverage vector

measured 97 of 97 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-06T17:30:02.816653Z

measured 97 of 97 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-15T06:32:42.880941+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

97 of 97 outbound references displayed

  • verified exact0
  • verified fuzzy48
  • unresolved49
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 6d12d57c-732d-4028-bb67-b64018d2764d · outbound

This paper cites Fbi releases annual internet crime report,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Fbi releases annual internet crime report,

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:55.132008Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:55.132008Z digest=sha256:2a8154ed9718723ee23f3e78daa808d86e90db10ef61701f797344ebdcf8bec4

Observation 6523c75f-9cfe-42da-92f3-d0a52837aad7 · outbound

This paper cites Cyberattacks cost victims more than quadruple the amount hackers pay to execute attacks,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Cyberattacks cost victims more than quadruple the amount hackers pay to execute attacks,

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:55.197894Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:55.197894Z digest=sha256:d4384446b87da43c616480439f904aa7598ae753cb18955f25e1a1e01a307f55

Observation c17ede2a-c9e1-49c8-822b-7d938506974b · outbound

This paper cites Intrusion detection system market size, share, and growth analysis,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Intrusion detection system market size, share, and growth analysis,

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:55.258642Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:55.258642Z digest=sha256:bc069c9b6681f3107643589447702dee4874cd083767eb4088920daea780fd59

Observation 30d7a3d9-e0ae-4819-b412-a6bf108b836e · outbound

This paper cites Sok: History is a vast early warning system: Auditing the provenance of system intrusions,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Sok: History is a vast early warning system: Auditing the provenance of system intrusions,

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:55.314421Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:55.314421Z digest=sha256:849b32d84cb1ee769e67b9450f9a0fadbd74d28be1af77d99ab2e97cd28ccf18

Observation d0509619-1a87-4c5e-a810-63ec329f3739 · outbound

This paper cites Backtracking intrusions,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Backtracking intrusions,

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:55.365365Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:55.365365Z digest=sha256:7e5a34f4abdd61e33ca4edef1d1b5df2f54841c233d43e3b2c14f36c5c9395df

Observation fa19b7f0-ed25-469c-b907-7e7333aa9f03 · outbound

This paper cites Nodoze: Combatting threat alert fatigue with automated provenance triage,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Nodoze: Combatting threat alert fatigue with automated provenance triage,

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:55.442449Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:55.442449Z digest=sha256:20af18610278d318198a16d4e43ae46bbcde32837bcb71e40194f24500ec2990

Observation 4ca6dab6-1426-4e26-948c-0241dca3ba8d · outbound

This paper cites Transparent computing engagement 3,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Transparent computing engagement 3,

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:55.493585Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:55.493585Z digest=sha256:c7d60ad349e9d62af1d998af0ed3d9e2df0ad0c677ba30b027423990593a7408

Observation b8b371cf-84b7-4ebc-9190-b5442c96057b · outbound

This paper cites Nodlink repo,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Nodlink repo,

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:55.577168Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:55.577168Z digest=sha256:329e439d21f206bb1df50df312a9c1b0150124a5e5f73ae2991a318dbfd37ec7

Observation e6953084-7cd4-4583-b7f8-b72aa8f8e028 · outbound

This paper cites ATLASv2: ATLAS Attack Engagements, Version 2.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection ATLASv2: ATLAS Attack Engagements, Version 2

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:55.639072Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:55.639072Z digest=sha256:55d877de6582cf7565961cdda0a4ca253dc8150b4b2ff55949bed40045cecd96

Observation b982eecd-4760-44d5-bcba-b5d324018a40 · outbound

This paper cites Nodlink: An online system for fine-grained apt attack detection and investigation,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Nodlink: An online system for fine-grained apt attack detection and investigation,

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:55.723736Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:55.723736Z digest=sha256:363a82d8066e08c7f7eb345bdbbb9fb03bf1f5ae2bfa93b0d6fab31cbaa1bf1c

Observation 8cc19acd-c948-4b19-bd9d-17406118ca7a · outbound

This paper cites AIRTAG: Towards automated attack investigation by unsupervised learning with log texts,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection AIRTAG: Towards automated attack investigation by unsupervised learning with log texts,

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:55.796781Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:55.796781Z digest=sha256:fc1bf77674babcf9421f8ac13def4a3ed3c726f1263ded1d41bc69f559d1381a

Observation aeea8833-ba95-4413-9f7e-44784368702c · outbound

This paper cites Flash: A comprehensive approach to intrusion detection via provenance graph representation learning,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Flash: A comprehensive approach to intrusion detection via provenance graph representation learning,

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:55.838261Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:55.838261Z digest=sha256:aaa0f0544b8b185747f3d9428040f790947be15d318f5bd463f2962d16d5c5f6

Observation 623022e4-8378-4c6e-b6d3-8181a22b4456 · outbound

This paper cites {MAGIC}: Detecting advanced persistent threats via masked graph representation learning,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection {MAGIC}: Detecting advanced persistent threats via masked graph representation learning,

