Ppin: Anomaly-Based Intrusion Detection on Provenance Graph via Behavior Pattern Mining
inforesearchPeer-Reviewed
researchsecurity
Source: IEEE Xplore (Security & AI Journals)July 3, 2026
Summary
Ppin is an anomaly-based intrusion detection system that uses provenance graphs (visual maps showing how different parts of a computer system interact with each other) to identify attacks by finding unusual patterns in system behavior. Unlike existing systems that struggle to explain attacks clearly, Ppin uses a memory-augmented neural network (a machine learning model that remembers information over time) to detect rare behaviors and correlate them to show the full story of how an attack happened.
Classification
Attack SophisticationModerate
Impact (CIA+S)
integrityavailability
AI Component TargetedFramework
Monthly digest — independent AI security research
Original source: http://ieeexplore.ieee.org/document/11594958
First tracked: September 26, 2026 at 02:01 AM
Classified by LLM (prompt v3) · confidence: 75%