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:55.889328Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:55.889328Z digest=sha256:6fb7842f3d47b0c055624cd8ed08cb2a34198bbb1e75ae112f9160875271be6e

Observation 545c9ecc-2e4e-49f6-9572-478f6de31323 · outbound

This paper cites ORTHRUS: Achieving High Quality of At- tribution in Provenance-based Intrusion Detection Systems,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection ORTHRUS: Achieving High Quality of At- tribution in Provenance-based Intrusion Detection Systems,

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:55.947179Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:55.947179Z digest=sha256:711a56c84e82f2e13b40af2d0f4b1edda87ba463955d15ef00c5ac9cfcb8b9fb

Observation bf5e56bc-4f91-4d76-8e2b-b6d8ea91d891 · outbound

This paper cites Constructing knowledge graph from cyber threat intelligence using large language model,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Constructing knowledge graph from cyber threat intelligence using large language model,

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:56.065803Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:56.065803Z digest=sha256:463e195f8700f9af5184fda8b28850a31e9a745ab468baac8820ce0ef8744b04

Observation 7a406207-4c56-40e2-ae19-6cb03fdc8a7d · outbound

This paper cites Ctikg: Llm-powered knowledge graph construc- tion from cyber threat intelligence,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Ctikg: Llm-powered knowledge graph construc- tion from cyber threat intelligence,

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:56.103099Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:56.103099Z digest=sha256:007e40fe933d4a5e8eb97d3c72abc4f74b999ef1878b5c3d34d1b9c989d4ec39

Observation 93335473-a017-433b-8f41-3ab5b9979eeb · outbound

This paper cites Towards a scalable ai- driven framework for data-independent cyber threat intelligence infor- mation extraction,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Towards a scalable ai- driven framework for data-independent cyber threat intelligence infor- mation extraction,

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:56.187713Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:56.187713Z digest=sha256:262015f674508f183b3b35e74bf513e45e03de0da3e951d81492c47e31b8eff3

Observation fd88ed37-f2a7-497e-82d0-64acd31024f0 · outbound

This paper cites FADE: Few-shot/zero-shot Anomaly Detection Engine using Large Vision-Language Model.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection FADE: Few-shot/zero-shot Anomaly Detection Engine using Large Vision-Language Model

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:56.288957Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:56.288957Z digest=sha256:23772d24d5c39388f92c1c24218ab19e7483082106ecda331bd1a1f6750c8172

Observation b3e86ec5-7273-4cfe-b4ed-bdb0816f2efc · outbound

This paper cites Ad-llm: Benchmarking large language models for anomaly detection,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Ad-llm: Benchmarking large language models for anomaly detection,

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:56.333428Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:56.333428Z digest=sha256:a9b1ba9e4cda7d64f6ba4ed42ff1aec05252a08214b53a8e5f40c093bc3f00bd

Observation e96cca0f-90d4-465e-92f9-d8d967935606 · outbound

This paper cites Large Language Models for Forecasting and Anomaly Detection: A Systematic Literature Review.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Large Language Models for Forecasting and Anomaly Detection: A Systematic Literature Review

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:56.413683Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:56.413683Z digest=sha256:ba7a2a022de7668341d23e9a93d9cde1667f6ee69a656f81ed731d7d0a3ad2d5

Observation 5ebc9c72-4215-4167-a6e4-2c4fba8df154 · outbound

This paper cites Anomaly Detection of Tabular Data Using LLMs.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Anomaly Detection of Tabular Data Using LLMs

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:56.482589Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:56.482589Z digest=sha256:2fca3a1d1064de5663bb31625ed819acadca6d7448b0f98e5db252c40621ee5e

Observation 331f0a74-7f7d-4b0e-a2f1-f3b7fed78823 · outbound

This paper cites Summarization is (Almost) Dead.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Summarization is (Almost) Dead

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:56.545032Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:56.545032Z digest=sha256:378b70a2fb314a877460208212d35aa6e1667c3b4dc2ed4f325845592dfcdb02

Observation 0ce1a4af-8ee7-45cd-b8cf-ae2d2638b62b · outbound

This paper cites Lost in the middle: How language models use long contexts,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Lost in the middle: How language models use long contexts,

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:56.614158Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:56.614158Z digest=sha256:468644dda4aaf9ddabde7645a353774585d532ec59e2d5fe47a663f5e486b576

Observation 74a3cc14-fef0-4b38-964a-d0098fadd308 · outbound

This paper cites UNICORN: Runtime Provenance-Based Detector for Advanced Persistent Threats.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection UNICORN: Runtime Provenance-Based Detector for Advanced Persistent Threats

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:56.676292Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:56.676292Z digest=sha256:aaac1976521e195d661b20bd6da49a5a8c4ff3faf37a281f923a6ed53f0e7bf9

Observation bf37aa4d-06d2-4aae-a1aa-1a02a9152312 · outbound

This paper cites {PROGRAPHER}: An anomaly detection system based on provenance graph embedding,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection {PROGRAPHER}: An anomaly detection system based on provenance graph embedding,

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:56.739178Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:56.739178Z digest=sha256:f118d51633ec2aeaae703c58ff4f4fd33cec457698dd46bd7c35d527b8a6c844

Observation 11ef014e-e86d-4c34-8c6d-cd3d309f6229 · outbound

This paper cites Masked au- toencoders are scalable vision learners,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Masked au- toencoders are scalable vision learners,

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:56.785201Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:56.785201Z digest=sha256:05d466c4790dbdae422dba0bef58ed7cc1fbd89e2047606ebca9ce7cb492d885

Observation 60c9746d-03ac-447f-bc67-64260f9c7636 · outbound

This paper cites Madeline: Continuous and low-cost monitoring with graph-free representations to combat cyber threats,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Madeline: Continuous and low-cost monitoring with graph-free representations to combat cyber threats,

Reference 27

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:12.562372Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:29:56.865512Z digest=sha256:d57785ce52457cea1754e21c98f778ea972a4444b8669ad41bb64a52833e5fc6

Observation cc1c0220-5d7e-4535-94a3-fb112c784bac · outbound

This paper cites Retrieval- augmented generation for knowledge-intensive nlp tasks,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Retrieval- augmented generation for knowledge-intensive nlp tasks,

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:56.925805Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:56.925805Z digest=sha256:1ded7771e80ea5cae173736592c5b652d77a2ac42bf6522a70da367f1b798fe1

Observation 51002c21-5f6b-4241-8a21-0d8ffcbff21e · outbound

This paper cites Enterprise tactics,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Enterprise tactics,

Reference 29

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:12.503913Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:29:57.014605Z digest=sha256:c357e5a51fadc29ef73102b857e5c3d64aa21ca851e9c7a5395485f068cb6670

Observation bc32f1d4-dc46-47d5-a50b-267e33b5b469 · outbound

This paper cites Sometimes, you aren’t what you do: Mimicry attacks against provenance graph host intrusion detection systems,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Sometimes, you aren’t what you do: Mimicry attacks against provenance graph host intrusion detection systems,

Reference 30

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:12.476864Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:29:57.113337Z digest=sha256:f4f2f1575ef667d6a8ec9c762b54b5121e711ae8dfe4618f58a0b50413f1225b

Observation 3b481f37-8303-48ef-a26a-8ba2125f3ffe · outbound

This paper cites Winodws event tracing,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Winodws event tracing,

Reference 31

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:12.423358Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:29:57.158829Z digest=sha256:3f8f7868bbc9b4ea479390d8a76dee6218faea6b9cd65c2dd02e8f0a1e39bd15

Observation 755523ac-d889-40ce-a0a1-2f104bcdf38f · outbound

This paper cites Linux audit,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Linux audit,

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:57.198668Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:57.198668Z digest=sha256:077410aeb7952930a5988e9309ee9537ae0c8963b505e598b29606f7e4799ff0

Observation 9c29804e-a6de-465c-ac18-235013060c9c · outbound

This paper cites Dtrace on freebsd,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Dtrace on freebsd,

Reference 33

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:12.325727Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:29:57.248180Z digest=sha256:7587339fa6a0d8ba49790f773861e741e2715071082198a13f1bf63ccf4936d0

Observation a002069e-9c4c-46d4-ae91-0803156ac044 · outbound

This paper cites Cyber kill chain,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Cyber kill chain,

Reference 34

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:12.288133Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:29:57.315933Z digest=sha256:d39db131721eec5bc373d081953de30578d400d84c9ec815428cb75ad3442970

Observation cc6477c2-121c-4282-8096-f91c6c1b3068 · outbound

This paper cites Are we there yet? an industrial viewpoint on provenance-based endpoint detection and response tools,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Are we there yet? an industrial viewpoint on provenance-based endpoint detection and response tools,

Reference 35

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:12.260681Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:29:57.398158Z digest=sha256:83a6eab937cb850ceb5e8218e4c280f7b1fa0f952543272b3679e1fd2e700609

Observation c1032364-5510-4dbb-b061-5e3c2452bacb · outbound

This paper cites Provenance-aware tracing ofworm break-in and contaminations: A process coloring approach,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Provenance-aware tracing ofworm break-in and contaminations: A process coloring approach,

Reference 36

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:12.077735Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:29:57.478180Z digest=sha256:8b95353042c8909edd2703263e914a987404dc8f9a5005f8573ed44550c79825

Observation 32c66bed-caba-470f-aee0-6ff34b60efd1 · outbound

This paper cites High fidelity data reduction for big data security dependency analyses,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection High fidelity data reduction for big data security dependency analyses,

Reference 37

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:11.864469Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:29:57.571013Z digest=sha256:e971bccd620c26b91b17c0d2c140f7f1d564f3f0a50b49db78dde739951a5422

Observation a95a7223-8937-4830-b9d2-edec0269356a · outbound

This paper cites Can data provenance put an end to the data breach?.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Can data provenance put an end to the data breach?

Reference 38

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:11.676377Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:29:57.637912Z digest=sha256:2e102431437ec4d7c27c4c4f74e750dfeabd8cfc12ede83ae97b45d4aa510712

Observation efbaca8d-d3a6-4b6a-a653-5e9d6da35801 · outbound

This paper cites Towards a timely causality analysis for enterprise security,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Towards a timely causality analysis for enterprise security,

Reference 39

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:11.531480Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:29:57.694250Z digest=sha256:c5f5a5b247100525d3c7beb178105421ccfed251f67c4a7b4be2cd86ee0aa4a5

Observation 21994383-d6a5-4a8d-ae78-7cc93587e33a · outbound

This paper cites Holmes: real-time apt detection through correlation of suspicious information flows,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Holmes: real-time apt detection through correlation of suspicious information flows,

Reference 40

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:11.394444Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:29:57.767033Z digest=sha256:1a1bb1fc6f940cccf2d8a60a06c92246f6a6b2ca1b2d2606f2305fb0b82738c5

Observation cbeebed0-74d1-48ee-a866-766b6bff6071 · outbound

This paper cites Combating dependence ex- plosion in forensic analysis using alternative tag propagation semantics,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Combating dependence ex- plosion in forensic analysis using alternative tag propagation semantics,

Reference 41

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:11.269314Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:29:57.842744Z digest=sha256:00bcb716ca6021d0189e909f221dfda404233d9a572de35e82c9ae14fbc7d6dc

Observation a636947d-19e2-49b2-a320-d78491761ad7 · outbound

This paper cites Nodemerge: Template based efficient data reduction for big-data causality analysis,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Nodemerge: Template based efficient data reduction for big-data causality analysis,

Reference 42

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:11.093865Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:29:57.892251Z digest=sha256:932071bdb000660635b1051f9fe5dddb66b6995086754289f56677ea009eaab4

Observation b2ac9bd9-f63d-4626-966c-5eaf91cde3ea · outbound

This paper cites {SEAL}: Storage- efficient causality analysis on enterprise logs with query-friendly com- pression,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection {SEAL}: Storage- efficient causality analysis on enterprise logs with query-friendly com- pression,

Reference 43

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:11.001851Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:29:57.993856Z digest=sha256:97dfc0109b513878dbd5612eed06ab255832f219d39d3059e49bcd4540e2745f

Observation 1ab11741-c766-43ea-97c8-65bc9d4804af · outbound

This paper cites The case for learned provenance graph storage systems,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection The case for learned provenance graph storage systems,

Reference 44

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:10.837763Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:29:58.044421Z digest=sha256:069575434aa00412f4ca11f34a3e33b504032ebc67a3b930a2c4bb7cba7432bb

Observation 4c64684a-b93e-422a-9db1-e5cb21cc8751 · outbound

This paper cites Tactical provenance analysis for endpoint detection and response systems,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Tactical provenance analysis for endpoint detection and response systems,

Reference 45

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:10.693697Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:29:58.126512Z digest=sha256:717527fc0f5708fa1d7498d9d2386050b68e8763b1da3dae0a2b69ec18b22045

Observation c55b2174-36bc-4d45-b1ce-2c3e572f58c0 · outbound

This paper cites Alchemist: Fusing application and audit logs for precise attack provenance without instrumentation,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Alchemist: Fusing application and audit logs for precise attack provenance without instrumentation,

Reference 46

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:10.559253Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:29:58.196404Z digest=sha256:ab9640dc28062257323eefd2b5ce35106828adc3d2f920f03d31e64dbf4ffad1

Observation a14968af-ddc0-4579-8a48-b001a6daf866 · outbound

This paper cites Kairos: Practical Intrusion Detection and Investigation using Whole-system Provenance.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Kairos: Practical Intrusion Detection and Investigation using Whole-system Provenance

Reference 47

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:58.331185Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:58.331185Z digest=sha256:9c524ae2bfdcfa3c3b1d4dce27f46db834d7ffb87661062b2f5781e20c882855

Observation 2a0b26fc-6f60-4aae-b79f-1c7d60d56c35 · outbound

This paper cites R-caid: Embedding root cause analysis within provenance-based intrusion detection,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection R-caid: Embedding root cause analysis within provenance-based intrusion detection,

Reference 48

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:10.419230Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:29:58.397703Z digest=sha256:18f811bdd7731a54d70830ad5551f63f00fb959e5cbdc9b64913b175b7fa401a

Observation cd355c83-bf6e-49ac-acd8-6374431c1444 · outbound

This paper cites Shadewatcher: Recommendation-guided cyber threat analysis using system audit records,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Shadewatcher: Recommendation-guided cyber threat analysis using system audit records,

Reference 49

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:10.202376Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:29:58.480167Z digest=sha256:a6e6bc43b30eed3f138f080a950d454980030a7daba13fc5c5672a95b9715438

Observation e674b14c-49a4-48d4-afc8-cea022764d6c · outbound

This paper cites SIGL: securing software installations through deep graph learning,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection SIGL: securing software installations through deep graph learning,

Reference 50

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:09.784335Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:29:58.581410Z digest=sha256:20e3562508d0394fcbf1c7eb9a2c8d612af88237619237b1590403a83042d5b2

Observation 4e0ca736-a786-4bc4-acbe-51fb416f1b0a · outbound

This paper cites Darpa tc engagement 3 ground-truth,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Darpa tc engagement 3 ground-truth,

Reference 51

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:09.643516Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:29:58.661412Z digest=sha256:2b91a9c62df11ca798a4c90714c82e292a13a0c96e700d373fbccaf9354a6885

Observation eb275d39-3a86-4342-8385-8eff66bc6596 · outbound

This paper cites A Comprehensive Overview of Large Language Models (LLMs) for Cyber Defences: Opportunities and Directions.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection A Comprehensive Overview of Large Language Models (LLMs) for Cyber Defences: Opportunities and Directions

Reference 52

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:58.767171Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:58.767171Z digest=sha256:137b471841aec21d7844f27d70f2906810621fcfc6a729e429cd7353dcf17ebd

Observation 50cf2013-9dd2-4a06-b1de-2683af952af4 · outbound

This paper cites AutoAttacker: A Large Language Model Guided System to Implement Automatic Cyber-attacks.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection AutoAttacker: A Large Language Model Guided System to Implement Automatic Cyber-attacks

Reference 53

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:58.851040Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:58.851040Z digest=sha256:3d0f5a602bb4d9eed0d416fc784bff842b2278983841aba4c7e39dd54e2f8119

Observation e00dd72d-9c72-4f3d-a575-cdf0b69b69b4 · outbound

This paper cites {PentestGPT}: Evaluating and harnessing large language models for automated penetration testing,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection {PentestGPT}: Evaluating and harnessing large language models for automated penetration testing,

Reference 54

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:09.436223Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:29:58.977515Z digest=sha256:56aabaadae06638e6ddf312d0de3785724a7fdba5497ea542cdac2718cde7d2a

Observation a13b05ca-5738-4d33-9109-b90f79215757 · outbound

This paper cites Large language model guided protocol fuzzing,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Large language model guided protocol fuzzing,

Reference 55

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:59.047072Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:59.047072Z digest=sha256:d62c925697a7285060a3c599872b459cca538bd0cc984ee8b1a74d7e0ac13503

Observation fa90e2fd-1840-47a0-ab46-5aaa40e79302 · outbound

This paper cites Exploring {ChatGPT’s} capabilities on vulnerability management,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Exploring {ChatGPT’s} capabilities on vulnerability management,

Reference 56

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:09.208433Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:29:59.121697Z digest=sha256:bca78acfe5def9f9af01ad745127c6b344cdda82606fd54f9346d57185b26c61

Observation 9f848941-9faf-4cab-8752-77b90f8a62cb · outbound

This paper cites RACONTEUR: A Knowledgeable, Insightful, and Portable LLM-Powered Shell Command Explainer.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection RACONTEUR: A Knowledgeable, Insightful, and Portable LLM-Powered Shell Command Explainer

Reference 57

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:59.187409Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:59.187409Z digest=sha256:35ae9f462da0f6d32d4adbde0928872904867cebdd32d1bd299a489fc46fa7f5

Observation 8672f890-1202-4141-958f-caa8166b5092 · outbound

This paper cites Deeplog: Anomaly detection and diagnosis from system logs through deep learning,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Deeplog: Anomaly detection and diagnosis from system logs through deep learning,

Reference 58

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:59.259554Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:59.259554Z digest=sha256:02d9d5e40853cd4bc770aadce78bd08bdf06bb28fb13f7b4df5d4e9903dc9777

Observation 8173209c-0ee5-4ae3-bf7d-aae14f1b27b0 · outbound

This paper cites Log2vec: A heterogeneous graph embedding based approach for detecting cyber threats within enterprise,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Log2vec: A heterogeneous graph embedding based approach for detecting cyber threats within enterprise,

Reference 59

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:08.963852Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:29:59.331971Z digest=sha256:e9befca371bd120fe45596a4c7607c92f2e1b6b538c6414e9ddad2d64e42be39

Observation cc428afa-144e-4f12-886a-9a40a3e882d4 · outbound

This paper cites {ATTACK2VEC}: Leveraging temporal word embeddings to understand the evolution of cyberattacks,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection {ATTACK2VEC}: Leveraging temporal word embeddings to understand the evolution of cyberattacks,

Reference 60

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:08.778686Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:29:59.388082Z digest=sha256:d25eb25d21f8f1dd4582ee267dd406eabe4e12081829264d17976b7a3331a224

Observation 47815c30-c1c6-4137-b7f2-f6359a5f3231 · outbound

This paper cites Semantic anomaly detection with large language models,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Semantic anomaly detection with large language models,

Reference 61

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:59.475590Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:59.475590Z digest=sha256:49cda46c923e62f5550f869231c8e9d872620dca02c7c4abe40d0b1d2b70e9d2

Observation 0ebfde0e-8156-416d-bf86-6f6f17022f13 · outbound

This paper cites tiktoken,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection tiktoken,

Reference 62

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:08.548005Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:29:59.548683Z digest=sha256:8e104fa90614018cc63cb8494ab4de5f2af41ae26db4fd332fdc989f0d7f214d

Observation 3d985bc1-cec7-44e5-919f-670e01084ff8 · outbound

This paper cites NoLiMa: Long-Context Evaluation Beyond Literal Matching.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection NoLiMa: Long-Context Evaluation Beyond Literal Matching

Reference 63

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:59.630413Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:59.630413Z digest=sha256:78d4c2dc64d2298c5747600206555a068246f7af2054b042d0bbf4e430519ddf

Observation c6ec1f36-3fc1-4e39-87c5-a10f0317f963 · outbound

This paper cites Fundamental limits of prompt compression: A rate-distortion framework for black-box language models,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Fundamental limits of prompt compression: A rate-distortion framework for black-box language models,

Reference 64

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:08.403909Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:29:59.673991Z digest=sha256:9692e559a85fd90e476c9168b8c8b7eb22cedceed091cb06b7e638f8bd6154da

Observation 3e9b5f89-4d86-460f-b30e-e4fb93c622a8 · outbound

This paper cites A Systematic Survey of Prompt Engineering in Large Language Models: Techniques and Applications.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection A Systematic Survey of Prompt Engineering in Large Language Models: Techniques and Applications

Reference 65

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:59.766686Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:59.766686Z digest=sha256:d251af2ae7258fad1f9c16757bc3fe3d0cd586724b5c95e8723667c413577f86

Observation 34dace7f-e0ec-452c-b684-9b55bb187ec7 · outbound

This paper cites Chain-of-thought prompting elicits reasoning in large language models,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Chain-of-thought prompting elicits reasoning in large language models,

Reference 66

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:59.821399Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:59.821399Z digest=sha256:58f9526e553ab2ed582147f5ac404383300e3cad8b6de5a1e5b6b401a26a3eb9

Observation 37adf0a8-5c73-4ae2-9e9a-ac887b188d38 · outbound

This paper cites Self-Consistency Improves Chain of Thought Reasoning in Language Models.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Self-Consistency Improves Chain of Thought Reasoning in Language Models

Reference 67

Resolution
unresolved
no resolver link, observed 2026-08-06T17:29:59.893803Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:29:59.893803Z digest=sha256:88648b1fd3df96a91be81e1eb2562d385364c057ba4eb7eb7606cd4450155330

Observation 61f762c5-d2ae-49be-8a2e-19e6c3018b46 · outbound

This paper cites Custos: Practical tamper-evident auditing of operating systems using trusted execution,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Custos: Practical tamper-evident auditing of operating systems using trusted execution,

Reference 68

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:08.204888Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:30:00.030936Z digest=sha256:afd056e38d41174e0c3665ff19bc908358c76aaf1b8b603858c6f1fc706eacea

Observation 5a51d194-754b-4757-8bc0-cff2a5b38694 · outbound

This paper cites Auditing frameworks need resource isolation: A systematic study on the super producer threat to system auditing and its mitigation,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Auditing frameworks need resource isolation: A systematic study on the super producer threat to system auditing and its mitigation,

Reference 69

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:07.998211Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:30:00.104146Z digest=sha256:9b200272f5802455bb76eb67016e149212bdc66bb626592946f2765aa88fba44

Observation eb7bc96a-190c-4e83-b42a-c7e80283763e · outbound

This paper cites Support vector method for novelty detection,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Support vector method for novelty detection,

Reference 70

Resolution
unresolved
no resolver link, observed 2026-08-06T17:30:00.181120Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:30:00.181120Z digest=sha256:e52ec9861a18f4aa275babece47611c60d48e965a7a9868a86ca0a26eb161cf5

Observation 5c7022b8-b34e-4229-b239-e6d9f0c42b9b · outbound

This paper cites Bert: Pre-training of deep bidirectional transformers for language understanding,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Bert: Pre-training of deep bidirectional transformers for language understanding,

Reference 71

Resolution
unresolved
no resolver link, observed 2026-08-06T17:30:00.248846Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:30:00.248846Z digest=sha256:b316f26ef6743e6b6e408cadf0a77c57bebc8ad36eedb3e13eaba3ac9fa4df26

Observation c26624ca-fdd1-40d9-b51e-14501afc0029 · outbound

This paper cites bert-base-uncased,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection bert-base-uncased,

Reference 72

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:07.768556Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:30:00.328746Z digest=sha256:b4079721871f41a786c31a882f885efa30af29927107e0f2694826cfc7536a53

Observation 99832e11-fd86-4a71-8ce3-a65a9c4bb9ca · outbound

This paper cites RetroMAE: Pre-Training Retrieval-oriented Language Models Via Masked Auto-Encoder.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection RetroMAE: Pre-Training Retrieval-oriented Language Models Via Masked Auto-Encoder

Reference 73

Resolution
unresolved
no resolver link, observed 2026-08-06T17:30:00.412279Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:30:00.412279Z digest=sha256:6963aa5c7fe37eb256f58d242d6742dc0a63bcf621568a30144845833f90505b

Observation 8d3cd82d-e2ab-4432-be2e-9770047c3b9a · outbound

This paper cites Backtracking intrusions,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Backtracking intrusions,

Reference 74

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:07.669440Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:30:00.514080Z digest=sha256:feacba0e5fdbcbd4e59ff56e8a169c2444e29aec391ce0a2b5aa68a8f57aad33

Observation 264a1406-3a78-4df1-b5ca-3cddd1e5527d · outbound

This paper cites Representative sam- pling for reliable data analysis: theory of sampling,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Representative sam- pling for reliable data analysis: theory of sampling,

Reference 75

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:07.506534Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:30:00.614753Z digest=sha256:0c7a61e6632ee202d05852017ca89555c9b8f0479148e3b3c3bc0bffa3e54f3f

Observation 029e3d08-2928-4994-abc7-a1d8f112e856 · outbound

This paper cites ATLAS: A sequence-based learning approach for attack investigation,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection ATLAS: A sequence-based learning approach for attack investigation,

Reference 76

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:07.310877Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:30:00.709741Z digest=sha256:8f5f13583c64de753c852782c4087fab0369fbe82f1d3014fdf78593302d6fba

Observation 692a6a49-6875-466f-8ed8-10c6f9a316ae · outbound

This paper cites Threatrace: Detecting and tracing host-based threats in node level through provenance graph learning,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Threatrace: Detecting and tracing host-based threats in node level through provenance graph learning,

Reference 77

Resolution
unresolved
no resolver link, observed 2026-08-06T17:30:00.791725Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:30:00.791725Z digest=sha256:dd8cce49417d64fad6c29d6baa1079db58822d1a5da954cc4061a28faa062834

Observation 753570f1-183c-4067-b2cf-fff35d4eae1d · outbound

This paper cites Mitigating advanced and persistent threat (apt) damage by reasoning with provenance in large enterprise network (marple) program,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Mitigating advanced and persistent threat (apt) damage by reasoning with provenance in large enterprise network (marple) program,

Reference 78

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:07.144132Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:30:00.883684Z digest=sha256:1d21131ea65c3566c81960bba707b19cf94683675757d4a284252bf2f93716da

Observation e50e8dec-88b4-4ef6-9dba-5761ca5dfe89 · outbound

This paper cites Atlasv2,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Atlasv2,

Reference 79

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:06.928481Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:30:00.985610Z digest=sha256:e23f0fa01573683012ceb852cd73beef0426ac695d9ba5697948322a4b0d068b

Observation a7444d72-e49e-49ab-ae43-04c093b4fc7e · outbound

This paper cites Flash repo,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Flash repo,

Reference 80

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:06.668629Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:30:01.065685Z digest=sha256:1d2e40b3610ed14a2168c3195241ef52ae1d282812f9b35689112ad6e0c67c63

Observation a05f47ee-be04-4128-bb15-047193a9860c · outbound

This paper cites Magic repo,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Magic repo,

Reference 81

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:06.402552Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:30:01.196441Z digest=sha256:469ce24700faa852b81aa6416f8351134f98b0a7c9a70f95ead2415f27e8090b

Observation f24993d7-3ba3-470b-8acf-bc5c0eee970f · outbound

This paper cites Orthrus repo,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Orthrus repo,

Reference 82

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:06.203612Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:30:01.278438Z digest=sha256:dc2fc0d20229057a6da68849ddad9799ff9155926bdd73bbbe388a86b66ba006

Observation 2b2b42d8-8271-42bc-822c-d70abc547a4b · outbound

This paper cites Airtag repo,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Airtag repo,

Reference 83

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:05.960843Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:30:01.330764Z digest=sha256:2caeddb6cbbce86dd673b14866ecbbab387e056386b260eecf544f86cb6c8bf3

Observation 7778bf9a-0a31-403c-81b8-ca8c53d90919 · outbound

This paper cites Atlas dataset,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Atlas dataset,

Reference 84

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:05.721419Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:30:01.420613Z digest=sha256:55812f71030643e85dc9daa0c9d80b73fb32676b727ee9fcbde2ba830fdd31ad

Observation 29df7f98-d898-4900-8254-af9e293b2e0b · outbound

This paper cites DeepSeek-R1: Incentivizing Reasoning Capability in LLMs via Reinforcement Learning.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection DeepSeek-R1: Incentivizing Reasoning Capability in LLMs via Reinforcement Learning

Reference 85

Resolution
unresolved
no resolver link, observed 2026-08-06T17:30:01.535060Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:30:01.535060Z digest=sha256:7c91b7645fe44a5eadf020c5fda301749d7673e9145675ef67dcca9e4b3cac2e

Observation d083c56b-190b-4321-80e5-0bbdf127b5bb · outbound

This paper cites The Llama 3 Herd of Models.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection The Llama 3 Herd of Models

Reference 86

Resolution
unresolved
no resolver link, observed 2026-08-06T17:30:01.634139Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:30:01.634139Z digest=sha256:e5271dd00ccd7bcc3798365273e59de3268cf9edb8de036f4c99cdc1fe52941d

Observation 0cdc90d4-c8ad-4a56-987b-d6b1ef6a9c98 · outbound

This paper cites Openai o3-mini,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Openai o3-mini,

Reference 87

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:05.515588Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:30:01.764153Z digest=sha256:8282be90fc9f7abf18cebf71ac5f538ce526619198a80f41e617be19828419d4

Observation c6d97db2-39a2-4894-be5a-b09f6bb0919b · outbound

This paper cites Sonar reasoning pro,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Sonar reasoning pro,

Reference 88

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:05.318796Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:30:01.829143Z digest=sha256:d80d0cc30e19a1ae8d3c86a954483549c4dd4b2cd669fe0857d93e9ae600b30c

Observation c5113323-6e29-48b3-8951-d6deba6d9b03 · outbound

This paper cites all-MiniLM-L6-v2,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection all-MiniLM-L6-v2,

Reference 89

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:05.151212Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:30:01.932568Z digest=sha256:1167c25e0454e2e51b9322b4a5b28c57614f6b65e66c16a77580c8b84795c0e2

Observation dccc9578-dceb-4cae-99e2-1e3dcc0cfa48 · outbound

This paper cites SemEval-2017 Task 1: Semantic Textual Similarity - Multilingual and Cross-lingual Focused Evaluation.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection SemEval-2017 Task 1: Semantic Textual Similarity - Multilingual and Cross-lingual Focused Evaluation

Reference 90

Resolution
unresolved
no resolver link, observed 2026-08-06T17:30:02.021302Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:30:02.021302Z digest=sha256:8201424e2bc34332f061228ada5b4588b5e0eac13506f909037a244ab1a6e61e

Observation 53ef3339-c6cc-4ace-8b3a-48db4f1b85d6 · outbound

This paper cites (2025) Api pricing.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection (2025) Api pricing

Reference 91

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:04.934529Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:30:02.137618Z digest=sha256:2e876a874996f1b74073e679603f9dc9f1be9ae5e1678412303f2cc84d7d3e43

Observation 602419b2-44a9-495f-b8f3-f11e16810ccb · outbound

This paper cites Attacks on deidentification’s defenses,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Attacks on deidentification’s defenses,

Reference 92

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:04.738393Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:30:02.256881Z digest=sha256:8708f32c908c0451059fac7efbc75d5430f8656c1a42073fa34f4dcceb618faa

Observation 985fefb7-c75f-4fdc-a66a-c262d885aec3 · outbound

This paper cites LlamaFactory: Unified Efficient Fine-Tuning of 100+ Language Models.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection LlamaFactory: Unified Efficient Fine-Tuning of 100+ Language Models

Reference 93

Resolution
unresolved
no resolver link, observed 2026-08-06T17:30:02.345862Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:30:02.345862Z digest=sha256:90483d1b25d8c7e01fc4988e42dc452349238c17594793ced363a8da9eb7fda9

Observation d9ca10db-f661-4016-92b3-beff54f075b1 · outbound

This paper cites s1: Simple test-time scaling.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection s1: Simple test-time scaling

Reference 94

Resolution
unresolved
no resolver link, observed 2026-08-06T17:30:02.499902Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:30:02.499902Z digest=sha256:c8a8908406f6e6160075e9d6f14cd94c3cec761e33020e362541027a6c37a31d

Observation 7172ed78-bb13-4fd4-be47-6d7877ac3bd1 · outbound

This paper cites Persistent Pre-Training Poisoning of LLMs.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Persistent Pre-Training Poisoning of LLMs

Reference 95

Resolution
unresolved
no resolver link, observed 2026-08-06T17:30:02.613382Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:30:02.613382Z digest=sha256:e216bb13ebc0d75f882b6c83b35c04c5e7271dfc4a321f0834e61cbed6c792e5

Observation 130925ab-1efb-4e0e-a993-56414968dbcb · outbound

This paper cites Sok: Pragmatic assessment of machine learning for network intrusion detection,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection Sok: Pragmatic assessment of machine learning for network intrusion detection,

Reference 96

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:04.575165Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:30:02.728879Z digest=sha256:0ca5262b67edc3660e530648b054458a111a623ee1ff237bbb8ff6c2c506c54a

Observation 7d98fc00-c8fa-4411-be94-0ae4b934d7d7 · outbound

This paper cites A survey on data-driven network intrusion detection,.

From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection A survey on data-driven network intrusion detection,

Reference 97

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:30:04.381432Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-06T17:30:02.816653Z digest=sha256:101006ce1b8f6cac2e1ed96cca794d581e5b3b7f5c7195b86598864006753821

Pith citing papers

No inbound Pith citation observations are available.